57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.971 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2021-41333 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 1,1% | — |
| CVE-2021-41332 | MED 6.5 | microsoft windows_10 Windows Print Spooler Information Disclosure Vulnerability | 2,7% | — |
| CVE-2021-41331 | HIGH 7.8 | microsoft windows_10 Windows Media Audio Decoder Remote Code Execution Vulnerability | 2,0% | — |
| CVE-2021-41330 | HIGH 7.8 | microsoft windows_10 Microsoft Windows Media Foundation Remote Code Execution Vulnerability | 2,0% | — |
| CVE-2021-41303 | CRIT 9.8 | apache shiro Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass. Users should update to Apache Shiro 1.8.0. | 76,7% | — |
| CVE-2021-41079 | HIGH 7.5 | apache tomcat Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets. When Tomcat was configured to use NIO+OpenSSL or NIO2+OpenSSL for TLS, a specially crafted packet could be used to trigger an infinite loo | 7,2% | — |
| CVE-2021-41073 | HIGH 7.8 | debian debian_linux loop_rw_iter in fs/io_uring.c in the Linux kernel 5.10 through 5.14.6 allows local users to gain privileges by using IORING_OP_PROVIDE_BUFFERS to trigger a free of a kernel buffer, as demonstrated by using /proc/<pid>/maps for exploitation. | 1,7% | — |
| CVE-2021-41057 | HIGH 7.1 | siemens pss_cape In WIBU CodeMeter Runtime before 7.30a, creating a crafted CmDongles symbolic link will overwrite the linked file without checking permissions. | 0,3% | — |
| CVE-2021-4104 | HIGH 7.5 | apache log4j JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to per | 81,1% | — |
| CVE-2021-41032 | MED 6.3 | fortinet fortios An improper access control vulnerability [CWE-284] in FortiOS versions 6.4.8 and prior and 7.0.3 and prior may allow an authenticated attacker with a restricted user profile to gather sensitive information and modify the SSL-VPN tunnel status of other VDOMs us | 0,6% | — |
| CVE-2021-41031 | HIGH 7.8 | fortinet forticlient A relative path traversal vulnerability [CWE-23] in FortiClient for Windows versions 7.0.2 and prior, 6.4.6 and prior and 6.2.9 and below may allow a local unprivileged attacker to escalate their privileges to SYSTEM via the named pipe responsible for FortiESN | 0,5% | — |
| CVE-2021-41030 | MED 5.4 | fortinet forticlient_enterprise_management_server An authentication bypass by capture-replay vulnerability [CWE-294] in FortiClient EMS versions 7.0.1 and below and 6.4.4 and below may allow an unauthenticated attacker to impersonate an existing user by intercepting and re-using valid SAML authentication mess | 1,0% | — |
| CVE-2021-41029 | MED 6.4 | fortinet fortiwlm A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWLM version 8.6.1 and below allows attacker to store malicious javascript code in the device and trigger it via crafted HTTP requests | 0,5% | — |
| CVE-2021-41028 | HIGH 8.2 | fortinet forticlient A combination of a use of hard-coded cryptographic key vulnerability [CWE-321] in FortiClientEMS 7.0.1 and below, 6.4.6 and below and an improper certificate validation vulnerability [CWE-297] in FortiClientWindows, FortiClientLinux and FortiClientMac 7.0.1 an | 0,2% | — |
| CVE-2021-41027 | HIGH 7.3 | fortinet fortiweb A stack-based buffer overflow in Fortinet FortiWeb version 6.4.1 and 6.4.0, allows an authenticated attacker to execute unauthorized code or commands via crafted certificates loaded into the device. | 0,2% | — |
| CVE-2021-41026 | MED 6.5 | fortinet fortiweb A relative path traversal in FortiWeb versions 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allow an authenticated attacker to retrieve arbitrary files from the underlying filesystem via specially crafted web requests. | 0,9% | — |
| CVE-2021-41025 | HIGH 7.3 | fortinet fortiweb Multiple vulnerabilities in the authentication mechanism of confd in FortiWeb versions 6.4.1, 6.4.0, 6.3.0 through 6.3.15, 6.2.0 through 6.2.6, 6.1.0 through 6.1.2, 6.0.0 thorugh 6.0.7, including an instance of concurrent execution using shared resource with i | 1,4% | — |
| CVE-2021-41024 | HIGH 7.5 | fortinet fortios A relative path traversal [CWE-23] vulnerabiltiy in FortiOS versions 7.0.0 and 7.0.1 and FortiProxy verison 7.0.0 may allow an unauthenticated, unauthorized attacker to inject path traversal character sequences to disclose sensitive information of the server v | 1,6% | — |
| CVE-2021-41023 | MED 5.5 | fortinet fortisiem A unprotected storage of credentials in Fortinet FortiSIEM Windows Agent version 4.1.4 and below allows an authenticated user to disclosure agent password due to plaintext credential storage in log files | 0,2% | — |
| CVE-2021-41022 | HIGH 7.8 | fortinet fortisiem A improper privilege management in Fortinet FortiSIEM Windows Agent version 4.1.4 and below allows attacker to execute privileged code or commands via powershell scripts | 0,2% | — |
| CVE-2021-41021 | HIGH 7.8 | fortinet fortinac A privilege escalation vulnerability in FortiNAC versions 8.8.8 and below and 9.1.2 and below may allow an admin user to escalate the privileges to root via the sudo command. | 0,3% | — |
| CVE-2021-41020 | HIGH 8.8 | fortinet fortiisolator An improper access control vulnerability [CWE-284] in FortiIsolator versions 2.3.2 and below may allow an authenticated, non privileged attacker to regenerate the CA certificate via the regeneration URL. | 0,6% | — |
| CVE-2021-41019 | LOW 3.5 | fortinet fortios An improper validation of certificate with host mismatch [CWE-297] vulnerability in FortiOS versions 6.4.6 and below may allow the connection to a malicious LDAP server via options in GUI, leading to disclosure of sensitive information, such as AD credentials. | 0,6% | — |
| CVE-2021-41018 | HIGH 8.8 | fortinet fortiweb A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests. | 3,3% | — |
| CVE-2021-41017 | HIGH 8.8 | fortinet fortiweb Multiple heap-based buffer overflow vulnerabilities in some web API controllers of FortiWeb 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allow a remote authenticated attacker to execute arbitrary code or commands via specifically crafted HTTP requests. | 1,9% | — |