57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.971 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2021-42721 | HIGH 7.8 | adobe media_encoder Acrobat Bridge versions 11.1.1 and earlier are affected by a use-after-free vulnerability in the processing of Format event actions that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user inter | 3,7% | — |
| CVE-2021-42717 | HIGH 7.5 | debian debian_linux ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens-of-thousands deep could result in the web server being unable to service legitimate requests. Even a moderately large (e.g., 300KB) HTTP request ca | 3,1% | — |
| CVE-2021-42714 | HIGH 7.8 | splashtop splashtop Splashtop Remote Client (Business Edition) through 3.4.8.3 creates a Temporary File in a Directory with Insecure Permissions. | 0,4% | — |
| CVE-2021-42713 | HIGH 7.8 | splashtop splashtop Splashtop Remote Client (Personal Edition) through 3.4.6.1 creates a Temporary File in a Directory with Insecure Permissions. | 0,3% | — |
| CVE-2021-42638 | HIGH 8.1 | printerlogic web_stack PrinterLogic Web Stack versions 19.1.1.13 SP9 and below do not sanitize user input resulting in pre-auth remote code execution. | 5,5% | — |
| CVE-2021-42635 | HIGH 8.1 | printerlogic web_stack PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use a hardcoded APP_KEY value, leading to pre-auth remote code execution. | 5,6% | — |
| CVE-2021-42631 | HIGH 8.1 | printerlogic virtual_appliance PrinterLogic Web Stack versions 19.1.1.13 SP9 and below deserializes attacker controlled leading to pre-auth remote code execution. | 6,2% | — |
| CVE-2021-42563 | HIGH 7.8 | ni ni_service_locator There is an Unquoted Service Path in NI Service Locator (nisvcloc.exe) in versions prior to 18.0 on Windows. This may allow an authorized local user to insert arbitrary code into the unquoted service path and escalate privileges. | 0,2% | — |
| CVE-2021-42527 | HIGH 7.8 | adobe premiere_elements Adobe Premiere Elements 20210809.daily.2242976 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious file, potentially resulting in arbitrary code execution in the context of the current user. User interaction i | 1,7% | — |
| CVE-2021-42526 | HIGH 7.8 | adobe premiere_elements Adobe Premiere Elements 20210809.daily.2242976 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious file, potentially resulting in arbitrary code execution in the context of the current user. User interaction i | 1,6% | — |
| CVE-2021-42525 | LOW 3.3 | adobe animate Acrobat Animate versions 21.0.9 (and earlier)is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requ | 1,7% | — |
| CVE-2021-42524 | HIGH 7.8 | adobe animate Adobe Animate version 21.0.9 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a | 2,7% | — |
| CVE-2021-42357 | MED 6.1 | apache knox When using Apache Knox SSO prior to 1.6.1, a request could be crafted to redirect a user to a malicious page due to improper URL parsing. A request that included a specially crafted request parameter could be used to redirect the user to a page controlled by a | 2,6% | — |
| CVE-2021-42340 | HIGH 7.5 | apache tomcat The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket co | 11,8% | — |
| CVE-2021-42327 | MED 6.7 | fedoraproject fedora dp_link_settings_write in drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_debugfs.c in the Linux kernel through 5.14.14 allows a heap-based buffer overflow by an attacker who can write a string to the AMD GPU display drivers debug filesystem. There are no chec | 0,9% | — |
| CVE-2021-42323 | LOW 3.3 | microsoft azure_real_time_operating_system Azure RTOS Information Disclosure Vulnerability | 1,4% | — |
| CVE-2021-42322 | HIGH 7.8 | microsoft visual_studio_code Visual Studio Code Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2021-42320 | HIGH 8.0 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability | 1,5% | — |
| CVE-2021-42319 | MED 4.7 | microsoft visual_studio_2017 Visual Studio Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2021-42316 | HIGH 8.8 | microsoft dynamics_365 Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability | 2,3% | — |
| CVE-2021-42315 | HIGH 8.8 | microsoft defender_for_iot Microsoft Defender for IoT Remote Code Execution Vulnerability | 2,2% | — |
| CVE-2021-42314 | HIGH 8.8 | microsoft defender_for_iot Microsoft Defender for IoT Remote Code Execution Vulnerability | 2,2% | — |
| CVE-2021-42313 | CRIT 10.0 | microsoft defender_for_iot Microsoft Defender for IoT Remote Code Execution Vulnerability | 3,8% | — |
| CVE-2021-42312 | HIGH 7.8 | microsoft defender_for_iot Microsoft Defender for IoT Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2021-42311 | CRIT 10.0 | microsoft defender_for_iot Microsoft Defender for IoT Remote Code Execution Vulnerability | 4,0% | — |