imPC@ndo EN

Vulnerabilità sfruttate attivamente

770 CVE

CVE-2021-34448
Sfruttata Media 6.8

Scripting Engine Memory Corruption Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_1909 · e altri 10
0.40EPSS
CVE-2013-6282
Sfruttata Alta 8.8

The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addresses, which allows attackers to read or modify the contents of arbitrary kernel memory locations via a crafted applica…

linux linux_kernel
0.40EPSS
CVE-2013-3660
Sfruttata Alta 7.8

The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server 2012 does not proper…

microsoft windows_7 · microsoft windows_8 · microsoft windows_rt · microsoft windows_server_2003 · e altri 4
0.40EPSS
CVE-2021-1647
Sfruttata Alta 7.8

Microsoft Defender Remote Code Execution Vulnerability

microsoft security_essentials · microsoft system_center_endpoint_protection · microsoft windows_defender
0.39EPSS
CVE-2021-26828
Sfruttata Alta 8.8

OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm.

scadabr scadabr
0.39EPSS
CVE-2025-20352
Sfruttata Alta 7.7

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following: An authenticated, remote attacker with low privileges could cause a denial of service (DoS) condition on …

cisco ios · cisco ios_xe · cisco ios_xe_sd-wan
0.39EPSS
CVE-2015-2502
Sfruttata Alta 8.8

Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," as exploited in the wild in August 2015.

microsoft internet_explorer
0.39EPSS
CVE-2015-2424
Sfruttata Alta 8.8

Microsoft PowerPoint 2007 SP3, Word 2007 SP3, PowerPoint 2010 SP2, Word 2010 SP2, PowerPoint 2013 SP1, Word 2013 SP1, and PowerPoint 2013 RT SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Off…

microsoft excel_viewer · microsoft office · microsoft office_compatibility_pack · microsoft powerpoint · e altri 2
0.38EPSS
CVE-2018-13374
Ransomware Media 4.3

A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connectivity test request to a …

fortinet fortiadc · fortinet fortios
0.38EPSS
CVE-2023-4762
Sfruttata Alta 8.8

Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

debian debian_linux · fedoraproject fedora · google chrome · microsoft edge_chromium
0.38EPSS
CVE-2014-3153
Sfruttata Alta 7.8

The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE command that facilitates unsafe waiter modifi…

canonical ubuntu_linux · linux linux_kernel · opensuse opensuse · oracle linux · e altri 5
0.37EPSS
CVE-2016-0099
Ransomware Alta 7.8

The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 does not properly process request handles, which allows lo…

microsoft windows_10_1507 · microsoft windows_10_1511 · microsoft windows_7 · microsoft windows_8.1 · e altri 3
0.37EPSS
CVE-2018-4990
Sfruttata Alta 8.8

Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Double Free vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

adobe acrobat_dc · adobe acrobat_reader_dc
0.37EPSS
CVE-2020-17144
Sfruttata Alta 8.4

Microsoft Exchange Remote Code Execution Vulnerability

microsoft exchange_server
0.37EPSS
CVE-2022-22960
Sfruttata Alta 7.8

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. A malicious actor with local access can escalate privileges to 'root'.

vmware cloud_foundation · vmware identity_manager · vmware vrealize_automation · vmware vrealize_suite_lifecycle_manager · e altri 1
0.36EPSS
CVE-2015-2387
Sfruttata Alta 7.8

ATMFD.DLL in the Adobe Type Manager Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users …

microsoft windows_7 · microsoft windows_8 · microsoft windows_8.1 · microsoft windows_rt · e altri 5
0.35EPSS
CVE-2015-1770
Sfruttata Alta 8.8

Microsoft Office 2013 SP1 and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Uninitialized Memory Use Vulnerability."

microsoft office
0.35EPSS
CVE-2013-5065
Sfruttata Alta 7.8

NDProxy.sys in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in November 2013.

microsoft windows_2003_server · microsoft windows_xp
0.35EPSS
CVE-2016-5198
Sfruttata Alta 8.8

V8 in Google Chrome prior to 54.0.2840.90 for Linux, and 54.0.2840.85 for Android, and 54.0.2840.87 for Windows and Mac included incorrect optimisation assumptions, which allowed a remote attacker to perform arbitrary read/write operations, leading to code exe…

google chrome · redhat enterprise_linux_desktop · redhat enterprise_linux_server · redhat enterprise_linux_workstation
0.35EPSS
CVE-2018-13383
Ransomware Media 4.3

A heap buffer overflow in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through 5.4.12, 5.2.14 and earlier and FortiProxy 2.0.0, 1.2.8 and earlier in the SSL VPN web portal may cause the SSL VPN web service termination for logged in users d…

fortinet fortios · fortinet fortiproxy
0.34EPSS
CVE-2015-0071
Sfruttata Media 6.5

Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass Vulnerability."

microsoft internet_explorer
0.34EPSS
CVE-2020-8195
Sfruttata Media 6.5

Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low priv…

citrix application_delivery_controller_firmware · citrix gateway_firmware · citrix gateway_plug-in_for_linux · citrix netscaler_gateway_firmware · e altri 1
0.33EPSS
CVE-2008-4128
Sfruttata Media 4.3

Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router allow remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /leve…

cisco ios
0.33EPSS
CVE-2025-32756
Sfruttata Critica 9.8

A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7…

fortinet forticamera_firmware · fortinet fortimail · fortinet fortindr · fortinet fortirecorder · e altri 1
0.33EPSS
CVE-2013-0641
Sfruttata Alta 7.8

Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allows remote attackers to execute arbitrary code via a crafted PDF document, as exploited in the wild in February 2013.

adobe acrobat · adobe acrobat_reader · opensuse opensuse · redhat enterprise_linux_desktop · e altri 5
0.32EPSS