57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.971 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2021-43747 | HIGH 7.8 | adobe premiere_rush Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious WAV file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is requir | 2,3% | — |
| CVE-2021-43746 | MED 5.5 | adobe premiere_rush Adobe Premiere Rush versions 1.5.16 (and earlier) allows access to an uninitialized pointer vulnerability that allows remote attackers to disclose sensitive information on affected installations. User interaction is required to exploit this vulnerability in th | 1,7% | — |
| CVE-2021-43557 | HIGH 7.5 | apache apisix The uri-block plugin in Apache APISIX before 2.10.2 uses $request_uri without verification. The $request_uri is the full original request URI without normalization. This makes it possible to construct a URI to bypass the block list on some occasions. For insta | 12,7% | — |
| CVE-2021-43410 | MED 5.3 | apache airavata_django_portal Apache Airavata Django Portal allows CRLF log injection because of lack of escaping log statements. In particular, some HTTP request parameters are logged without first being escaped. Versions affected: master branch before commit 3c5d8c7 [1] of airavata-djang | 2,4% | — |
| CVE-2021-43389 | MED 5.5 | debian debian_linux An issue was discovered in the Linux kernel before 5.14.15. There is an array-index-out-of-bounds flaw in the detach_capi_ctr function in drivers/isdn/capi/kcapi.c. | 0,7% | — |
| CVE-2021-43350 | CRIT 9.8 | apache traffic_control An unauthenticated Apache Traffic Control Traffic Ops user can send a request with a specially-crafted username to the POST /login endpoint of any API version to inject unsanitized content into the LDAP filter. | 4,8% | — |
| CVE-2021-43326 | HIGH 7.8 | automox automox Automox Agent before 32 on Windows incorrectly sets permissions on a temporary directory. | 1,2% | — |
| CVE-2021-43325 | HIGH 7.8 | automox automox Automox Agent 33 on Windows incorrectly sets permissions on a temporary directory. NOTE: this issue exists because of a CVE-2021-43326 regression. | 0,2% | — |
| CVE-2021-43297 | CRIT 9.8 | apache dubbo A deserialization vulnerability existed in dubbo hessian-lite 3.2.11 and its earlier versions, which could lead to malicious code execution. Most Dubbo users use Hessian2 as the default serialization/deserialization protocol, during Hessian catch unexpected ex | 17,0% | — |
| CVE-2021-43267 | CRIT 9.8 | fedoraproject fedora An issue was discovered in net/tipc/crypto.c in the Linux kernel before 5.14.16. The Transparent Inter-Process Communication (TIPC) functionality allows remote attackers to exploit insufficient validation of user-supplied sizes for the MSG_CRYPTO message type. | 57,9% | — |
| CVE-2021-43256 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 2,1% | — |
| CVE-2021-43255 | MED 5.5 | microsoft 365_apps Microsoft Office Trust Center Spoofing Vulnerability | 2,0% | — |
| CVE-2021-43248 | HIGH 7.8 | microsoft windows_10 Windows Digital Media Receiver Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2021-43247 | HIGH 7.8 | microsoft windows_10 Windows TCP/IP Driver Elevation of Privilege Vulnerability | 0,9% | — |
| CVE-2021-43246 | MED 5.6 | microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability | 0,8% | — |
| CVE-2021-43245 | HIGH 7.8 | microsoft windows_7 Windows Digital TV Tuner Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2021-43244 | MED 6.5 | microsoft windows_10 Windows Kernel Information Disclosure Vulnerability | 0,8% | — |
| CVE-2021-43243 | MED 5.5 | microsoft vp9_video_extensions VP9 Video Extensions Information Disclosure Vulnerability | 0,8% | — |
| CVE-2021-43242 | HIGH 7.6 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability | 1,2% | — |
| CVE-2021-43240 | HIGH 7.8 | microsoft windows_10 NTFS Set Short Name Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2021-43239 | HIGH 7.1 | microsoft windows_10 Windows Recovery Environment Agent Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2021-43238 | HIGH 7.8 | microsoft windows_10 Windows Remote Access Elevation of Privilege Vulnerability | 0,9% | — |
| CVE-2021-43237 | HIGH 7.8 | microsoft windows_10 Windows Setup Elevation of Privilege Vulnerability | 1,0% | — |
| CVE-2021-43236 | HIGH 7.5 | microsoft windows_10 Microsoft Message Queuing Information Disclosure Vulnerability | 3,0% | — |
| CVE-2021-43235 | MED 5.5 | microsoft windows_10 Storage Spaces Controller Information Disclosure Vulnerability | 0,8% | — |