imPC@ndo EN

CVE Tracker

56.198 CVE

CVE-2024-3400
Ransomware Critica 10.0

A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbit…

paloaltonetworks pan-os
1.00EPSS
CVE-2023-4966
Ransomware Critica 9.4

Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA  virtual server.

citrix netscaler_application_delivery_controller · citrix netscaler_gateway
1.00EPSS
CVE-2023-44487
Sfruttata Alta 7.5

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

akka http_server · amazon opensearch_data_prepper · apache apisix · apache solr · e altri 161
1.00EPSS
CVE-2015-1635
Sfruttata Critica 9.8

HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP requests, aka "HTTP.sys Remote Code Execution Vulnerability."

microsoft windows_7 · microsoft windows_8 · microsoft windows_8.1 · microsoft windows_server_2008 · e altri 1
1.00EPSS
CVE-2014-6271
Sfruttata Critica 9.8

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature …

apple mac_os_x · arista eos · canonical ubuntu_linux · checkpoint security_gateway · e altri 70
1.00EPSS
CVE-2021-44228
Ransomware Critica 10.0

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who c…

apache log4j · apple xcode · bentley synchro · bentley synchro_4d · e altri 139
1.00EPSS
CVE-2021-40438
Ransomware Critica 9.0

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

apache http_server · broadcom brocade_fabric_operating_system_firmware · debian debian_linux · f5 f5os · e altri 35
1.00EPSS
CVE-2021-22005
Ransomware Critica 9.8

The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to execute code on vCenter Server by uploading a specially crafted file.

vmware cloud_foundation · vmware vcenter_server
1.00EPSS
CVE-2021-34473
Ransomware Critica 9.1

Microsoft Exchange Server Remote Code Execution Vulnerability

microsoft exchange_server
1.00EPSS
CVE-2021-21985
Ransomware Critica 9.8

The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this …

vmware cloud_foundation · vmware vcenter_server
1.00EPSS
CVE-2021-1498
Sfruttata Critica 9.8

Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Deta…

cisco hyperflex_hx_data_platform
1.00EPSS
CVE-2021-26855
Ransomware Critica 9.1

Microsoft Exchange Server Remote Code Execution Vulnerability

microsoft exchange_server
1.00EPSS
CVE-2020-5902
Ransomware Critica 9.8

In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has a Remote Code Execution (RCE) vulnerability in undisclo…

f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · f5 big-ip_advanced_web_application_firewall · f5 big-ip_analytics · e altri 10
1.00EPSS
CVE-2019-19781
Ransomware Critica 9.8

An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.

citrix application_delivery_controller_firmware · citrix gateway_firmware · citrix netscaler_gateway_firmware
1.00EPSS
CVE-2018-13379
Ransomware Critica 9.1

An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an una…

fortinet fortios · fortinet fortiproxy
1.00EPSS
CVE-2019-0708
Ransomware Critica 9.8

A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code …

huawei agile_controller-campus_firmware · huawei bh620_v2_firmware · huawei bh621_v2_firmware · huawei bh622_v2_firmware · e altri 63
1.00EPSS
CVE-2017-5638
Ransomware Critica 9.8

The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted C…

apache struts · arubanetworks clearpass_policy_manager · hp server_automation · ibm storwize_v3500_firmware · e altri 5
1.00EPSS
CVE-2013-2251
Sfruttata Critica 9.8

Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.

apache archiva · apache struts · fujitsu interstage_business_process_manager_analytics · oracle siebel_apps_-_e-billing
1.00EPSS
CVE-2022-22954
Ransomware Critica 9.8

VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution.

vmware cloud_foundation · vmware identity_manager · vmware vrealize_automation · vmware vrealize_suite_lifecycle_manager · e altri 1
1.00EPSS
CVE-2021-41773
Ransomware Critica 9.8

A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not …

apache http_server · fedoraproject fedora · netapp cloud_backup · oracle instantis_enterprisetrack
1.00EPSS
CVE-2020-3452
Sfruttata Alta 7.5

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and read sensitive files …

cisco adaptive_security_appliance_software · cisco secure_firewall_threat_defense
1.00EPSS
CVE-2018-11776
Sfruttata Alta 8.1

Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: results are used with no namespace and in same time, its uppe…

apache struts · netapp active_iq_unified_manager · netapp oncommand_insight · netapp oncommand_workflow_automation · e altri 4
1.00EPSS
CVE-2021-34523
Ransomware Critica 9.0

Microsoft Exchange Server Elevation of Privilege Vulnerability

microsoft exchange_server
1.00EPSS
CVE-2017-12617
Sfruttata Alta 8.1

When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file…

apache tomcat · canonical ubuntu_linux · debian debian_linux · netapp active_iq_unified_manager · e altri 54
1.00EPSS
CVE-2024-4577
Ransomware Critica 9.8

In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace characters in command line given to Win32 …

fedoraproject fedora · php php
1.00EPSS