imPC@ndo EN

CVE Tracker

56.413 CVE

CVE-2017-6663
Sfruttata Media 6.5

A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause autonomic nodes of an affected system to reload, resulting in a denial of service (DoS) condition. Mo…

cisco ios · cisco ios_xe
0.02EPSS
CVE-2025-3928
Sfruttata Alta 8.8

Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory: "Webservers can be compromised through bad actors creating and executing webshells." Fixed in version 11.36.46…

commvault commvault
0.02EPSS
CVE-2021-41357
Sfruttata Alta 7.8

Win32k Elevation of Privilege Vulnerability

microsoft windows_10_2004 · microsoft windows_10_20h2 · microsoft windows_10_21h1 · microsoft windows_11_21h2 · e altri 3
0.02EPSS
CVE-2021-40450
Sfruttata Alta 7.8

Win32k Elevation of Privilege Vulnerability

microsoft windows_10_1809 · microsoft windows_10_1909 · microsoft windows_10_2004 · microsoft windows_10_20h2 · e altri 6
0.02EPSS
CVE-2017-12238
Sfruttata Media 6.5

A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS 15.0 through 15.4 for Cisco Catalyst 6800 Series Switches could allow an unauthenticated, adjacent attacker to cause a C6800-16P10G or C6800-16P10G-XL type line card to crash, resultin…

cisco ios
0.02EPSS
CVE-2026-3910
Sfruttata Alta 8.8

Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

google chrome
0.02EPSS
CVE-2025-24991
Sfruttata Media 5.5

Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 11
0.02EPSS
CVE-2022-41091
Ransomware Media 5.4

Windows Mark of the Web Security Feature Bypass Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_20h2 · e altri 8
0.02EPSS
CVE-2025-24984
Sfruttata Media 4.6

Insertion of sensitive information into log file in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 10
0.02EPSS
CVE-2025-0111
Sfruttata Media 6.5

An authenticated file read vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker with network access to the management web interface to read files on the PAN-OS filesystem that are readable by the “nobody” user. You can gre…

paloaltonetworks pan-os
0.02EPSS
CVE-2019-0797
Sfruttata Alta 7.8

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0808.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1703 · microsoft windows_10_1709 · e altri 9
0.02EPSS
CVE-2019-1129
Ransomware Alta 7.8

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1130.

microsoft windows_10_1703 · microsoft windows_10_1709 · microsoft windows_10_1803 · microsoft windows_10_1809 · e altri 4
0.02EPSS
CVE-2024-7262
Sfruttata Alta 7.8

Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.16412 (exclusive) on Windows allows an attacker to load an arbitrary Windows library. The vulnerability was found weaponized as a single-click…

kingsoft wps_office
0.02EPSS
CVE-2025-30400
Sfruttata Alta 7.8

Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.

microsoft windows_10_1809 · microsoft windows_10_21h2 · microsoft windows_10_22h2 · microsoft windows_11_22h2 · e altri 6
0.02EPSS
CVE-2023-28229
Sfruttata Alta 7.0

Windows CNG Key Isolation Service Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_20h2 · e altri 9
0.02EPSS
CVE-2025-22226
Sfruttata Alta 7.1

VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit this issue to leak memory from the vmx proce…

vmware cloud_foundation · vmware esxi · vmware fusion · vmware telco_cloud_infrastructure · e altri 2
0.02EPSS
CVE-2025-24989
Sfruttata Alta 8.2

An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control. This vulnerability has already been mitigated in the service and all affected cust…

microsoft power_pages
0.02EPSS
CVE-2025-21590
Sfruttata Media 4.4

An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to compromise the integrity of the device. A local attacker with access to the shell is able to inject arbitrar…

juniper junos
0.02EPSS
CVE-2022-41033
Sfruttata Alta 7.8

Windows COM+ Event System Service Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_20h2 · e altri 12
0.02EPSS
CVE-2025-32709
Sfruttata Alta 7.8

Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 11
0.02EPSS
CVE-2024-38107
Sfruttata Alta 7.8

Windows Power Dependency Coordinator Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 10
0.02EPSS
CVE-2026-3909
Sfruttata Alta 8.8

Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

google chrome
0.02EPSS
CVE-2025-22224
Sfruttata Critica 9.3

VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual mach…

vmware cloud_foundation · vmware esxi · vmware telco_cloud_infrastructure · vmware telco_cloud_platform · e altri 1
0.02EPSS
CVE-2025-21334
Sfruttata Alta 7.8

Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability

microsoft windows_10_21h2 · microsoft windows_10_22h2 · microsoft windows_11_22h2 · microsoft windows_11_23h2 · e altri 3
0.02EPSS
CVE-2025-21418
Sfruttata Alta 7.8

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · microsoft windows_10_22h2 · e altri 10
0.02EPSS