1080 vulnerabilidades · 🔥 KEV Orden: CVSS EPSS Año ID
CVE-2023-41064
🔥 KEV macOS General
7.8
HIGH
EPSS
85.4%
2023 6 PoCs

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 16.6.1 and iPadOS 16.6.1, macOS Monterey 12.6.9, macOS Ventura 13.5.2, iOS 15.7.9 and iPadOS 15.7.9, macOS Big Sur 11.7.10. Processing a maliciously crafted image may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

CVE-2018-0802
🔥 KEV Equation Editor General
7.8
HIGH
EPSS
94.1%
2018 7 PoCs

Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE is unique from CVE-2018-0797 and CVE-2018-0812.

CVE-2019-13272
🔥 KEV Software Genérico General
7.8
HIGH
EPSS
81.1%
2019 24 PoCs

In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows local users to obtain root access by leveraging certain scenarios with a parent-child process relationship, where a parent drops privileges and calls execve (potentially allowing control by an attacker). One contributing factor is an object lifetime issue (which can also cause a panic). Another contributing factor is incorrect marking of a ptrace relationship as privileged, which is exploitable through (for example)

CVE-2020-1464
🔥 KEV Windows 10 Version 1803 Windows
7.8
HIGH
EPSS
7.9%
2020 3 PoCs

A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could bypass security features and load improperly signed files. In an attack scenario, an attacker could bypass security features intended to prevent improperly signed files from being loaded. The update addresses the vulnerability by correcting how Windows validates file signatures.

CVE-2015-5119
🔥 KEV Software Genérico Cloud Windows
7.8
HIGH
EPSS
93.2%
2015 5 PoCs

Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows and OS X and 11.x through 11.2.202.468 on Linux allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function, as exploited in the wild in July 2015.

CVE-2020-0787
🔥 KEV Windows Windows
7.8
HIGH
EPSS
61.8%
2020 3 PoCs

An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'.

CVE-2020-0041
🔥 KEV Android General
7.8
HIGH
EPSS
23.9%
2020 4 PoCs

In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-145988638References: Upstream kernel

CVE-2023-20963
🔥 KEV Android General
7.8
HIGH
EPSS
1.8%
2023 2 PoCs

In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-220302519

CVE-2015-7645
🔥 KEV Software Genérico Windows
7.8
HIGH
EPSS
85.2%
2015 3 PoCs

Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote attackers to execute arbitrary code via a crafted SWF file, as exploited in the wild in October 2015.

CVE-2020-28949
🔥 KEV Software Genérico General
7.8
HIGH
EPSS
93.4%
2020 3 PoCs

Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed.

CVE-2018-8453
🔥 KEV Windows 7 Windows
7.8
HIGH
EPSS
81.3%
2018 5 PoCs

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

CVE-2010-1297
🔥 KEV Software Genérico Windows
7.8
HIGH
EPSS
92.8%
2010 4 PoCs

Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted SWF content, related to authplay.dll and the ActionScript Virtual Machine 2 (AVM2) newfunction instruction, as exploited in the wild in June 2010.

CVE-2016-3235
🔥 KEV Software Genérico General
7.8
HIGH
EPSS
81.2%
2016 1 PoC

Microsoft Visio 2007 SP3, Visio 2010 SP2, Visio 2013 SP1, Visio 2016, Visio Viewer 2007 SP3, and Visio Viewer 2010 mishandle library loading, which allows local users to gain privileges via a crafted application, aka "Microsoft Office OLE DLL Side Loading Vulnerability."

CVE-2020-1147
🔥 KEV Microsoft SharePoint Enterprise Server Windows
7.8
HIGH
EPSS
93.4%
2020 3 PoCs

A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'.

CVE-2018-4878
🔥 KEV Adobe Flash Player before 28.0.0.161 General
7.8
HIGH
EPSS
93.5%
2018 16 PoCs

A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player handling of listener objects. A successful attack can lead to arbitrary code execution. This was exploited in the wild in January and February 2018.

CVE-2023-32434
🔥 KEV macOS General
7.8
HIGH
EPSS
52.8%
2023 1 PoC

An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.5.2, macOS Big Sur 11.7.8, iOS 15.7.7 and iPadOS 15.7.7, macOS Monterey 12.6.7, watchOS 8.8.1, iOS 16.5.1 and iPadOS 16.5.1, macOS Ventura 13.4.1. An app may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.

CVE-2021-34486
🔥 KEV Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
36.5%
2021 2 PoCs

Windows Event Tracing Elevation of Privilege Vulnerability

CVE-2023-32046
🔥 KEV Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
42.7%
2023 1 PoC

Windows MSHTML Platform Elevation of Privilege Vulnerability