imPC@ndo EN

Vulnerabilità sfruttate attivamente

770 CVE

CVE-2022-26923
Sfruttata Alta 8.8

Active Directory Domain Services Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_1909 · e altri 10
0.83EPSS
CVE-2026-34486
Sfruttata Alta 7.5

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0…

apache tomcat · redhat enterprise_linux · redhat enterprise_linux_els · redhat enterprise_linux_eus · e altri 3
0.83EPSS
CVE-2016-7200
Sfruttata Alta 8.8

The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerabilit…

microsoft edge
0.82EPSS
CVE-2010-2883
Sfruttata Alta 7.3

Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PDF document with a l…

adobe acrobat · adobe acrobat_reader
0.82EPSS
CVE-2018-15982
Ransomware Alta 7.8

Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

adobe flash_player · adobe flash_player_installer · redhat enterprise_linux_desktop · redhat enterprise_linux_server · e altri 1
0.82EPSS
CVE-2010-1297
Sfruttata Alta 7.8

Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow remote attackers to execute arbitrary code or cause a denial of ser…

adobe acrobat · adobe air · adobe flash_player · opensuse opensuse · e altri 1
0.82EPSS
CVE-2010-0806
Sfruttata Alta 8.8

Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object, as…

microsoft internet_explorer
0.82EPSS
CVE-2009-4324
Sfruttata Alta 7.8

Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted PDF file using ZLib compres…

adobe acrobat · adobe acrobat_reader · opensuse opensuse · suse linux_enterprise · e altri 1
0.82EPSS
CVE-2013-1331
Sfruttata Alta 7.8

Buffer overflow in Microsoft Office 2003 SP3 and Office 2011 for Mac allows remote attackers to execute arbitrary code via crafted PNG data in an Office document, leading to improper memory allocation, aka "Office Buffer Overflow Vulnerability."

microsoft office
0.82EPSS
CVE-2013-0074
Ransomware Alta 7.8

Microsoft Silverlight 5, and 5 Developer Runtime, before 5.1.20125.0 does not properly validate pointers during HTML object rendering, which allows remote attackers to execute arbitrary code via a crafted Silverlight application, aka "Silverlight Double Derefe…

microsoft silverlight
0.82EPSS
CVE-2024-43451
Sfruttata Media 6.5

NTLM Hash Disclosure Spoofing Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 11
0.82EPSS
CVE-2012-4969
Sfruttata Alta 8.1

Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code via a crafted web site, as exploited in the wild in September 2012.

microsoft internet_explorer
0.82EPSS
CVE-2018-13382
Ransomware Critica 9.1

An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to modify the passwo…

fortinet fortios · fortinet fortiproxy
0.82EPSS
CVE-2014-4114
Sfruttata Alta 7.8

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted OLE object in an Office document…

microsoft windows_7 · microsoft windows_8 · microsoft windows_8.1 · microsoft windows_rt · e altri 4
0.82EPSS
CVE-2019-0752
Ransomware Alta 7.5

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0739, CVE-2019-0753, CVE-2019-0862.

microsoft internet_explorer
0.82EPSS
CVE-2017-11826
Sfruttata Alta 7.8

Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 2007, 2010, 2013 and 2016, Word Automation Services, and Office Online Server allow remote code executio…

microsoft office_compatibility_pack · microsoft office_online_server · microsoft office_web_apps_server · microsoft office_word_viewer · e altri 3
0.81EPSS
CVE-2021-31955
Sfruttata Media 5.5

Windows Kernel Information Disclosure Vulnerability

microsoft windows_10_1809 · microsoft windows_10_1909 · microsoft windows_10_2004 · microsoft windows_10_20h2 · e altri 4
0.81EPSS
CVE-2017-0262
Sfruttata Alta 7.8

Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0261 and…

microsoft office
0.81EPSS
CVE-2016-7255
Sfruttata Alta 7.8

The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow local users to gain privileg…

microsoft windows_10_1507 · microsoft windows_10_1511 · microsoft windows_10_1607 · microsoft windows_7 · e altri 6
0.81EPSS
CVE-2021-26411
Ransomware Alta 8.8

Internet Explorer Memory Corruption Vulnerability

microsoft edge · microsoft internet_explorer
0.81EPSS
CVE-2015-2545
Sfruttata Alta 7.8

Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted EPS image, aka "Microsoft Office Malformed EPS File Vulnerability."

microsoft office
0.80EPSS
CVE-2025-33073
Sfruttata Alta 8.8

Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 11
0.80EPSS
CVE-2017-0037
Sfruttata Alta 8.1

Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSpanningElement function in mshtml.dll, which allows remote attackers to execute arbitrary code via vectors invo…

microsoft edge · microsoft internet_explorer
0.80EPSS
CVE-2016-7201
Sfruttata Alta 8.8

The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerabilit…

microsoft edge
0.80EPSS
CVE-2012-4792
Sfruttata Alta 8.8

Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly allocated or (2) is deleted, as demonstrated by a CDwnB…

microsoft internet_explorer
0.79EPSS