1080 vulnerabilidades · 🔥 KEV Orden: CVSS EPSS Año ID
CVE-2016-0099
🔥 KEV Software Genérico Windows
7.8
HIGH
EPSS
90.4%
2016 4 PoCs

The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 does not properly process request handles, which allows local users to gain privileges via a crafted application, aka "Secondary Logon Elevation of Privilege Vulnerability."

CVE-2015-5122
🔥 KEV Software Genérico Cloud Windows
7.8
HIGH
EPSS
92.8%
2015 3 PoCs

Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that leverages improper handling of the opaqueBackground property, as exploited in the wild in July 2015.

CVE-2010-0232
🔥 KEV Software Genérico Windows
7.8
HIGH
EPSS
73.9%
2010 1 PoC

The kernel in Microsoft Windows NT 3.1 through Windows 7, including Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, and Windows Server 2008 Gold and SP2, when access to 16-bit applications is enabled on a 32-bit x86 platform, does not properly validate certain BIOS calls, which allows local users to gain privileges by crafting a VDM_TIB data structure in the Thread Environment Block (TEB), and then calling the NtVdmControl function to start the Windows Virtual DOS Machine (aka NTVDM) subsystem, leading to improperly handled exceptions involv

CVE-2021-30860
🔥 KEV macOS General
7.8
HIGH
EPSS
70.6%
2021 8 PoCs

An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. Processing a maliciously crafted PDF may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

CVE-2023-32434
🔥 KEV macOS General
7.8
HIGH
EPSS
52.8%
2023 1 PoC

An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.5.2, macOS Big Sur 11.7.8, iOS 15.7.7 and iPadOS 15.7.7, macOS Monterey 12.6.7, watchOS 8.8.1, iOS 16.5.1 and iPadOS 16.5.1, macOS Ventura 13.4.1. An app may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.

CVE-2024-38193
🔥 KEV Windows 11 Version 24H2 Windows
7.8
HIGH
EPSS
73.2%
2024 CWE-416 2 PoCs

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2023-32046
🔥 KEV Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
42.7%
2023 1 PoC

Windows MSHTML Platform Elevation of Privilege Vulnerability

CVE-2023-41992
🔥 KEV macOS General
7.8
HIGH
EPSS
1.1%
2023 1 PoC

The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7, iOS 16.7 and iPadOS 16.7, macOS Ventura 13.6. A local attacker may be able to elevate their privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.

CVE-2018-8453
🔥 KEV Windows 7 Windows
7.8
HIGH
EPSS
81.3%
2018 5 PoCs

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

CVE-2023-0386
🔥 KEV Kernel General
7.8
HIGH
EPSS
54.3%
2023 CWE-282 18 PoCs

A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.

CVE-2015-1701
🔥 KEV Software Genérico Windows
7.8
HIGH
EPSS
90.2%
2015 7 PoCs

Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in April 2015, aka "Win32k Elevation of Privilege Vulnerability."

CVE-2016-4117
🔥 KEV Software Genérico General
7.8
HIGH
EPSS
93.0%
2016 3 PoCs

Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016.

CVE-2007-5659
🔥 KEV Software Genérico Web
7.8
HIGH
EPSS
92.9%
2007 1 PoC

Multiple buffer overflows in Adobe Reader and Acrobat 8.1.1 and earlier allow remote attackers to execute arbitrary code via a PDF file with long arguments to unspecified JavaScript methods. NOTE: this issue might be subsumed by CVE-2008-0655.

CVE-2021-42292
🔥 KEV Microsoft Office 2019 General
7.8
HIGH
EPSS
35.5%
2021 1 PoC

Microsoft Excel Security Feature Bypass Vulnerability

CVE-2015-0016
🔥 KEV Software Genérico Windows
7.8
HIGH
EPSS
92.1%
2015 2 PoCs

Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows Vista SP2, Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to gain privileges via a crafted pathname in an executable file, as demonstrated by a transition from Low Integrity to Medium Integrity, aka "Directory Traversal Elevation of Privilege Vulnerability."

CVE-2021-38648
🔥 KEV Open Management Infrastructure General
7.8
HIGH
EPSS
31.8%
2021 1 PoC

Open Management Infrastructure Elevation of Privilege Vulnerability