imPC@ndo EN

Vulnerabilità sfruttate attivamente

770 CVE

CVE-2020-17530
Sfruttata Critica 9.8

Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25.

apache struts · oracle business_intelligence · oracle communications_diameter_intelligence_hub · oracle communications_policy_management · e altri 4
0.96EPSS
CVE-2020-5410
Sfruttata Alta 7.5

Spring Cloud Config, versions 2.2.x prior to 2.2.3, versions 2.1.x prior to 2.1.9, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a…

vmware spring_cloud_config
0.96EPSS
CVE-2024-21412
Ransomware Alta 8.1

Internet Shortcut Files Security Feature Bypass Vulnerability

microsoft windows_10_1809 · microsoft windows_10_21h2 · microsoft windows_10_22h2 · microsoft windows_11_21h2 · e altri 5
0.95EPSS
CVE-2014-6332
Sfruttata Alta 8.8

OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary co…

microsoft windows_7 · microsoft windows_8 · microsoft windows_8.1 · microsoft windows_rt · e altri 5
0.95EPSS
CVE-2024-47575
Sfruttata Critica 9.8

A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiManager 6.4.0 through 6.4.14, FortiManager 6.2.0 through 6.2.12, Fortinet FortiMan…

fortinet fortimanager · fortinet fortimanager_cloud
0.95EPSS
CVE-2024-9474
Ransomware Alta 7.2

A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access are not impacted by this…

paloaltonetworks pan-os
0.95EPSS
CVE-2023-24489
Sfruttata Critica 9.8

A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated attacker to remotely compromise the customer-managed ShareFile storage zones controller.

citrix sharefile_storage_zones_controller
0.95EPSS
CVE-2024-21413
Sfruttata Critica 9.8

Microsoft Outlook Remote Code Execution Vulnerability

microsoft 365_apps · microsoft office_2016 · microsoft office_2019 · microsoft office_long_term_servicing_channel
0.95EPSS
CVE-2025-8088
Ransomware Alta 8.8

A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and P…

dtsearch dtsearch · rarlab winrar
0.95EPSS
CVE-2020-1147
Sfruttata Alta 7.8

A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulner…

microsoft .net_core · microsoft .net_framework · microsoft sharepoint_enterprise_server · microsoft sharepoint_server · e altri 2
0.94EPSS
CVE-2011-0611
Sfruttata Alta 8.8

Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader 9.x before 9.4.4 and 10.x through 10.0.1 on Windows, Ad…

adobe acrobat · adobe acrobat_reader · adobe adobe_air · adobe flash_player · e altri 3
0.94EPSS
CVE-2019-12989
Sfruttata Critica 9.8

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.

citrix netscaler_sd-wan · citrix sd-wan
0.94EPSS
CVE-2023-36846
Sfruttata Media 5.3

A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to user.php that doesn't …

juniper junos
0.94EPSS
CVE-2026-21643
Sfruttata Critica 9.8

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.

fortinet forticlientems
0.94EPSS
CVE-2021-26857
Ransomware Alta 7.8

Microsoft Exchange Server Remote Code Execution Vulnerability

microsoft exchange_server
0.94EPSS
CVE-2026-0257
Ransomware Critica 9.1

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by …

paloaltonetworks pan-os · paloaltonetworks prisma_access · siemens ruggedcom_ape1808_firmware
0.94EPSS
CVE-2013-0625
Sfruttata Critica 9.8

Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly execute arbitrary code via unspecified vectors, as exploited in the wild in January 2013.

adobe coldfusion
0.94EPSS
CVE-2016-0189
Sfruttata Alta 7.5

The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scr…

microsoft internet_explorer · microsoft jscript · microsoft vbscript
0.94EPSS
CVE-2015-5122
Sfruttata Critica 9.8

Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x thro…

adobe flash_player · adobe flash_player_desktop_runtime · opensuse evergreen · redhat enterprise_linux_desktop · e altri 5
0.94EPSS
CVE-2023-36845
Sfruttata Critica 9.8

A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series and SRX Series allows an unauthenticated, network-based attacker to remotely execute code. Using a crafted request which sets the variable PHPRC an attac…

juniper junos
0.94EPSS
CVE-2017-0143
Ransomware Alta 8.8

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute ar…

microsoft server_message_block · philips intellispace_portal · siemens acuson_p300_firmware · siemens acuson_p500_firmware · e altri 6
0.93EPSS
CVE-2022-33891
Sfruttata Alta 8.8

The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the application. If ACLs are enabled, a code path in Ht…

apache spark
0.93EPSS
CVE-2016-4437
Sfruttata Critica 9.8

Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.

apache aurora · apache shiro · redhat fuse · redhat jboss_middleware_text-only_advisories
0.93EPSS
CVE-2015-1641
Sfruttata Alta 7.8

Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2 and 2013 SP1, and Office Web Apps Server 2010 SP2 and 2013 SP1 al…

microsoft office · microsoft office_compatibility_pack · microsoft office_web_apps · microsoft outlook · e altri 2
0.93EPSS
CVE-2022-24706
Sfruttata Critica 9.8

In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly securing an installation, including rec…

apache couchdb
0.92EPSS