imPC@ndo EN

CVE Tracker

56.413 CVE

CVE-2026-21514
Sfruttata Alta 7.8

Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally.

microsoft 365_apps · microsoft office_long_term_servicing_channel
0.02EPSS
CVE-2021-36742
Sfruttata Alta 7.8

A improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free Business Security 10.0 SP1 allows a local attacker to escalate privileges on affected installations. Please note: an attacker must first obta…

trendmicro apex_one · trendmicro officescan · trendmicro officescan_business_security · trendmicro worry-free_business_security
0.01EPSS
CVE-2026-8398
Sfruttata Critica 9.8

A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distributed from the legitimate website daemon-tools.cc between approximately April 8, 2026, and May 5, 2026. Attacker…

disc-soft daemon_tools
0.01EPSS
CVE-2019-1214
Sfruttata Alta 7.8

An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory, aka 'Windows Common Log File System Driver Elevation of Privilege Vulnerability'.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1703 · microsoft windows_10_1709 · e altri 12
0.01EPSS
CVE-2024-8068
Sfruttata Alta 8.0

Privilege escalation to NetworkService Account access in Citrix Session Recording when an attacker is an authenticated user in the same Windows Active Directory domain as the session recording server domain

citrix session_recording
0.01EPSS
CVE-2025-21335
Sfruttata Alta 7.8

Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability

microsoft windows_10_21h2 · microsoft windows_10_22h2 · microsoft windows_11_22h2 · microsoft windows_11_23h2 · e altri 3
0.01EPSS
CVE-2024-53150
Sfruttata Alta 7.1

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix out of bounds reads when finding clock sources The current USB-audio driver code doesn't check bLength of each descriptor at traversing for clock descriptors. That is, …

debian debian_linux · linux linux_kernel
0.01EPSS
CVE-2025-24983
Sfruttata Alta 7.0

Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_server_2008 · microsoft windows_server_2012 · e altri 1
0.01EPSS
CVE-2024-49035
Sfruttata Alta 8.7

An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network.

microsoft partner_center
0.01EPSS
CVE-2025-32701
Sfruttata Alta 7.8

Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 11
0.01EPSS
CVE-2025-38352
Sfruttata Alta 7.8

In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() If an exiting non-autoreaping task has already passed exit_notify() and calls handle_posix_cpu_timers()…

debian debian_linux · linux linux_kernel
0.01EPSS
CVE-2025-68686
Sfruttata Media 5.9

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow a r…

fortinet fortios
0.01EPSS
CVE-2023-36851
Sfruttata Media 5.3

A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to webauth_operation.ph…

juniper junos
0.01EPSS
CVE-2025-22225
Ransomware Alta 8.2

VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox.

vmware cloud_foundation · vmware esxi · vmware telco_cloud_infrastructure · vmware telco_cloud_platform
0.01EPSS
CVE-2026-20349
Sfruttata Alta 8.6

A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unex…

cisco adaptive_security_appliance_software · cisco secure_firewall_threat_defense
0.01EPSS
CVE-2021-44168
Sfruttata Bassa 3.3

A download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3 may allow a local authenticated attacker to download arbitrary files on the device via specially crafted update packages.

fortinet fortios
0.01EPSS
CVE-2021-0920
Sfruttata Media 6.4

In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

debian debian_linux · google android · linux linux_kernel
0.01EPSS
CVE-2024-50302
Sfruttata Media 5.5

In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since the report buffer is used by all kinds of drivers in various ways, let's zero-initialize it during allocation to make sure that it can't be…

debian debian_linux · google android · linux linux_kernel · siemens simatic_s7-1500_tm_mfp_firmware · e altri 1
0.01EPSS
CVE-2026-20316
Sfruttata Media 5.3

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. …

cisco secure_firewall_management_center
0.01EPSS
CVE-2026-68820
Sfruttata Alta 7.0

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · microsoft windows_10_22h2 · e altri 9
0.00EPSS
CVE-2021-45105
Media 5.9

Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a craft…

apache log4j · debian debian_linux · netapp cloud_manager · oracle agile_engineering_data_management · e altri 112
1.00EPSS
CVE-2023-50387
Alta 7.5

Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when ther…

fedoraproject fedora · isc bind · microsoft windows_server_2008 · microsoft windows_server_2012 · e altri 9
1.00EPSS
CVE-2012-1456
Media 4.3

The TAR file parser in AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scan…

aladdin esafe · avg avg_anti-virus · cat quick_heal · comodo comodo_antivirus · e altri 16
1.00EPSS
CVE-2022-42889
Critica 9.8

Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.text.lookup.StringL…

apache commons_text · juniper security_threat_response_manager · netapp bluexp
1.00EPSS
CVE-2025-53771
Media 6.5

Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

microsoft sharepoint_server
1.00EPSS