imPC@ndo EN

CVE Tracker

56.413 CVE

CVE-2021-31196
Sfruttata Alta 7.2

Microsoft Exchange Server Remote Code Execution Vulnerability

microsoft exchange_server
0.54EPSS
CVE-2022-21971
Sfruttata Alta 7.8

Windows Runtime Remote Code Execution Vulnerability

microsoft windows_10_1809 · microsoft windows_10_1909 · microsoft windows_10_20h2 · microsoft windows_10_21h1 · e altri 5
0.54EPSS
CVE-2021-22941
Ransomware Critica 9.8

Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compromise the storage zones controller.

citrix sharefile_storagezones_controller
0.54EPSS
CVE-2019-0808
Sfruttata Alta 7.8

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0797.

microsoft windows_7 · microsoft windows_server_2008
0.53EPSS
CVE-2015-1642
Sfruttata Alta 7.8

Microsoft Office 2007 SP3, 2010 SP2, and 2013 SP1 allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."

microsoft office
0.53EPSS
CVE-2019-0541
Sfruttata Alta 8.8

A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Office Word Viewer, Internet Explorer 9, Internet Explo…

microsoft excel_viewer · microsoft internet_explorer · microsoft office · microsoft office_365_proplus · e altri 1
0.53EPSS
CVE-2012-2539
Sfruttata Alta 7.8

Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1; Word Viewer; Office Compatibility Pack SP2 and SP3; and Office Web Apps 2010 SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted RTF data, ak…

microsoft office_compatibility_pack · microsoft office_web_apps · microsoft office_word_viewer · microsoft sharepoint_server · e altri 1
0.53EPSS
CVE-2020-1054
Sfruttata Alta 7.8

An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1143.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1709 · microsoft windows_10_1803 · e altri 13
0.53EPSS
CVE-2019-13272
Sfruttata Alta 7.8

In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows local users to obtain root access by leveraging certain scenarios with a parent-…

canonical ubuntu_linux · debian debian_linux · fedoraproject fedora · linux linux_kernel · e altri 18
0.52EPSS
CVE-2024-43461
Sfruttata Alta 8.8

Windows MSHTML Platform Spoofing Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 11
0.52EPSS
CVE-2021-28550
Sfruttata Alta 8.8

Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by a Use After Free vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary c…

adobe acrobat · adobe acrobat_dc · adobe acrobat_reader · adobe acrobat_reader_dc
0.52EPSS
CVE-2009-1537
Sfruttata Alta 8.8

Unspecified vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 allows remote attackers to execute arbitrary code via a cr…

microsoft directx · microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_server_2003 · e altri 1
0.51EPSS
CVE-2024-38094
Ransomware Alta 7.2

Microsoft SharePoint Remote Code Execution Vulnerability

microsoft sharepoint_server
0.51EPSS
CVE-2021-20023
Ransomware Media 4.9

SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host.

sonicwall email_security · sonicwall email_security_appliance_3300_firmware · sonicwall email_security_appliance_4300_firmware · sonicwall email_security_appliance_5000_firmware · e altri 7
0.50EPSS
CVE-2020-12812
Ransomware Critica 9.8

An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of authentication (FortiToken) if they changed the case of…

fortinet fortios
0.49EPSS
CVE-2021-22017
Sfruttata Media 5.3

Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to bypass proxy leading to internal endpoints being acc…

vmware vcenter_server
0.49EPSS
CVE-2023-5217
Sfruttata Alta 8.8

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

apple ipados · apple iphone_os · debian debian_linux · fedoraproject fedora · e altri 7
0.49EPSS
CVE-2023-28252
Ransomware Alta 7.8

Windows Common Log File System Driver Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_20h2 · e altri 9
0.49EPSS
CVE-2020-16009
Sfruttata Alta 8.8

Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

cefsharp cefsharp · debian debian_linux · fedoraproject fedora · google chrome · e altri 4
0.49EPSS
CVE-2020-9715
Sfruttata Alta 7.8

Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution .

adobe acrobat_dc · adobe acrobat_reader_dc
0.48EPSS
CVE-2006-2492
Sfruttata Alta 8.8

Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allows user-assisted attackers to execute arbitrary code via a malformed object pointer, as originally reported by ISC on 200…

microsoft office · microsoft works_suite
0.48EPSS
CVE-2011-1889
Sfruttata Critica 9.8

The NSPLookupServiceNext function in the client in Microsoft Forefront Threat Management Gateway (TMG) 2010 allows remote attackers to execute arbitrary code via vectors involving unspecified requests, aka "TMG Firewall Client Memory Corruption Vulnerability."…

microsoft forefront_threat_management_gateway
0.48EPSS
CVE-2021-26829
Sfruttata Media 5.4

OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm.

scadabr scadabr
0.48EPSS
CVE-2013-2094
Sfruttata Alta 8.4

The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows local users to gain privileges via a crafted perf_event_open system call.

linux linux_kernel
0.48EPSS
CVE-2014-4077
Sfruttata Alta 7.8

Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Office 2007 SP3, when IMJPDCT.EXE (aka IME for Japanese) is installed, allow remote attackers to bypass a sandbox protection mechanism via a crafted PD…

microsoft office_2007_ime · microsoft windows_7 · microsoft windows_server_2003 · microsoft windows_server_2008 · e altri 1
0.48EPSS