57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.971 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2021-40460 | MED 6.5 | microsoft windows_10 Windows Remote Procedure Call Runtime Security Feature Bypass Vulnerability | 1,6% | — |
| CVE-2021-40457 | HIGH 7.4 | microsoft dynamics_365 Microsoft Dynamics 365 Customer Engagement Cross-Site Scripting Vulnerability | 1,6% | — |
| CVE-2021-40456 | MED 5.3 | microsoft windows_server Windows AD FS Security Feature Bypass Vulnerability | 2,3% | — |
| CVE-2021-40455 | MED 5.5 | microsoft windows_10 Windows Installer Spoofing Vulnerability | 0,6% | — |
| CVE-2021-40454 | MED 5.5 | microsoft 365_apps Rich Text Edit Control Information Disclosure Vulnerability | 0,5% | — |
| CVE-2021-40453 | HIGH 7.8 | microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability | 2,2% | — |
| CVE-2021-40452 | HIGH 7.8 | microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability | 2,5% | — |
| CVE-2021-40448 | MED 6.3 | microsoft accessibility_insights_for_android Microsoft Accessibility Insights for Android Information Disclosure Vulnerability | 3,2% | — |
| CVE-2021-40447 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2021-40443 | HIGH 7.8 | microsoft windows_10 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2021-40442 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 2,3% | — |
| CVE-2021-40441 | HIGH 7.8 | microsoft windows_7 Windows Media Center Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2021-40440 | MED 5.4 | microsoft dynamics_365_business_central Microsoft Dynamics Business Central Cross-site Scripting Vulnerability | 1,1% | — |
| CVE-2021-40439 | MED 6.5 | apache openoffice Apache OpenOffice has a dependency on expat software. Versions prior to 2.1.0 were subject to CVE-2013-0340 a "Billion Laughs" entity expansion denial of service attack and exploit via crafted XML files. ODF files consist of a set of XML files. All versions of | 3,9% | — |
| CVE-2021-4040 | MED 5.3 | apache artemis A flaw was found in AMQ Broker. This issue can cause a partial interruption to the availability of AMQ Broker via an Out of memory (OOM) condition. This flaw allows an attacker to partially disrupt availability to the broker through a sustained attack of malic | 3,1% | — |
| CVE-2021-4037 | MED 4.4 | debian debian_linux A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create files for the XFS file-system with an unintended group ownership and with group execution and SGID permission bits set, in a sce | 0,3% | — |
| CVE-2021-40369 | MED 6.1 | apache jspwiki A carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the Denounce plugin, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. A | 3,3% | — |
| CVE-2021-40331 | HIGH 8.1 | apache ranger An Incorrect Permission Assignment for Critical Resource vulnerability was found in the Apache Ranger Hive Plugin. Any user with SELECT privilege on a database can alter the ownership of the table in Hive when Apache Ranger Hive Plugin is enabled This issue af | 0,9% | — |
| CVE-2021-40326 | MED 5.5 | foxit pdf_editor Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, mishandle hidden and incremental data in signed documents. An attacker can write to an arbitrary file, and display controlled contents, during signature verification. | 0,3% | — |
| CVE-2021-4032 | MED 4.4 | linux linux_kernel A vulnerability was found in the Linux kernel's KVM subsystem in arch/x86/kvm/lapic.c kvm_free_lapic when a failure allocation was detected. In this flaw the KVM subsystem may crash the kernel due to mishandling of memory errors that happens during VCPU constr | 0,4% | — |
| CVE-2021-4028 | HIGH 7.8 | linux linux_kernel A flaw in the Linux kernel's implementation of RDMA communications manager listener code allowed an attacker with local access to setup a socket to listen on a high port allowing for a list element to be used after free. Given the ability to execute code, a lo | 0,3% | — |
| CVE-2021-4023 | MED 5.5 | fedoraproject fedora A flaw was found in the io-workqueue implementation in the Linux kernel versions prior to 5.15-rc1. The kernel can panic when an improper cancellation operation triggers the submission of new io-uring operations during a shortage of free space. This flaw allow | 0,2% | — |
| CVE-2021-40146 | CRIT 9.8 | apache any23 A Remote Code Execution (RCE) vulnerability was discovered in the Any23 YAMLExtractor.java file and is known to affect Any23 versions < 2.5. RCE vulnerabilities allow a malicious actor to execute any code of their choice on a remote machine over LAN, WAN, or i | 5,7% | — |
| CVE-2021-40131 | MED 5.5 | cisco common_services_platform_collector A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to | 0,7% | — |
| CVE-2021-40130 | MED 4.9 | cisco common_services_platform_collector A vulnerability in the web application of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to specify non-log files as sources for syslog reporting. This vulnerability is due to improper restriction of the syslog co | 1,1% | — |