57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.971 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2021-41585 | HIGH 7.5 | apache traffic_server Improper Input Validation vulnerability in accepting socket connections in Apache Traffic Server allows an attacker to make the server stop accepting new connections. This issue affects Apache Traffic Server 5.0.0 to 9.1.0. | 2,5% | — |
| CVE-2021-41571 | MED 6.5 | apache pulsar In Apache Pulsar it is possible to access data from BookKeeper that does not belong to the topics accessible by the authenticated user. The Admin API get-message-by-id requires the user to input a topic and a ledger id. The ledger id is a pointer to the data, | 1,7% | — |
| CVE-2021-4157 | HIGH 8.0 | fedoraproject fedora An out of memory bounds write flaw (1 or 2 bytes of memory) in the Linux kernel NFS subsystem was found in the way users use mirroring (replication of files with NFS). A user, having access to the NFS mount, could potentially use this flaw to crash the system | 1,6% | — |
| CVE-2021-41561 | HIGH 7.5 | apache parquet_java Improper Input Validation vulnerability in Parquet-MR of Apache Parquet allows an attacker to DoS by malicious Parquet files. This issue affects Apache Parquet-MR version 1.9.0 and later versions. | 3,1% | — |
| CVE-2021-4155 | MED 5.5 | linux linux_kernel A data leak flaw was found in the way XFS_IOC_ALLOCSP IOCTL in the XFS filesystem allowed for size increase of files with unaligned size. A local attacker could use this flaw to leak data on the XFS filesystem otherwise not accessible to them. | 0,3% | — |
| CVE-2021-4154 | HIGH 8.8 | linux linux_kernel A use-after-free flaw was found in cgroup1_parse_param in kernel/cgroup/cgroup-v1.c in the Linux kernel's cgroup v1 parser. A local attacker with a user privilege could cause a privilege escalation by exploiting the fsconfig syscall parameter leading to a cont | 1,2% | — |
| CVE-2021-41532 | MED 5.3 | apache ozone In Apache Ozone before 1.2.0, Recon HTTP endpoints provide access to OM, SCM and Datanode metadata. Due to a bug, any unauthenticated user can access the data from these endpoints. | 2,4% | — |
| CVE-2021-41524 | HIGH 7.5 | apache http_server While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing, allowing an external source to DoS the server. This requires a specially crafted request. The vulnerability was recently introduced in version 2.4.49. | 25,2% | — |
| CVE-2021-4150 | MED 5.5 | linux linux_kernel A use-after-free flaw was found in the add_partition in block/partitions/core.c in the Linux kernel. A local attacker with user privileges could cause a denial of service on the system. The issue results from the lack of code cleanup when device_add call fails | 0,3% | — |
| CVE-2021-4149 | MED 5.5 | debian debian_linux A vulnerability was found in btrfs_alloc_tree_b in fs/btrfs/extent-tree.c in the Linux kernel due to an improper lock operation in btrfs. In this flaw, a user with a local privilege may cause a denial of service (DOS) due to a deadlock problem. | 0,4% | — |
| CVE-2021-4148 | MED 5.5 | fedoraproject fedora A vulnerability was found in the Linux kernel's block_invalidatepage in fs/buffer.c in the filesystem. A missing sanity check may allow a local attacker with user privilege to cause a denial of service (DOS) problem. | 0,3% | — |
| CVE-2021-41378 | HIGH 7.8 | microsoft windows_10 Windows NTFS Remote Code Execution Vulnerability | 1,6% | — |
| CVE-2021-41377 | HIGH 7.8 | microsoft windows_10 Windows Fast FAT File System Driver Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2021-41376 | LOW 2.3 | microsoft azure_sphere Azure Sphere Information Disclosure Vulnerability | 0,9% | — |
| CVE-2021-41375 | MED 4.4 | microsoft azure_sphere Azure Sphere Information Disclosure Vulnerability | 0,9% | — |
| CVE-2021-41374 | MED 6.7 | microsoft azure_sphere Azure Sphere Information Disclosure Vulnerability | 0,7% | — |
| CVE-2021-41373 | MED 5.5 | microsoft fslogix FSLogix Information Disclosure Vulnerability | 0,8% | — |
| CVE-2021-41372 | HIGH 7.6 | microsoft power_bi_report_server A Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exists when Power BI Report Server Template file (pbix) containing HTML files is uploaded to the server and HTML files are accessed directly by the victim. Combining these 2 vulne | 0,7% | — |
| CVE-2021-41371 | MED 4.4 | microsoft windows_10 Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability | 1,6% | — |
| CVE-2021-41370 | HIGH 7.8 | microsoft windows_10 NTFS Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2021-41368 | MED 6.1 | microsoft 365_apps Microsoft Access Remote Code Execution Vulnerability | 4,9% | — |
| CVE-2021-41367 | HIGH 7.8 | microsoft windows_10 NTFS Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2021-41366 | HIGH 7.8 | microsoft windows_10 Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2021-41365 | HIGH 8.8 | microsoft defender_for_iot Microsoft Defender for IoT Remote Code Execution Vulnerability | 2,7% | — |
| CVE-2021-41363 | MED 4.2 | microsoft intune_management_extension Intune Management Extension Security Feature Bypass Vulnerability | 0,5% | — |