imPC@ndo EN

Vulnerabilità sfruttate attivamente

770 CVE

CVE-2026-21533
Sfruttata Alta 7.8

Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.

microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · microsoft windows_10_22h2 · e altri 9
0.04EPSS
CVE-2025-24985
Sfruttata Alta 7.8

Integer overflow or wraparound in Windows Fast FAT Driver allows an unauthorized attacker to execute code locally.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 11
0.04EPSS
CVE-2021-27085
Sfruttata Alta 8.8

Internet Explorer Remote Code Execution Vulnerability

microsoft internet_explorer
0.04EPSS
CVE-2023-0266
Sfruttata Alta 7.9

A use after free vulnerability exists in the ALSA PCM package in the Linux Kernel. SNDRV_CTL_IOCTL_ELEM_{READ|WRITE}32 is missing locks that can be used in a use-after-free that can result in a priviledge escalation to gain ring0 access from the system user. W…

debian debian_linux · linux linux_kernel
0.04EPSS
CVE-2020-3566
Sfruttata Alta 8.6

A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to exhaust process memory of an affected device. The vulnerability is due to insufficient queue managemen…

cisco ios_xr
0.04EPSS
CVE-2019-1385
Ransomware Alta 7.8

An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability, an authenticated attacker would need to run a specially craf…

microsoft windows_10_1709 · microsoft windows_10_1803 · microsoft windows_10_1809 · microsoft windows_10_1903 · e altri 2
0.04EPSS
CVE-2024-53197
Sfruttata Alta 7.8

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices A bogus device can provide a bNumConfigurations value that exceeds the initial value used in usb_get_configur…

debian debian_linux · linux linux_kernel
0.04EPSS
CVE-2018-0175
Sfruttata Alta 8.0

Format String vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute …

cisco ios · cisco ios_xe · cisco ios_xr
0.04EPSS
CVE-2019-1315
Ransomware Alta 7.8

An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles hard links, aka 'Windows Error Reporting Manager Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1339, CVE-2019-1342.

microsoft windows_10_1607 · microsoft windows_10_1703 · microsoft windows_10_1709 · microsoft windows_10_1803 · e altri 9
0.03EPSS
CVE-2018-8406
Ransomware Alta 7.8

An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory, aka "DirectX Graphics Kernel Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 …

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1703 · microsoft windows_10_1709 · e altri 4
0.03EPSS
CVE-2018-8405
Ransomware Alta 7.8

An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory, aka "DirectX Graphics Kernel Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Wind…

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1703 · microsoft windows_10_1709 · e altri 7
0.03EPSS
CVE-2018-0167
Sfruttata Alta 8.8

Multiple Buffer Overflow vulnerabilities in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) conditio…

cisco ios · cisco ios_xe · cisco ios_xr
0.03EPSS
CVE-2013-2596
Sfruttata Alta 7.8

Integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9, as used in a certain Motorola build of Android 4.1.2 and other products, allows local users to create a read-write memory mapping for the entirety of kernel mem…

linux linux_kernel · motorola android
0.03EPSS
CVE-2009-2055
Sfruttata Media 5.9

Cisco IOS XR 3.4.0 through 3.8.1 allows remote attackers to cause a denial of service (session reset) via a BGP UPDATE message with an invalid attribute, as demonstrated in the wild on 17 August 2009.

cisco ios_xr
0.03EPSS
CVE-2020-3569
Sfruttata Alta 8.6

Multiple vulnerabilities in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to either immediately crash the Internet Group Management Protocol (IGMP) process or make it con…

cisco ios_xr
0.03EPSS
CVE-2024-53104
Sfruttata Alta 7.8

In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format This can lead to out of bounds writes since frames of this type were not taken into account when calculating…

debian debian_linux · linux linux_kernel
0.03EPSS
CVE-2023-6548
Sfruttata Media 5.5

Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execution on Management Interf…

citrix netscaler_application_delivery_controller · citrix netscaler_gateway
0.03EPSS
CVE-2021-27059
Sfruttata Alta 7.6

Microsoft Office Remote Code Execution Vulnerability

microsoft office
0.03EPSS
CVE-2017-0001
Sfruttata Alta 7.8

The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a…

microsoft windows_10_1507 · microsoft windows_10_1511 · microsoft windows_10_1607 · microsoft windows_7 · e altri 6
0.03EPSS
CVE-2021-43226
Sfruttata Alta 7.8

Windows Common Log File System Driver Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_1909 · e altri 15
0.03EPSS
CVE-2023-36584
Sfruttata Media 5.4

Windows Mark of the Web Security Feature Bypass Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1809 · microsoft windows_10_21h1 · microsoft windows_10_22h2 · e altri 7
0.03EPSS
CVE-2020-0638
Ransomware Alta 7.8

An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Update Notification Manager Elevation of Privilege …

microsoft windows_10_1709 · microsoft windows_10_1803 · microsoft windows_10_1809 · microsoft windows_10_1903 · e altri 5
0.03EPSS
CVE-2018-8589
Sfruttata Alta 7.8

An elevation of privilege vulnerability exists when Windows improperly handles calls to Win32k.sys, aka "Windows Win32k Elevation of Privilege Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2.

microsoft windows_7 · microsoft windows_server_2008
0.03EPSS
CVE-2022-41125
Sfruttata Alta 7.8

Windows CNG Key Isolation Service Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_20h2 · e altri 10
0.03EPSS
CVE-2021-31199
Sfruttata Media 5.2

Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_1909 · e altri 12
0.03EPSS