58.015 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.015 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più alto |
|---|---|---|---|---|
| CVE-2021-43228 | HIGH 7.5 | microsoft windows_10 SymCrypt Denial of Service Vulnerability | 3,7% | — |
| CVE-2021-43227 | MED 5.5 | microsoft windows_10 Storage Spaces Controller Information Disclosure Vulnerability | 0,8% | — |
| CVE-2021-43225 | HIGH 7.5 | microsoft bot_framework_software_development_kit Bot Framework SDK Remote Code Execution Vulnerability | 2,8% | — |
| CVE-2021-43224 | MED 5.5 | microsoft windows_10 Windows Common Log File System Driver Information Disclosure Vulnerability | 3,9% | — |
| CVE-2021-43223 | HIGH 7.8 | microsoft windows_10 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2021-43222 | HIGH 7.5 | microsoft windows_10 Microsoft Message Queuing Information Disclosure Vulnerability | 3,0% | — |
| CVE-2021-43221 | MED 4.2 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 1,1% | — |
| CVE-2021-43220 | LOW 3.1 | microsoft edge_ios Microsoft Edge for iOS Spoofing Vulnerability | 1,3% | — |
| CVE-2021-43219 | HIGH 7.4 | microsoft windows_10 DirectX Graphics Kernel File Denial of Service Vulnerability | 3,7% | — |
| CVE-2021-43217 | HIGH 8.1 | microsoft windows_10 Windows Encrypting File System (EFS) Remote Code Execution Vulnerability | 6,4% | — |
| CVE-2021-43216 | MED 6.5 | microsoft windows_10 Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability | 3,2% | — |
| CVE-2021-43215 | CRIT 9.8 | microsoft windows_10 iSNS Server Memory Corruption Vulnerability Can Lead to Remote Code Execution | 2,7% | — |
| CVE-2021-43214 | HIGH 7.8 | microsoft raw_image_extension Web Media Extensions Remote Code Execution Vulnerability | 1,7% | — |
| CVE-2021-43211 | MED 5.5 | microsoft windows_10_update_assistant Windows 10 Update Assistant Elevation of Privilege Vulnerability | 0,8% | — |
| CVE-2021-43209 | HIGH 7.8 | microsoft 3d_viewer 3D Viewer Remote Code Execution Vulnerability | 6,8% | — |
| CVE-2021-43208 | HIGH 7.8 | microsoft 3d_viewer 3D Viewer Remote Code Execution Vulnerability | 4,3% | — |
| CVE-2021-43207 | HIGH 7.8 | microsoft windows_10 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2021-43206 | MED 4.3 | fortinet fortios A server-generated error message containing sensitive information in Fortinet FortiOS 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.x, 6.0.x and FortiProxy 7.0.0 through 7.0.1, 2.0.x allows malicious webservers to retrieve a web proxy's client username and IP | 0,8% | — |
| CVE-2021-43205 | MED 4.3 | fortinet forticlient An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClient for Linux version 7.0.2 and below, 6.4.7 and below and 6.2.9 and below may allow an unauthenticated attacker to access the confighandler webserver via external | 0,9% | — |
| CVE-2021-43204 | MED 4.4 | fortinet forticlient A improper control of a resource through its lifetime in Fortinet FortiClientWindows version 6.4.1 and 6.4.0, version 6.2.9 and below, version 6.0.10 and below allows attacker to cause a complete denial of service of its components via changes of directory acc | 0,3% | — |
| CVE-2021-43083 | HIGH 8.8 | apache plc4x Apache PLC4X - PLC4C (Only the C language implementation was effected) was vulnerable to an unsigned integer underflow flaw inside the tcp transport. Users should update to 0.9.1, which addresses this issue. However, in order to exploit this vulnerability, a u | 1,9% | — |
| CVE-2021-43082 | CRIT 9.8 | apache traffic_server Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in the stats-over-http plugin of Apache Traffic Server allows an attacker to overwrite memory. This issue affects Apache Traffic Server 9.1.0. | 2,4% | — |
| CVE-2021-43081 | MED 6.1 | fortinet fortios An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS version 7.0.3 and below, 6.4.8 and below, 6.2.10 and below, 6.0.14 to 6.0.0. and in FortiProxy version 7.0.1 and below, 2.0.7 to 2.0.0 web filter override form may | 0,9% | — |
| CVE-2021-43080 | MED 4.6 | fortinet fortios An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS version 7.2.0, version 6.4.0 through 6.4.9, version 7.0.0 through 7.0.5 may allow an authenticated attacker to perform a stored cross site scripting (XSS) attack t | 0,4% | — |
| CVE-2021-43077 | HIGH 8.8 | fortinet fortiwlm A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.2 and below, version 8.5.2 and below, version 8.4.2 and below, version 8.3.2 and below allows attacker to execute unauthorized code or comma | 0,8% | — |