EN
57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

57.971 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordinato dal più basso
CVE-2021-43747 HIGH 7.8 adobe premiere_rush Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious WAV file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is requir 2,3%
CVE-2021-43746 MED 5.5 adobe premiere_rush Adobe Premiere Rush versions 1.5.16 (and earlier) allows access to an uninitialized pointer vulnerability that allows remote attackers to disclose sensitive information on affected installations. User interaction is required to exploit this vulnerability in th 1,7%
CVE-2021-43557 HIGH 7.5 apache apisix The uri-block plugin in Apache APISIX before 2.10.2 uses $request_uri without verification. The $request_uri is the full original request URI without normalization. This makes it possible to construct a URI to bypass the block list on some occasions. For insta 12,7%
CVE-2021-43410 MED 5.3 apache airavata_django_portal Apache Airavata Django Portal allows CRLF log injection because of lack of escaping log statements. In particular, some HTTP request parameters are logged without first being escaped. Versions affected: master branch before commit 3c5d8c7 [1] of airavata-djang 2,4%
CVE-2021-43389 MED 5.5 debian debian_linux An issue was discovered in the Linux kernel before 5.14.15. There is an array-index-out-of-bounds flaw in the detach_capi_ctr function in drivers/isdn/capi/kcapi.c. 0,7%
CVE-2021-43350 CRIT 9.8 apache traffic_control An unauthenticated Apache Traffic Control Traffic Ops user can send a request with a specially-crafted username to the POST /login endpoint of any API version to inject unsanitized content into the LDAP filter. 4,8%
CVE-2021-43326 HIGH 7.8 automox automox Automox Agent before 32 on Windows incorrectly sets permissions on a temporary directory. 1,2%
CVE-2021-43325 HIGH 7.8 automox automox Automox Agent 33 on Windows incorrectly sets permissions on a temporary directory. NOTE: this issue exists because of a CVE-2021-43326 regression. 0,2%
CVE-2021-43297 CRIT 9.8 apache dubbo A deserialization vulnerability existed in dubbo hessian-lite 3.2.11 and its earlier versions, which could lead to malicious code execution. Most Dubbo users use Hessian2 as the default serialization/deserialization protocol, during Hessian catch unexpected ex 17,0%
CVE-2021-43267 CRIT 9.8 fedoraproject fedora An issue was discovered in net/tipc/crypto.c in the Linux kernel before 5.14.16. The Transparent Inter-Process Communication (TIPC) functionality allows remote attackers to exploit insufficient validation of user-supplied sizes for the MSG_CRYPTO message type. 57,9%
CVE-2021-43256 HIGH 7.8 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 2,1%
CVE-2021-43255 MED 5.5 microsoft 365_apps Microsoft Office Trust Center Spoofing Vulnerability 2,0%
CVE-2021-43248 HIGH 7.8 microsoft windows_10 Windows Digital Media Receiver Elevation of Privilege Vulnerability 0,5%
CVE-2021-43247 HIGH 7.8 microsoft windows_10 Windows TCP/IP Driver Elevation of Privilege Vulnerability 0,9%
CVE-2021-43246 MED 5.6 microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability 0,8%
CVE-2021-43245 HIGH 7.8 microsoft windows_7 Windows Digital TV Tuner Elevation of Privilege Vulnerability 0,5%
CVE-2021-43244 MED 6.5 microsoft windows_10 Windows Kernel Information Disclosure Vulnerability 0,8%
CVE-2021-43243 MED 5.5 microsoft vp9_video_extensions VP9 Video Extensions Information Disclosure Vulnerability 0,8%
CVE-2021-43242 HIGH 7.6 microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability 1,2%
CVE-2021-43240 HIGH 7.8 microsoft windows_10 NTFS Set Short Name Elevation of Privilege Vulnerability 0,6%
CVE-2021-43239 HIGH 7.1 microsoft windows_10 Windows Recovery Environment Agent Elevation of Privilege Vulnerability 0,5%
CVE-2021-43238 HIGH 7.8 microsoft windows_10 Windows Remote Access Elevation of Privilege Vulnerability 0,9%
CVE-2021-43237 HIGH 7.8 microsoft windows_10 Windows Setup Elevation of Privilege Vulnerability 1,0%
CVE-2021-43236 HIGH 7.5 microsoft windows_10 Microsoft Message Queuing Information Disclosure Vulnerability 3,0%
CVE-2021-43235 MED 5.5 microsoft windows_10 Storage Spaces Controller Information Disclosure Vulnerability 0,8%