imPC@ndo EN

Vulnerabilità sfruttate attivamente

770 CVE

CVE-2016-6367
Sfruttata Alta 7.8

Cisco Adaptive Security Appliance (ASA) Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices allows local users to gain privileges via invalid CLI commands, aka Bug ID CSCtu74257 or EPICBANANA.

cisco adaptive_security_appliance_software
0.23EPSS
CVE-2016-1019
Ransomware Critica 9.8

Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, as exploited in the wild in April 2016.

adobe air_desktop_runtime · adobe air_sdk · adobe air_sdk_\&_compiler · adobe flash_player · e altri 1
0.22EPSS
CVE-2014-0196
Sfruttata Media 5.5

The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory corruption and system crash) or gain privi…

canonical ubuntu_linux · debian debian_linux · f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · e altri 26
0.22EPSS
CVE-2026-56164
Sfruttata Media 5.3

Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

microsoft sharepoint_server
0.22EPSS
CVE-2024-37079
Sfruttata Critica 9.8

vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remo…

vmware cloud_foundation · vmware vcenter_server
0.22EPSS
CVE-2018-8639
Ransomware Alta 7.8

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 20…

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1703 · microsoft windows_10_1709 · e altri 9
0.22EPSS
CVE-2014-0546
Sfruttata Critica 9.8

Adobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows allow attackers to bypass a sandbox protection mechanism, and consequently execute native code in a privileged context, via unspecified vectors.

adobe acrobat · adobe acrobat_reader
0.22EPSS
CVE-2023-29360
Sfruttata Alta 8.4

Microsoft Streaming Service Elevation of Privilege Vulnerability

microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · microsoft windows_10_22h2 · e altri 5
0.22EPSS
CVE-2016-0162
Sfruttata Media 4.3

Microsoft Internet Explorer 9 through 11 allows remote attackers to determine the existence of files via crafted JavaScript code, aka "Internet Explorer Information Disclosure Vulnerability."

microsoft internet_explorer
0.22EPSS
CVE-2026-2441
Sfruttata Alta 8.8

Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

google chrome
0.22EPSS
CVE-2019-1297
Sfruttata Alta 8.8

A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'.

microsoft excel · microsoft office · microsoft office_365_proplus
0.22EPSS
CVE-2019-0903
Sfruttata Alta 8.8

A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1703 · microsoft windows_10_1709 · e altri 12
0.22EPSS
CVE-2021-34484
Sfruttata Alta 7.8

Windows User Profile Service Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_1909 · e altri 12
0.22EPSS
CVE-2023-20269
Ransomware Media 5.0

A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify val…

cisco adaptive_security_appliance_software · cisco secure_firewall_threat_defense
0.22EPSS
CVE-2017-6742
Sfruttata Alta 8.8

A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute code. An attacker could exploit this vulnerability by sending a crafted SNMP packet to the affected devi…

cisco ios · cisco ios_xe
0.21EPSS
CVE-2025-30397
Sfruttata Alta 7.5

Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 11
0.21EPSS
CVE-2012-1854
Sfruttata Alta 7.8

Untrusted search path vulnerability in VBE6.dll in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Microsoft Visual Basic for Applications (VBA); and Summit Microsoft Visual Basic for Applications SDK allows local users to gain privileges v…

microsoft office · microsoft visual_basic_for_applications · microsoft visual_basic_for_applications_sdk
0.21EPSS
CVE-2023-36563
Sfruttata Media 6.5

Microsoft WordPad Information Disclosure Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 8
0.21EPSS
CVE-2016-3309
Ransomware Alta 7.8

The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted appl…

microsoft windows_10_1507 · microsoft windows_10_1511 · microsoft windows_10_1607 · microsoft windows_7 · e altri 5
0.21EPSS
CVE-2024-7971
Sfruttata Critica 9.6

Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

google chrome · microsoft edge
0.21EPSS
CVE-2014-9163
Sfruttata Alta 7.8

Stack-based buffer overflow in Adobe Flash Player before 13.0.0.259 and 14.x and 15.x before 15.0.0.246 on Windows and OS X and before 11.2.202.425 on Linux allows attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in Decembe…

adobe flash_player
0.20EPSS
CVE-2021-31956
Sfruttata Alta 7.8

Windows NTFS Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_1909 · e altri 12
0.20EPSS
CVE-2016-4171
Sfruttata Critica 9.8

Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in June 2016.

adobe flash_player · opensuse opensuse · redhat enterprise_linux_desktop · redhat enterprise_linux_server · e altri 3
0.20EPSS
CVE-2021-41379
Ransomware Media 5.5

Windows Installer Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_1909 · e altri 14
0.20EPSS
CVE-2014-8439
Sfruttata Alta 8.8

Adobe Flash Player before 13.0.0.258 and 14.x and 15.x before 15.0.0.239 on Windows and OS X and before 11.2.202.424 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allow attackers to execu…

adobe air · adobe air_sdk · adobe air_sdk_\&_compiler · adobe flash_player
0.20EPSS