imPC@ndo EN

Vulnerabilità sfruttate attivamente

770 CVE

CVE-2023-3079
Sfruttata Alta 8.8

Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

apple macos · couchbase couchbase_server · debian debian_linux · fedoraproject fedora · e altri 2
0.32EPSS
CVE-2026-0300
Sfruttata Critica 9.8

A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls …

paloaltonetworks pan-os · siemens ruggedcom_ape1808_firmware
0.32EPSS
CVE-2021-42292
Sfruttata Alta 7.8

Microsoft Excel Security Feature Bypass Vulnerability

microsoft 365_apps · microsoft excel · microsoft office · microsoft office_long_term_servicing_channel
0.32EPSS
CVE-2019-15752
Sfruttata Alta 7.8

Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\DockerDesktop\version-bin\ as a low-privilege user, and then waiting for an admin or service use…

apache geode · docker docker
0.32EPSS
CVE-2022-4135
Sfruttata Critica 9.6

Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

google chrome · microsoft edge · microsoft edge_chromium
0.32EPSS
CVE-2011-2005
Sfruttata Alta 7.8

afd.sys in the Ancillary Function Driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "Ancillary Function Dr…

microsoft windows_server_2003 · microsoft windows_xp
0.32EPSS
CVE-2026-20963
Sfruttata Critica 9.8

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

microsoft sharepoint_server
0.32EPSS
CVE-2026-20133
Sfruttata Media 6.5

A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system. This vulnerability is due to insufficient file system restrictions. An authenticated attacker with netadmi…

cisco catalyst_sd-wan_manager
0.31EPSS
CVE-2026-20131
Ransomware Critica 10.0

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device. This vulnerability is due to i…

cisco secure_firewall_management_center
0.31EPSS
CVE-2017-5070
Sfruttata Alta 8.8

Type confusion in V8 in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

google chrome · redhat enterprise_linux_desktop · redhat enterprise_linux_server · redhat enterprise_linux_workstation
0.31EPSS
CVE-2025-26633
Ransomware Alta 7.0

Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 11
0.30EPSS
CVE-2024-21351
Sfruttata Alta 7.6

Windows SmartScreen Security Feature Bypass Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 8
0.30EPSS
CVE-2019-13608
Ransomware Alta 7.5

Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.

citrix storefront_server
0.30EPSS
CVE-2020-0968
Sfruttata Alta 7.5

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0970.

microsoft internet_explorer
0.30EPSS
CVE-2019-1405
Ransomware Alta 7.8

An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka 'Windows UPnP Service Elevation of Privilege Vulnerability'.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1709 · microsoft windows_10_1803 · e altri 11
0.30EPSS
CVE-2017-0222
Sfruttata Alta 8.8

A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0226.

microsoft internet_explorer
0.30EPSS
CVE-2025-20393
Sfruttata Critica 10.0

A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to execute arbitrary system commands on an affected device with root …

cisco asyncos
0.30EPSS
CVE-2010-0232
Sfruttata Alta 7.8

The kernel in Microsoft Windows NT 3.1 through Windows 7, including Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, and Windows Server 2008 Gold and SP2, when access to 16-bit applications is enabled on a 32…

microsoft windows_2000 · microsoft windows_7 · microsoft windows_xp
0.29EPSS
CVE-2017-0149
Sfruttata Alta 8.8

Microsoft Internet Explorer 9 through 11 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." This vulnerability is different from tho…

microsoft internet_explorer
0.29EPSS
CVE-2024-3393
Sfruttata Alta 7.5

A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger thi…

paloaltonetworks pan-os · paloaltonetworks prisma_access
0.29EPSS
CVE-2022-37969
Sfruttata Alta 7.8

Windows Common Log File System Driver Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_20h2 · e altri 11
0.28EPSS
CVE-2026-20262
Sfruttata Media 6.5

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. This vulnerability exists because the affe…

cisco catalyst_sd-wan_manager
0.28EPSS
CVE-2024-1086
Ransomware Alta 7.8

A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, and hence the nf_hook_s…

debian debian_linux · fedoraproject fedora · linux linux_kernel · netapp 500f_firmware · e altri 14
0.28EPSS
CVE-2024-38193
Sfruttata Alta 7.8

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 11
0.28EPSS
CVE-2020-3153
Ransomware Media 6.5

A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories with system level privileges. The vulnerability is due to the …

cisco anyconnect_secure_mobility_client
0.27EPSS