imPC@ndo EN

Vulnerabilità sfruttate attivamente

770 CVE

CVE-2018-8581
Ransomware Alta 7.4

An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability." This affects Microsoft Exchange Server.

microsoft exchange_server
0.27EPSS
CVE-2021-36948
Sfruttata Alta 7.8

Windows Update Medic Service Elevation of Privilege Vulnerability

microsoft windows_10_1809 · microsoft windows_10_1909 · microsoft windows_10_2004 · microsoft windows_10_20h2 · e altri 4
0.27EPSS
CVE-2014-2817
Sfruttata Alta 8.8

Microsoft Internet Explorer 6 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."

microsoft internet_explorer
0.26EPSS
CVE-2020-8196
Sfruttata Media 4.3

Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low privil…

citrix application_delivery_controller_firmware · citrix gateway_firmware · citrix netscaler_gateway_firmware · citrix sd-wan_wanop
0.26EPSS
CVE-2016-3351
Ransomware Media 6.5

Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."

microsoft edge · microsoft internet_explorer
0.26EPSS
CVE-2023-36802
Sfruttata Alta 7.8

Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability

microsoft windows_10_1809 · microsoft windows_10_21h2 · microsoft windows_10_22h2 · microsoft windows_11_21h2 · e altri 3
0.26EPSS
CVE-2024-37085
Ransomware Media 6.8

VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management https://blogs.vmware.com/vsphere…

vmware cloud_foundation · vmware esxi
0.26EPSS
CVE-2026-21510
Sfruttata Alta 8.8

Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.

microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · microsoft windows_10_22h2 · e altri 9
0.26EPSS
CVE-2024-49138
Sfruttata Alta 7.8

Windows Common Log File System Driver Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 11
0.25EPSS
CVE-2018-5002
Sfruttata Alta 7.8

Adobe Flash Player versions 29.0.0.171 and earlier have a Stack-based buffer overflow vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

adobe flash_player · adobe flash_player_desktop_runtime · redhat enterprise_linux_desktop · redhat enterprise_linux_server · e altri 1
0.25EPSS
CVE-2026-20245
Sfruttata Alta 7.8

A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an authenticated, local attacker to execute …

cisco catalyst_sd-wan_manager · cisco sd-wan_vsmart_controller
0.25EPSS
CVE-2024-35250
Sfruttata Alta 7.8

Windows Kernel-Mode Driver Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 10
0.25EPSS
CVE-2016-7855
Sfruttata Alta 8.8

Use-after-free vulnerability in Adobe Flash Player before 23.0.0.205 on Windows and OS X and before 11.2.202.643 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in October 2016.

adobe flash_player · redhat enterprise_linux_desktop · redhat enterprise_linux_server · redhat enterprise_linux_workstation
0.25EPSS
CVE-2022-0185
Sfruttata Alta 8.4

A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of unprivileged user namespaces enabled, otherw…

linux linux_kernel · netapp h300e_firmware · netapp h300s_firmware · netapp h410c_firmware · e altri 5
0.25EPSS
CVE-2019-18187
Sfruttata Alta 7.5

Trend Micro OfficeScan versions 11.0 and XG (12.0) could be exploited by an attacker utilizing a directory traversal vulnerability to extract files from an arbitrary zip file to a specific folder on the OfficeScan server, which could potentially lead to remote…

trendmicro officescan
0.25EPSS
CVE-2022-41128
Sfruttata Alta 8.8

Windows Scripting Languages Remote Code Execution Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_20h2 · e altri 12
0.25EPSS
CVE-2026-20122
Sfruttata Media 5.4

A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local file system. To exploit this vulnerability, the attacker must have valid read-only credentials with API access o…

cisco catalyst_sd-wan_manager
0.25EPSS
CVE-2016-0040
Sfruttata Alta 7.8

The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to gain privileges via a crafted application, aka "Windows Elevation of Privilege Vulnerability."

microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.25EPSS
CVE-2018-8653
Sfruttata Alta 7.5

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer …

microsoft internet_explorer
0.24EPSS
CVE-2014-0502
Sfruttata Alta 8.8

Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR SDK before 4.0.0.1628, and Adobe AIR SDK …

adobe adobe_air · adobe adobe_air_sdk · adobe flash_player · opensuse opensuse · e altri 6
0.24EPSS
CVE-2020-1380
Sfruttata Alta 7.8

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current u…

microsoft internet_explorer
0.24EPSS
CVE-2020-4006
Sfruttata Critica 9.1

VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability.

vmware cloud_foundation · vmware identity_manager · vmware identity_manager_connector · vmware one_access · e altri 1
0.24EPSS
CVE-2016-3298
Sfruttata Media 6.5

Microsoft Internet Explorer 9 through 11 and the Internet Messaging API in Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allow remote attackers to determine the existence of arbitrary files via a crafted web site, aka "Internet Explo…

microsoft internet_explorer · microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.23EPSS
CVE-2026-32201
Sfruttata Media 6.5

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

microsoft sharepoint_server
0.23EPSS
CVE-2025-14174
Sfruttata Alta 8.8

Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

apple ipados · apple iphone_os · apple macos · apple safari · e altri 5
0.23EPSS