964 vulnerabilidades · 🔥 KEV Orden: CVSS EPSS Año ID
CVE-2016-7201
🔥 KEV Software Genérico Web
8.8
HIGH
EPSS
89.8%
2016 3 PoCs

The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7200, CVE-2016-7202, CVE-2016-7203, CVE-2016-7208, CVE-2016-7240, CVE-2016-7242, and CVE-2016-7243.

CVE-2016-0034
🔥 KEV Software Genérico General
8.8
HIGH
EPSS
54.9%
2016 1 PoC

Microsoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, which allows remote attackers to execute arbitrary code or cause a denial of service (object-header corruption) via a crafted web site, aka "Silverlight Runtime Remote Code Execution Vulnerability."

CVE-2021-30551
🔥 KEV Chrome General
8.8
HIGH
EPSS
78.4%
2021 1 PoC

Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2015-2051
🔥 KEV Software Genérico Networking
8.8
HIGH
EPSS
93.0%
2015 1 PoC

The D-Link DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute arbitrary commands via a GetDeviceSettings action to the HNAP interface.

CVE-2023-21529
🔥 KEV Microsoft Exchange Server 2019 Cumulative Update 12 Windows
8.8
HIGH
EPSS
29.3%
2023 CWE-502 1 PoC

Microsoft Exchange Server Remote Code Execution Vulnerability

CVE-2017-0143
🔥 KEV Windows SMB Windows
8.8
HIGH
EPSS
94.0%
2017 18 PoCs

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0144, CVE-2017-0145, CVE-2017-0146, and CVE-2017-0148.

CVE-2021-29256
🔥 KEV Software Genérico General
8.8
HIGH
EPSS
0.5%
2021 1 PoC

. The Arm Mali GPU kernel driver allows an unprivileged user to achieve access to freed memory, leading to information disclosure or root privilege escalation. This affects Bifrost r16p0 through r29p0 before r30p0, Valhall r19p0 through r29p0 before r30p0, and Midgard r28p0 through r30p0.

CVE-2024-49039
🔥 KEV Windows Server 2025 Windows
8.8
HIGH
EPSS
63.7%
2024 CWE-287 2 PoCs

Windows Task Scheduler Elevation of Privilege Vulnerability

CVE-2018-8414
🔥 KEV Windows 10 Servers Windows
8.8
HIGH
EPSS
87.9%
2018 1 PoC

A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths, aka "Windows Shell Remote Code Execution Vulnerability." This affects Windows 10 Servers, Windows 10.

CVE-2021-38003
🔥 KEV Chrome General
8.8
HIGH
EPSS
65.7%
2021 2 PoCs

Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2018-4990
🔥 KEV Adobe Acrobat and Reader 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier versions General
8.8
HIGH
EPSS
51.5%
2018 1 PoC

Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Double Free vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

CVE-2016-7200
🔥 KEV Software Genérico Web
8.8
HIGH
EPSS
88.3%
2016 3 PoCs

The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7201, CVE-2016-7202, CVE-2016-7203, CVE-2016-7208, CVE-2016-7240, CVE-2016-7242, and CVE-2016-7243.

CVE-2016-6366
🔥 KEV Software Genérico Networking
8.8
HIGH
EPSS
91.2%
2016 2 PoCs

Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv, Firepower 9300 ASA Security Module, PIX, and FWSM devices allows remote authenticated users to execute arbitrary code via crafted IPv4 SNMP packets, aka Bug ID CSCva92151 or EXTRABACON.

CVE-2023-35674
🔥 KEV Android Windows
8.8
HIGH
EPSS
0.1%
2023 2 PoCs

In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2021-40444
🔥 KEV Windows 10 Version 1809 Windows
8.8
HIGH
EPSS
94.3%
2021 44 PoCs

<p>Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to exploit this vulnerability by using specially-crafted Microsoft Office documents.</p> <p>An attacker could craft a malicious ActiveX control to be used by a Microsoft Office document that hosts the browser rendering engine. The attacker would then have to convince the user to open the malicious document. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who oper

CVE-2015-2502
🔥 KEV Software Genérico General
8.8
HIGH
EPSS
21.7%
2015 1 PoC

Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," as exploited in the wild in August 2015.

CVE-2024-23222
🔥 KEV Safari General
8.8
HIGH
EPSS
0.6%
2024 1 PoC

A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.3, macOS Sonoma 14.3, macOS Ventura 13.6.4, tvOS 17.3, visionOS 1.0.2. Processing maliciously crafted web content may lead to arbitrary code execution. This fix associated with the Coruna exploit was shipped in iOS 17.3 on January 22, 2024. This update brings that fix to devices that cannot update to the latest iOS version.