57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.971 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2021-37580 | CRIT 9.8 | apache shenyu A flaw was found in Apache ShenYu Admin. The incorrect use of JWT in ShenyuAdminBootstrap allows an attacker to bypass authentication. This issue affected Apache ShenYu 2.3.0 and 2.4.0 | 41,9% | — |
| CVE-2021-37579 | CRIT 9.8 | apache dubbo The Dubbo Provider will check the incoming request and the corresponding serialization type of this request meet the configuration set by the server. But there's an exception that the attacker can use to skip the security check (when enabled) and reaching a de | 6,6% | — |
| CVE-2021-37578 | CRIT 9.8 | apache juddi Apache jUDDI uses several classes related to Java's Remote Method Invocation (RMI) which (as an extension to UDDI) provides an alternate transport for accessing UDDI services. RMI uses the default Java serialization mechanism to pass parameters in RMI invocati | 4,1% | — |
| CVE-2021-37576 | HIGH 7.8 | fedoraproject fedora arch/powerpc/kvm/book3s_rtas.c in the Linux kernel through 5.13.5 on the powerpc platform allows KVM guest OS users to cause host OS memory corruption via rtas_args.nargs, aka CID-f62f3c20647e. | 0,6% | — |
| CVE-2021-37533 | MED 6.5 | apache commons_net Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default. A malicious server can redirect the Commons Net code to use a different host, but the user has to connect to the malicious server in the first place. This may le | 2,1% | — |
| CVE-2021-3753 | MED 4.7 | linux linux_kernel A race problem was seen in the vt_k_ioctl in drivers/tty/vt/vt_ioctl.c in the Linux kernel, which may cause an out of bounds read in vt as the write access to vc_mode is not protected by lock-in vt_ioctl (KDSETMDE). The highest threat from this vulnerability i | 0,4% | — |
| CVE-2021-3752 | HIGH 7.1 | debian debian_linux A use-after-free flaw was found in the Linux kernel’s Bluetooth subsystem in the way user calls connect to the socket and disconnect simultaneously due to a race condition. This flaw allows a user to crash the system or escalate their privileges. The highest t | 1,7% | — |
| CVE-2021-3744 | MED 5.5 | debian debian_linux A memory leak flaw was found in the Linux kernel in the ccp_run_aes_gcm_cmd() function in drivers/crypto/ccp/ccp-ops.c, which allows attackers to cause a denial of service (memory consumption). This vulnerability is similar with the older CVE-2019-18808. | 0,5% | — |
| CVE-2021-3743 | HIGH 7.1 | fedoraproject fedora An out-of-bounds (OOB) memory read flaw was found in the Qualcomm IPC router protocol in the Linux kernel. A missing sanity check allows a local attacker to gain access to out-of-bounds memory, leading to a system crash or a leak of internal kernel information | 0,7% | — |
| CVE-2021-37404 | CRIT 9.8 | apache hadoop There is a potential heap buffer overflow in Apache Hadoop libhdfs native code. Opening a file path provided by user without validation may result in a denial of service or arbitrary code execution. Users should upgrade to Apache Hadoop 2.10.2, 3.2.3, 3.3.2 or | 3,2% | — |
| CVE-2021-3739 | HIGH 7.1 | fedoraproject fedora A NULL pointer dereference flaw was found in the btrfs_rm_device function in fs/btrfs/volumes.c in the Linux Kernel, where triggering the bug requires ‘CAP_SYS_ADMIN’. This flaw allows a local attacker to crash the system or leak kernel internal information. T | 0,6% | — |
| CVE-2021-3736 | MED 5.5 | linux linux_kernel A flaw was found in the Linux kernel. A memory leak problem was found in mbochs_ioctl in samples/vfio-mdev/mbochs.c in Virtual Function I/O (VFIO) Mediated devices. This flaw could allow a local attacker to leak internal kernel information. | 0,2% | — |
| CVE-2021-3732 | MED 5.5 | linux linux_kernel A flaw was found in the Linux kernel's OverlayFS subsystem in the way the user mounts the TmpFS filesystem with OverlayFS. This flaw allows a local user to gain access to hidden files that should not be accessible. | 0,3% | — |
| CVE-2021-3718 | MED 4.3 | lenovo thinkpad_11e_3rd_gen_firmware A denial of service vulnerability was reported in some ThinkPad models that could cause a system to crash when the Enhanced Biometrics setting is enabled in BIOS. | 0,2% | — |
| CVE-2021-37159 | MED 6.4 | debian debian_linux hso_free_net_device in drivers/net/usb/hso.c in the Linux kernel through 5.13.4 calls unregister_netdev without checking for the NETREG_REGISTERED state, leading to a use-after-free and a double free. | 0,4% | — |
| CVE-2021-37150 | HIGH 7.5 | apache traffic_server Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to request secure resources. This issue affects Apache Traffic Server 8.0.0 to 9.1.2. | 2,1% | — |
| CVE-2021-3715 | HIGH 7.8 | linux linux_kernel A flaw was found in the "Routing decision" classifier in the Linux kernel's Traffic Control networking subsystem in the way it handled changing of classification filters, leading to a use-after-free condition. This flaw allows unprivileged local users to escal | 0,4% | — |
| CVE-2021-37149 | HIGH 7.5 | apache traffic_server Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0. | 2,6% | — |
| CVE-2021-37148 | HIGH 7.5 | apache traffic_server Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.0.1. | 2,6% | — |
| CVE-2021-37147 | HIGH 7.5 | apache traffic_server Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0. | 2,5% | — |
| CVE-2021-3714 | MED 5.9 | linux linux_kernel A flaw was found in the Linux kernels memory deduplication mechanism. Previous work has shown that memory deduplication can be attacked via a local exploitation mechanism. The same technique can be used if an attacker can upload page sized files and detect the | 1,5% | — |
| CVE-2021-36975 | HIGH 7.8 | microsoft windows_10 Win32k Elevation of Privilege Vulnerability | 1,3% | — |
| CVE-2021-36974 | HIGH 7.8 | microsoft windows_10 Windows SMB Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2021-36973 | HIGH 7.8 | microsoft windows_10 Windows Redirected Drive Buffering System Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2021-36972 | MED 5.5 | microsoft windows_10 Windows SMB Information Disclosure Vulnerability | 0,9% | — |