imPC@ndo EN

Vulnerabilità sfruttate attivamente

770 CVE

CVE-2018-8120
Ransomware Alta 7.0

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2. This CVE ID …

microsoft windows_7 · microsoft windows_server_2008
0.74EPSS
CVE-2026-25089
Sfruttata Critica 9.8

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, Fo…

fortinet fortisandbox · fortinet fortisandbox_cloud · fortinet fortisandbox_paas
0.74EPSS
CVE-2020-5741
Sfruttata Alta 7.2

Deserialization of Untrusted Data in Plex Media Server on Windows allows a remote, authenticated attacker to execute arbitrary Python code.

plex media_server
0.73EPSS
CVE-2019-1429
Sfruttata Alta 7.5

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1426, CVE-2019-1427, CVE-2019-1428.

microsoft internet_explorer
0.73EPSS
CVE-2017-6316
Sfruttata Critica 9.8

Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as root via a CGISESSID cookie. On CloudBridge (the former name of NetScaler SD-WAN) devices, the cookie name was CAKEPHP rather than CGISESSID.…

citrix netscaler_sd-wan
0.73EPSS
CVE-2022-20699
Sfruttata Critica 10.0

Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization prot…

cisco rv340_firmware · cisco rv340w_firmware · cisco rv345_firmware · cisco rv345p_firmware
0.72EPSS
CVE-2018-0824
Sfruttata Alta 8.8

A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized objects, aka "Microsoft COM for Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1…

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1703 · microsoft windows_10_1709 · e altri 9
0.72EPSS
CVE-2026-21509
Sfruttata Alta 7.8

Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.

microsoft 365_apps · microsoft office · microsoft office_long_term_servicing_channel
0.72EPSS
CVE-2017-8540
Sfruttata Alta 7.8

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, a…

microsoft endpoint_protection · microsoft exchange_server · microsoft forefront_endpoint_protection · microsoft forefront_security · e altri 5
0.72EPSS
CVE-2024-20353
Sfruttata Alta 8.6

A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting i…

cisco adaptive_security_appliance_software · cisco secure_firewall_threat_defense
0.71EPSS
CVE-2013-3163
Sfruttata Alta 8.8

Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013…

microsoft internet_explorer
0.71EPSS
CVE-2017-6736
Sfruttata Alta 8.8

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. …

cisco ios · cisco ios_xe
0.71EPSS
CVE-2012-1535
Sfruttata Alta 7.8

Unspecified vulnerability in Adobe Flash Player before 11.3.300.271 on Windows and Mac OS X and before 11.2.202.238 on Linux allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted SWF content, as exploite…

adobe flash_player · opensuse opensuse · redhat enterprise_linux_desktop · redhat enterprise_linux_server · e altri 2
0.70EPSS
CVE-2026-42897
Sfruttata Alta 8.1

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

microsoft exchange_server · microsoft exchange_server_subscription_edition
0.70EPSS
CVE-2021-42278
Ransomware Alta 7.5

Active Directory Domain Services Elevation of Privilege Vulnerability

microsoft windows_server_2004 · microsoft windows_server_2008 · microsoft windows_server_2012 · microsoft windows_server_2016 · e altri 3
0.70EPSS
CVE-2018-8453
Ransomware Alta 7.8

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 20…

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1703 · microsoft windows_10_1709 · e altri 11
0.70EPSS
CVE-2016-0185
Sfruttata Alta 7.8

Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, and Windows 8.1 allows remote attackers to execute arbitrary code via a crafted Media Center link (aka .mcl) file, aka "Windows Media Center Remote Code Execution Vulnerability."

microsoft windows_7 · microsoft windows_8.1 · microsoft windows_vista
0.70EPSS
CVE-2013-3896
Sfruttata Media 5.5

Microsoft Silverlight 5 before 5.1.20913.0 does not properly validate pointers during access to Silverlight elements, which allows remote attackers to obtain sensitive information via a crafted Silverlight application, aka "Silverlight Vulnerability."

microsoft silverlight
0.70EPSS
CVE-2020-3259
Ransomware Alta 7.5

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to retrieve memory contents on an affected device, which could l…

cisco adaptive_security_appliance_software · cisco secure_firewall_threat_defense
0.69EPSS
CVE-2020-0938
Sfruttata Alta 7.8

A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a specially-crafted multi-master font - Adobe Type 1 PostScript format.For all systems except Windows 10, an attacker who successfu…

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1709 · microsoft windows_10_1803 · e altri 13
0.69EPSS
CVE-2016-3393
Sfruttata Alta 7.8

Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows remote attackers to execute …

microsoft windows_10_1507 · microsoft windows_10_1511 · microsoft windows_10_1607 · microsoft windows_7 · e altri 5
0.69EPSS
CVE-2015-7645
Ransomware Alta 7.8

Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote attackers to execute arbitrary code via a crafted SWF file, as exploited in the wild in October 2015.

adobe flash_player · opensuse evergreen · opensuse opensuse · redhat enterprise_linux_desktop · e altri 6
0.68EPSS
CVE-2024-30088
Ransomware Alta 7.0

Windows Kernel Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 8
0.68EPSS
CVE-2022-34713
Sfruttata Alta 7.8

Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_20h2 · e altri 12
0.68EPSS
CVE-2015-8651
Sfruttata Alta 8.8

Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allo…

adobe air · adobe air_sdk · adobe air_sdk_\&_compiler · adobe flash_player · e altri 13
0.68EPSS