imPC@ndo EN

Vulnerabilità sfruttate attivamente

770 CVE

CVE-2022-42475
Ransomware Critica 9.8

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier and FortiProxy SSL-VPN 7.2.0 through 7.2.1, 7.0.7 and earlier may allow a remote u…

fortinet fortios · fortinet fortiproxy
0.99EPSS
CVE-2024-32113
Sfruttata Critica 9.8

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 18.12.13. Users are recommended to upgrade to version 18.12.13, which fixes the issue.

apache ofbiz
0.99EPSS
CVE-2023-34048
Sfruttata Critica 9.8

vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds write potentially leading to remote code execution.

vmware vcenter_server
0.99EPSS
CVE-2024-38856
Sfruttata Critica 9.8

Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to version 18.12.15, which fixes the issue. Unauthenticated endpoints could allow execution of screen rendering code o…

apache ofbiz
0.99EPSS
CVE-2017-9805
Sfruttata Alta 8.1

The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payload…

apache struts · cisco digital_media_manager · cisco hosted_collaboration_solution · cisco media_experience_engine · e altri 3
0.99EPSS
CVE-2022-30190
Ransomware Alta 7.8

A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the privileges of the calling application. The…

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_20h2 · e altri 12
0.99EPSS
CVE-2017-0148
Ransomware Alta 8.1

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute ar…

microsoft server_message_block · siemens acuson_p300_firmware · siemens acuson_p500_firmware · siemens acuson_sc2000_firmware · e altri 5
0.99EPSS
CVE-2015-5119
Sfruttata Critica 9.8

Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows and OS X and 11.x through 11.2.202.468 on Linux allows remote attackers to execu…

adobe flash_player · opensuse evergreen · opensuse opensuse · redhat enterprise_linux_desktop · e altri 7
0.99EPSS
CVE-2020-1938
Sfruttata Critica 9.8

When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attac…

apache geode · apache tomcat · blackberry good_control · blackberry workspaces_server · e altri 17
0.99EPSS
CVE-2017-0144
Ransomware Alta 8.8

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute ar…

microsoft server_message_block · siemens acuson_p300_firmware · siemens acuson_p500_firmware · siemens acuson_sc2000_firmware · e altri 5
0.99EPSS
CVE-2020-0646
Sfruttata Critica 9.8

A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code Execution Injection Vulnerability'.

microsoft .net_framework
0.99EPSS
CVE-2024-27348
Sfruttata Critica 9.8

RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & Java11 Users are recommended to upgrade to version 1.3.0 with Java11 & enable the Auth system, which fixes the…

apache hugegraph
0.99EPSS
CVE-2020-11978
Sfruttata Alta 8.8

An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow which would allow any authenticated user to run arbitrary commands as the user running…

apache airflow
0.99EPSS
CVE-2022-30333
Ransomware Alta 7.5

RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected.

debian debian_linux · rarlab unrar
0.99EPSS
CVE-2020-0618
Sfruttata Alta 8.8

A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'.

microsoft sql_server
0.99EPSS
CVE-2017-3881
Sfruttata Critica 9.8

A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely execute code with elevated privileges. The…

cisco ios · cisco ios_xe
0.99EPSS
CVE-2023-36884
Ransomware Alta 7.5

Windows Search Remote Code Execution Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 8
0.99EPSS
CVE-2017-9791
Sfruttata Critica 9.8

The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.

apache struts
0.99EPSS
CVE-2008-4250
Sfruttata Critica 9.8

The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that triggers the overflow during path canoni…

microsoft windows_2000 · microsoft windows_server_2003 · microsoft windows_server_2008 · microsoft windows_vista · e altri 1
0.99EPSS
CVE-2024-29059
Sfruttata Alta 7.5

.NET Framework Information Disclosure Vulnerability

microsoft .net_framework
0.99EPSS
CVE-2025-32433
Sfruttata Critica 10.0

Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protoco…

cisco cloud_native_broadband_network_gateway · cisco confd_basic · cisco enterprise_nfv_infrastructure_software · cisco inode_manager · e altri 19
0.99EPSS
CVE-2019-17558
Sfruttata Alta 7.5

Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provided through Velocity templates in a configset `velocity/` directory or as a parameter. A user defined configset…

apache solr · oracle primavera_unifier
0.99EPSS
CVE-2016-3088
Sfruttata Critica 9.8

The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.

apache activemq
0.99EPSS
CVE-2024-9463
Sfruttata Alta 7.5

An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys …

paloaltonetworks expedition
0.98EPSS
CVE-2025-0108
Sfruttata Critica 9.1

An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authentication otherwise required by the PAN-OS management web interface and invoke certain…

paloaltonetworks pan-os
0.98EPSS