imPC@ndo EN

Vulnerabilità sfruttate attivamente

770 CVE

CVE-2019-1132
Sfruttata Alta 7.8

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.

microsoft windows_7 · microsoft windows_server_2008
0.10EPSS
CVE-2022-20701
Sfruttata Critica 10.0

Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization prot…

cisco rv340_firmware · cisco rv340w_firmware · cisco rv345_firmware · cisco rv345p_firmware
0.10EPSS
CVE-2026-41091
Sfruttata Alta 7.8

Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.

microsoft malware_protection_engine
0.10EPSS
CVE-2019-0703
Sfruttata Media 6.5

An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, aka 'Windows SMB Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0704, CVE-2019-0821.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1703 · microsoft windows_10_1709 · e altri 11
0.10EPSS
CVE-2021-34486
Sfruttata Alta 7.8

Windows Event Tracing Elevation of Privilege Vulnerability

microsoft windows_10_1809 · microsoft windows_10_1909 · microsoft windows_10_2004 · microsoft windows_10_20h2 · e altri 4
0.09EPSS
CVE-2022-20703
Sfruttata Critica 10.0

Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization prot…

cisco rv160_firmware · cisco rv160w_firmware · cisco rv260_firmware · cisco rv260p_firmware · e altri 5
0.09EPSS
CVE-2026-45659
Ransomware Alta 8.8

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

microsoft sharepoint_server
0.09EPSS
CVE-2015-2291
Ransomware Alta 7.8

(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a denial of service or possibly execute arbitrary code with kernel privileges via a crafted (a) 0x80862013, (b) 0x8…

intel ethernet_diagnostics_driver_iqvw32.sys · intel ethernet_diagnostics_driver_iqvw64.sys
0.09EPSS
CVE-2010-4398
Sfruttata Alta 7.8

Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges…

microsoft windows_7 · microsoft windows_server_2003 · microsoft windows_server_2008 · microsoft windows_vista · e altri 1
0.09EPSS
CVE-2019-1388
Ransomware Alta 7.8

An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user privileges, aka 'Windows Certificate Dialog Elevation of Privilege Vulnerability'.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1709 · microsoft windows_10_1803 · e altri 10
0.09EPSS
CVE-2022-23748
Sfruttata Alta 7.8

mDNSResponder.exe is vulnerable to DLL Sideloading attack. Executable improperly specifies how to load the DLL, from which folder and under what conditions. In these scenarios, a malicious attacker could be using the valid and legitimate executable to load mal…

audinate dante_application_library
0.09EPSS
CVE-2025-2783
Sfruttata Alta 8.3

Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker to perform a sandbox escape via a malicious file. (Chromium security severity: High)

google chrome
0.08EPSS
CVE-2021-28310
Sfruttata Alta 7.8

Win32k Elevation of Privilege Vulnerability

microsoft windows_10_1803 · microsoft windows_10_1809 · microsoft windows_10_1909 · microsoft windows_10_2004 · e altri 5
0.08EPSS
CVE-2018-0156
Sfruttata Alta 7.5

A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due t…

cisco ios · cisco ios_xe
0.08EPSS
CVE-2024-38189
Sfruttata Alta 8.8

Microsoft Project Remote Code Execution Vulnerability

microsoft 365_apps · microsoft office_2019 · microsoft office_long_term_servicing_channel · microsoft project_2016
0.08EPSS
CVE-2019-11634
Ransomware Critica 9.8

Citrix Workspace App before 1904 for Windows has Incorrect Access Control.

citrix receiver · citrix workspace
0.08EPSS
CVE-2021-38646
Ransomware Alta 7.8

Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability

microsoft 365_apps · microsoft office · microsoft office_2016 · microsoft office_2019
0.08EPSS
CVE-2025-41244
Sfruttata Alta 7.8

VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploi…

debian debian_linux · vmware aria_operations · vmware cloud_foundation · vmware cloud_foundation_operations · e altri 4
0.08EPSS
CVE-2023-0386
Sfruttata Alta 7.8

A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mappi…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · netapp h300s_firmware · e altri 4
0.08EPSS
CVE-2018-0172
Sfruttata Alta 8.6

A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulne…

cisco ios · cisco ios_xe
0.08EPSS
CVE-2012-2034
Sfruttata Alta 7.5

Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 10.3.183.20 and 11.x before 11.2.202.236 on Linux; before 11.1.111.10 on Android 2.x and 3.x; and before 11.1.115.9 on Android 4.x, and Adobe AIR before 3.3.0.36…

adobe air · adobe flash_player · opensuse opensuse · redhat enterprise_linux_desktop · e altri 5
0.08EPSS
CVE-2018-0155
Sfruttata Alta 8.6

A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches could allow an unauthenticated, remote attacker to cause a crash of the iosd process, causin…

cisco ios · cisco ios_xe
0.08EPSS
CVE-2020-0683
Sfruttata Alta 7.8

An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0686.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1709 · microsoft windows_10_1803 · e altri 13
0.08EPSS
CVE-2018-0174
Sfruttata Alta 8.6

A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulne…

cisco ios · cisco ios_xe
0.08EPSS
CVE-2018-0173
Sfruttata Alta 8.6

A vulnerability in the Cisco IOS Software and Cisco IOS XE Software function that restores encapsulated option 82 information in DHCP Version 4 (DHCPv4) packets could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in…

cisco ios · cisco ios_xe
0.08EPSS