imPC@ndo EN

CVE Tracker

56.413 CVE

CVE-2025-21298
Critica 9.8

Windows OLE Remote Code Execution Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 11
0.81EPSS
CVE-2023-24488
Media 6.1

Cross site scripting vulnerability in Citrix ADC and Citrix Gateway  in allows and attacker to perform cross site scripting

citrix application_delivery_controller · citrix gateway
0.81EPSS
CVE-2025-27636
Media 5.6

Bypass/Injection vulnerability in Apache Camel components under particular conditions. This issue affects Apache Camel: from 4.10.0 through <= 4.10.1, from 4.8.0 through <= 4.8.4, from 3.10.0 through <= 3.22.3. Users are recommended to upgrade to version 4.1…

apache camel
0.81EPSS
CVE-2023-50164
Critica 9.8

An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution. Users are recommended to upgrade to versions Struts 2.5.33 or S…

apache struts
0.81EPSS
CVE-2018-0758
Alta 7.5

Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corrupti…

microsoft chakracore · microsoft edge
0.81EPSS
CVE-2007-6203
Media 4.3

Apache HTTP Server 2.0.x and 2.2.x does not sanitize the HTTP Method specifier header from an HTTP request when it is reflected back in a "413 Request Entity Too Large" error message, which might allow cross-site scripting (XSS) style attacks using web client …

apache http_server
0.81EPSS
CVE-2024-20419
Critica 10.0

A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to change the password of any user, including administrative users. This vulnerability is due to improper impl…

cisco smart_software_manager_on-prem
0.81EPSS
CVE-2010-0805
Alta 9.3

The Tabular Data Control (TDC) ActiveX control in Microsoft Internet Explorer 5.01 SP4, 6 on Windows XP SP2 and SP3, and 6 SP1 allows remote attackers to execute arbitrary code via a long URL (DataURL parameter) that triggers memory corruption in the CTDCCtl::…

microsoft internet_explorer · microsoft windows_2000 · microsoft windows_xp
0.81EPSS
CVE-2020-13160
Critica 9.8

AnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that can be exploited for remote code execution.

anydesk anydesk
0.81EPSS
CVE-2016-3087
Critica 9.8

Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via vectors related to an ! (exclamation mark) operator to the REST Plugin.

apache struts
0.81EPSS
CVE-2013-3183
Alta 7.8

The TCP/IP implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly perform memory allocation for inbound ICMPv6 packets, which allows remote attackers to…

microsoft windows_7 · microsoft windows_8 · microsoft windows_rt · microsoft windows_server_2008 · e altri 2
0.80EPSS
CVE-2022-34715
Critica 9.8

Windows Network File System Remote Code Execution Vulnerability

microsoft windows_server_2022
0.80EPSS
CVE-2021-1499
Media 5.3

A vulnerability in the web-based management interface of Cisco HyperFlex HX Data Platform could allow an unauthenticated, remote attacker to upload files to an affected device. This vulnerability is due to missing authentication for the upload function. An att…

cisco hyperflex_hx_data_platform
0.80EPSS
CVE-2011-4858
Media 5.0

Apache Tomcat before 5.5.35, 6.x before 6.0.35, and 7.x before 7.0.23 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) …

apache tomcat
0.80EPSS
CVE-2023-39143
Critica 9.8

PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete arbitrary files. This leads to remote code execution when external device integration is enabled (a very common configuration).

papercut papercut_mf · papercut papercut_ng
0.80EPSS
CVE-2004-0230
Media 5.0

TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-li…

juniper junos · mcafee network_data_loss_prevention · microsoft windows_2000 · microsoft windows_98 · e altri 8
0.80EPSS
CVE-2003-0349
Alta 7.5

Buffer overflow in the streaming media component for logging multicast requests in the ISAPI for the logging capability of Microsoft Windows Media Services (nsiislog.dll), as installed in IIS 5.0, allows remote attackers to execute arbitrary code via a large P…

microsoft windows_2000
0.80EPSS
CVE-2002-1359
Alta 10.0

Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code via buffer overflow attacks, as demonstrated by the SSHredder SSH protocol …

cisco ios · fissh ssh_client · intersoft securenetterm · netcomposite shellguard_ssh · e altri 3
0.80EPSS
CVE-2004-0790
Media 5.0

Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages, aka the "blind connection-reset attack." NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLI…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_98 · microsoft windows_98se · e altri 4
0.80EPSS
CVE-2023-34992
Critica 10.0

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via crafted API requests.

fortinet fortisiem
0.80EPSS
CVE-2022-20705
Critica 10.0

Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization prot…

cisco rv160_firmware · cisco rv160w_firmware · cisco rv260_firmware · cisco rv260p_firmware · e altri 5
0.80EPSS
CVE-2019-0567
Alta 7.5

A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique …

microsoft chakracore · microsoft edge
0.80EPSS
CVE-2022-21972
Alta 8.1

Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability

microsoft windows_10 · microsoft windows_11 · microsoft windows_7 · microsoft windows_8.1 · e altri 7
0.80EPSS
CVE-2004-1080
Alta 10.0

The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attackers to write to arbitrary memory locations and possibly execute arbitrary code via a modified memory pointer in a WINS replication …

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_nt
0.80EPSS
CVE-2006-4777
Alta 7.6

Heap-based buffer overflow in the DirectAnimation Path Control (DirectAnimation.PathControl) COM object (daxctle.ocx) for Internet Explorer 6.0 SP1, on Chinese and possibly other Windows distributions, allows remote attackers to execute arbitrary code via unkn…

microsoft ie
0.80EPSS