964 vulnerabilidades · 🔥 KEV Orden: CVSS EPSS Año ID
CVE-2017-16651
🔥 KEV Software Genérico General
7.8
HIGH
EPSS
37.3%
2017 3 PoCs

Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November 2017. The attacker must be able to authenticate at the target system with a valid username/password as the attack requires an active session. The issue is related to file-based attachment plugins and _task=settings&_action=upload-display&_from=timezone requests.

CVE-2004-0210
🔥 KEV Software Genérico Windows
7.8
HIGH
EPSS
6.8%
2004 1 PoC

The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifying message length values and causing a buffer overflow.

CVE-2019-0841
🔥 KEV Windows Windows
7.8
HIGH
EPSS
82.7%
2019 11 PoCs

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0730, CVE-2019-0731, CVE-2019-0796, CVE-2019-0805, CVE-2019-0836.

CVE-2023-4911
🔥 KEV Software Genérico General
7.8
HIGH
EPSS
71.5%
2023 CWE-122 22 PoCs

A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.

CVE-2015-2291
🔥 KEV Software Genérico Windows
7.8
HIGH
EPSS
4.9%
2015 5 PoCs

(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a denial of service or possibly execute arbitrary code with kernel privileges via a crafted (a) 0x80862013, (b) 0x8086200B, (c) 0x8086200F, or (d) 0x80862007 IOCTL call.

CVE-2019-0863
🔥 KEV Windows Windows
7.8
HIGH
EPSS
6.2%
2019 1 PoC

An elevation of privilege vulnerability exists in the way Windows Error Reporting (WER) handles files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'.

CVE-2016-1019
🔥 KEV Software Genérico General
7.8
HIGH
EPSS
58.0%
2016 1 PoC

Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, as exploited in the wild in April 2016.

CVE-2020-1147
🔥 KEV Microsoft SharePoint Enterprise Server Windows
7.8
HIGH
EPSS
93.4%
2020 3 PoCs

A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'.

CVE-2019-1132
🔥 KEV Windows Windows
7.8
HIGH
EPSS
36.5%
2019 2 PoCs

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.

CVE-2025-41244
🔥 KEV VCF operations General
7.8
HIGH
EPSS
0.6%
2025 CWE-267 3 PoCs

VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.

CVE-2014-4113
🔥 KEV Software Genérico Windows
7.8
HIGH
EPSS
82.7%
2014 8 PoCs

win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, as exploited in the wild in October 2014, aka "Win32k.sys Elevation of Privilege Vulnerability."

CVE-2025-30400
🔥 KEV Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
0.8%
2025 CWE-416 1 PoC

Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.

CVE-2016-3643
🔥 KEV Software Genérico General
7.8
HIGH
EPSS
5.2%
2016 3 PoCs

SolarWinds Virtualization Manager 6.3.1 and earlier allow local users to gain privileges by leveraging a misconfiguration of sudo, as demonstrated by "sudo cat /etc/passwd."

CVE-2019-2215
🔥 KEV Android General
7.8
HIGH
EPSS
50.8%
2019 24 PoCs

A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate vulnerability in a network facing application.Product: AndroidAndroid ID: A-141720095

CVE-2015-1130
🔥 KEV Software Genérico General
7.8
HIGH
EPSS
23.4%
2015 1 PoC

The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges via unspecified vectors.

CVE-2019-1385
🔥 KEV Windows Windows
7.8
HIGH
EPSS
0.5%
2019 2 PoCs

An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability, an authenticated attacker would need to run a specially crafted application to elevate privileges.The security update addresses the vulnerability by correcting how AppX Deployment Extensions manages privileges., aka 'Windows AppX Deployment Extensions Elevation of Privilege Vulnerability'.