imPC@ndo EN

Vulnerabilità sfruttate attivamente

770 CVE

CVE-2022-41328
Sfruttata Media 6.7

A improper limitation of a pathname to a restricted directory vulnerability ('path traversal') [CWE-22] in Fortinet FortiOS version 7.2.0 through 7.2.3, 7.0.0 through 7.0.9 and before 6.4.11 allows a privileged attacker to read and write files on the underlyin…

fortinet fortios
0.12EPSS
CVE-2020-3118
Sfruttata Alta 8.8

A vulnerability in the Cisco Discovery Protocol implementation for Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to execute arbitrary code or cause a reload on an affected device. The vulnerability is due to improper validation of str…

cisco ios_xr
0.12EPSS
CVE-2019-1253
Ransomware Alta 7.8

An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Elevation of Privilege Vulnerab…

microsoft windows_10_1703 · microsoft windows_10_1709 · microsoft windows_10_1803 · microsoft windows_10_1809 · e altri 4
0.12EPSS
CVE-2021-38648
Sfruttata Alta 7.8

Open Management Infrastructure Elevation of Privilege Vulnerability

microsoft azure_automation_state_configuration · microsoft azure_automation_update_management · microsoft azure_diagnostics_\(lad\) · microsoft azure_open_management_infrastructure · e altri 7
0.11EPSS
CVE-2013-0648
Sfruttata Alta 8.8

Unspecified vulnerability in the ExternalInterface ActionScript functionality in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x before 11.2.202.273 on Linux, allows remote attackers t…

adobe flash_player · opensuse opensuse · redhat enterprise_linux_desktop · redhat enterprise_linux_eus · e altri 4
0.11EPSS
CVE-2017-0005
Sfruttata Alta 7.8

The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a…

microsoft windows_10_1507 · microsoft windows_10_1511 · microsoft windows_10_1607 · microsoft windows_7 · e altri 6
0.11EPSS
CVE-2015-2546
Ransomware Alta 8.2

The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted appli…

microsoft windows_10_1507 · microsoft windows_7 · microsoft windows_8 · microsoft windows_8.1 · e altri 5
0.11EPSS
CVE-2023-23376
Ransomware Alta 7.8

Windows Common Log File System Driver Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_20h2 · e altri 9
0.11EPSS
CVE-2022-26925
Sfruttata Alta 8.1

Windows LSA Spoofing Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_1909 · e altri 13
0.11EPSS
CVE-2017-6740
Sfruttata Alta 8.8

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. …

cisco ios · cisco ios_xe
0.11EPSS
CVE-2017-1000253
Ransomware Alta 7.8

Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committed on April 14, 2015). This kernel vulnerability was fixed in April 2015 by commit a87938b2e246b81b4fb713edb371…

centos centos · linux linux_kernel · redhat enterprise_linux
0.11EPSS
CVE-2017-6743
Sfruttata Alta 8.8

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. …

cisco ios · cisco ios_xe
0.11EPSS
CVE-2017-6739
Sfruttata Alta 8.8

A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute code. An attacker could exploit this vulnerability by sending a crafted SNMP packet to the affected devi…

cisco ios · cisco ios_xe
0.11EPSS
CVE-2017-6738
Sfruttata Alta 8.8

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. …

cisco ios · cisco ios_xe
0.11EPSS
CVE-2013-0643
Sfruttata Alta 8.8

The Firefox sandbox in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x before 11.2.202.273 on Linux, does not properly restrict privileges, which makes it easier for remote attackers t…

adobe flash_player · opensuse opensuse · redhat enterprise_linux_desktop · redhat enterprise_linux_eus · e altri 4
0.11EPSS
CVE-2022-2586
Sfruttata Media 5.3

It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted.

canonical ubuntu_linux · linux linux_kernel
0.10EPSS
CVE-2021-43890
Ransomware Alta 7.1

We have investigated reports of a spoofing vulnerability in AppX installer that affects Microsoft Windows. Microsoft is aware of attacks that attempt to exploit this vulnerability by using specially crafted packages that include the malware family known as Emo…

microsoft app_installer
0.10EPSS
CVE-2021-33771
Sfruttata Alta 7.8

Windows Kernel Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_1909 · e altri 10
0.10EPSS
CVE-2025-6543
Sfruttata Critica 9.8

Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server

citrix netscaler_application_delivery_controller · citrix netscaler_gateway
0.10EPSS
CVE-2023-32046
Sfruttata Alta 7.8

Windows MSHTML Platform Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 8
0.10EPSS
CVE-2020-3433
Ransomware Alta 7.8

A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack. To exploit this vulnerability, the attacker would need to hav…

cisco anyconnect_secure_mobility_client
0.10EPSS
CVE-2017-0263
Sfruttata Alta 7.8

The kernel-mode drivers in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow local users to gain privileges via a crafted …

microsoft windows_10_1507 · microsoft windows_10_1511 · microsoft windows_10_1607 · microsoft windows_10_1703 · e altri 6
0.10EPSS
CVE-2025-21333
Sfruttata Alta 7.8

Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability

microsoft windows_10_21h2 · microsoft windows_10_22h2 · microsoft windows_11_22h2 · microsoft windows_11_23h2 · e altri 3
0.10EPSS
CVE-2024-38217
Sfruttata Media 5.4

Windows Mark of the Web Security Feature Bypass Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 11
0.10EPSS
CVE-2022-26904
Sfruttata Alta 7.0

Windows User Profile Service Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_1909 · e altri 13
0.10EPSS