imPC@ndo EN

Vulnerabilità sfruttate attivamente

770 CVE

CVE-2002-0367
Sfruttata Alta 7.8

smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstr…

microsoft windows_2000 · microsoft windows_nt
0.05EPSS
CVE-2009-1123
Sfruttata Alta 7.8

The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application, ak…

microsoft windows_2000 · microsoft windows_server_2003 · microsoft windows_server_2008 · microsoft windows_vista · e altri 1
0.05EPSS
CVE-2023-41179
Sfruttata Alta 7.2

A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security and Worry-Free Business Security Services could allow an attacker to manipulate the module to execute arbitrary commands o…

trendmicro apex_one · trendmicro worry-free_business_security · trendmicro worry-free_business_security_services
0.05EPSS
CVE-2020-1631
Sfruttata Alta 8.8

A vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirect, and Zero Touch Provisioning (ZTP) allows an unauthenticated attacker to perform local file inclusion (LFI) …

juniper junos
0.05EPSS
CVE-2019-0543
Ransomware Alta 7.8

An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka "Microsoft Windows Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows S…

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1703 · microsoft windows_10_1709 · e altri 11
0.05EPSS
CVE-2004-1464
Sfruttata Media 5.9

Cisco IOS 12.2(15) and earlier allows remote attackers to cause a denial of service (refused VTY (virtual terminal) connections), via a crafted TCP connection to the Telnet or reverse Telnet port.

cisco ios
0.05EPSS
CVE-2018-0161
Sfruttata Media 6.3

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain models of Cisco Catalyst Switches could allow an authenticated, remote attacker to cause a denial of service (DoS) condition, aka a GET MIB Obje…

cisco ios
0.05EPSS
CVE-2025-60710
Sfruttata Alta 7.8

Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.

microsoft windows_11_24h2 · microsoft windows_11_25h2 · microsoft windows_server_2025
0.05EPSS
CVE-2020-1027
Sfruttata Alta 7.8

An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0913, CVE-2020-1000, CVE-2020-1003.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1709 · microsoft windows_10_1803 · e altri 13
0.05EPSS
CVE-2021-31979
Sfruttata Alta 7.8

Windows Kernel Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_1909 · e altri 12
0.05EPSS
CVE-2022-2856
Sfruttata Media 6.5

Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker to arbitrarily browse to a malicious website via a crafted HTML page.

fedoraproject fedora · google chrome
0.05EPSS
CVE-2023-46748
Sfruttata Alta 8.8

An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which may allow an authenticated attacker with network access to the Configuration utility through the BIG-IP management port and/or self IP addresses to execute arbitrar…

f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · f5 big-ip_advanced_web_application_firewall · f5 big-ip_analytics · e altri 16
0.04EPSS
CVE-2020-2021
Ransomware Critica 10.0

When Security Assertion Markup Language (SAML) authentication is enabled and the 'Validate Identity Provider Certificate' option is disabled (unchecked), improper verification of signatures in PAN-OS SAML authentication enables an unauthenticated network-based…

paloaltonetworks pan-os
0.04EPSS
CVE-2026-20045
Sfruttata Alta 8.2

A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unity Connection…

cisco unified_communications_manager · cisco unified_communications_manager_im_and_presence_service · cisco unity_connection
0.04EPSS
CVE-2024-20399
Sfruttata Media 6.0

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession of Administrator credentials to execute arbitrary commands as root on the underlying operating system of an affected device. This vulnerability is due to insu…

cisco nx-os
0.04EPSS
CVE-2018-8611
Sfruttata Alta 7.8

An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "Windows Kernel Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, W…

microsoft windows_10_1607 · microsoft windows_10_1703 · microsoft windows_10_1709 · microsoft windows_10_1803 · e altri 8
0.04EPSS
CVE-2023-32049
Sfruttata Alta 8.8

Windows SmartScreen Security Feature Bypass Vulnerability

microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · microsoft windows_10_22h2 · e altri 5
0.04EPSS
CVE-2019-0859
Sfruttata Alta 7.8

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0685, CVE-2019-0803.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1703 · microsoft windows_10_1709 · e altri 11
0.04EPSS
CVE-2025-54313
Sfruttata Alta 7.5

eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.

alexghr got-fetch · homarr homarr · prettier eslint-config-prettier · prettier eslint-plugin-prettier · e altri 3
0.04EPSS
CVE-2015-1769
Sfruttata Media 6.6

Mount Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 mishandles symlinks, which allows physically proximate attackers t…

microsoft windows_10 · microsoft windows_7 · microsoft windows_8 · microsoft windows_8.1 · e altri 5
0.04EPSS
CVE-2021-36955
Ransomware Alta 7.8

Windows Common Log File System Driver Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_1909 · e altri 13
0.04EPSS
CVE-2025-47827
Sfruttata Media 4.6

In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a crafted root filesystem can be mounted from an unverified SquashFS image.

igel igel_os · microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · e altri 12
0.04EPSS
CVE-2024-26169
Ransomware Alta 7.8

Windows Error Reporting Service Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 10
0.04EPSS
CVE-2024-30040
Sfruttata Alta 8.8

Windows MSHTML Platform Security Feature Bypass Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 8
0.04EPSS
CVE-2025-24472
Ransomware Alta 8.1

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior knowledge of upstream an…

fortinet fortios · fortinet fortiproxy
0.04EPSS