imPC@ndo EN

Vulnerabilità sfruttate attivamente

770 CVE

CVE-2021-22986
Ransomware Critica 9.8

On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2, the iControl REST interface has an unauthenticated remote …

f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · f5 big-ip_advanced_web_application_firewall · f5 big-ip_analytics · e altri 11
1.00EPSS
CVE-2018-0296
Sfruttata Alta 7.5

A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. It is also possible on cer…

cisco adaptive_security_appliance_software · cisco firepower_threat_defense · cisco secure_firewall_threat_defense
1.00EPSS
CVE-2014-0497
Sfruttata Critica 9.8

Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors.

adobe flash_player · google chrome · opensuse opensuse · redhat enterprise_linux_desktop · e altri 5
1.00EPSS
CVE-2025-49706
Ransomware Media 6.5

Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

microsoft sharepoint_enterprise_server · microsoft sharepoint_server
1.00EPSS
CVE-2019-1653
Sfruttata Alta 7.5

A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to retrieve sensitive information. The vulnerability is due to improper access controls f…

cisco rv320_firmware · cisco rv325_firmware
1.00EPSS
CVE-2019-0604
Ransomware Critica 9.8

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0594.

microsoft sharepoint_enterprise_server · microsoft sharepoint_foundation · microsoft sharepoint_server
1.00EPSS
CVE-2017-7269
Sfruttata Critica 9.8

Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to execute arbitrary code via a long header beginning with "If: <http://" in a PRO…

microsoft internet_information_services
1.00EPSS
CVE-2020-0796
Ransomware Critica 10.0

A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'.

microsoft windows_10_1903 · microsoft windows_10_1909 · microsoft windows_server_1903 · microsoft windows_server_1909
1.00EPSS
CVE-2021-34527
Ransomware Alta 8.8

A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could the…

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_20h2 · e altri 11
1.00EPSS
CVE-2021-31207
Ransomware Media 6.6

Microsoft Exchange Server Security Feature Bypass Vulnerability

microsoft exchange_server
1.00EPSS
CVE-2020-13927
Sfruttata Critica 9.8

The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to users who miss this fact. From Airflow 1.10.11 the default has been changed to deny all requests by default and i…

apache airflow
1.00EPSS
CVE-2023-4863
Sfruttata Alta 8.8

Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)

bandisoft honeyview · bentley seequent_leapfrog · debian debian_linux · fedoraproject fedora · e altri 8
1.00EPSS
CVE-2023-3519
Ransomware Critica 9.8

Unauthenticated remote code execution

citrix netscaler_application_delivery_controller · citrix netscaler_gateway
1.00EPSS
CVE-2024-0012
Ransomware Critica 9.8

An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or …

paloaltonetworks pan-os
1.00EPSS
CVE-2017-0147
Ransomware Alta 7.5

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to obtain sen…

microsoft windows_10_1507 · microsoft windows_10_1511 · microsoft windows_10_1607 · microsoft windows_7 · e altri 14
1.00EPSS
CVE-2022-22965
Sfruttata Critica 9.8

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot …

cisco cx_cloud_agent · oracle commerce_platform · oracle communications_cloud_native_core_automated_test_suite · oracle communications_cloud_native_core_binding_support_function · e altri 34
1.00EPSS
CVE-2021-31166
Sfruttata Critica 9.8

HTTP Protocol Stack Remote Code Execution Vulnerability

microsoft windows_10_2004 · microsoft windows_10_20h2 · microsoft windows_server_2004 · microsoft windows_server_20h2
1.00EPSS
CVE-2023-46604
Ransomware Critica 10.0

The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary shell commands by manipulating serialized clas…

apache activemq · apache activemq_legacy_openwire_module · debian debian_linux · netapp e-series_santricity_unified_manager · e altri 2
1.00EPSS
CVE-2023-29357
Ransomware Critica 9.8

Microsoft SharePoint Server Elevation of Privilege Vulnerability

microsoft sharepoint_server
1.00EPSS
CVE-2024-9465
Sfruttata Critica 9.1

An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and …

paloaltonetworks expedition
1.00EPSS
CVE-2017-12615
Ransomware Alta 8.1

When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could the…

apache tomcat · netapp 7-mode_transition_tool · netapp oncommand_balance · netapp oncommand_shift · e altri 18
1.00EPSS
CVE-2023-20198
Sfruttata Critica 10.0

Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating the list of fixed releases and adding the Software Checker. Our investigation has determined that the actors e…

cisco ios_xe · rockwellautomation allen-bradley_stratix_5200_firmware · rockwellautomation allen-bradley_stratix_5800_firmware
1.00EPSS
CVE-2021-21972
Ransomware Critica 9.8

The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system t…

vmware cloud_foundation · vmware vcenter_server
1.00EPSS
CVE-2020-1472
Ransomware Media 5.5

An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vulnerability could run…

canonical ubuntu_linux · debian debian_linux · fedoraproject fedora · microsoft windows_server_1903 · e altri 11
1.00EPSS
CVE-2018-0171
Sfruttata Critica 9.8

A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition, or to execute arbitrary co…

cisco ios
0.99EPSS