57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.971 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2021-36940 | HIGH 7.6 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability | 4,0% | — |
| CVE-2021-36938 | MED 5.5 | microsoft windows_10 Windows Cryptographic Primitives Library Information Disclosure Vulnerability | 0,9% | — |
| CVE-2021-36937 | HIGH 7.8 | microsoft windows_10 Windows Media MPEG-4 Video Decoder Remote Code Execution Vulnerability | 2,3% | — |
| CVE-2021-36936 | HIGH 8.8 | microsoft windows_10 Windows Print Spooler Remote Code Execution Vulnerability | 7,4% | — |
| CVE-2021-36933 | HIGH 7.5 | microsoft windows_10 Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability | 3,5% | — |
| CVE-2021-36932 | HIGH 7.5 | microsoft windows_10 Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability | 3,5% | — |
| CVE-2021-36931 | MED 4.4 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 1,3% | — |
| CVE-2021-36930 | MED 5.3 | microsoft edge Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 1,1% | — |
| CVE-2021-36929 | MED 6.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | 3,2% | — |
| CVE-2021-36928 | MED 6.0 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 0,9% | — |
| CVE-2021-36927 | HIGH 7.8 | microsoft windows_7 Windows Digital TV Tuner device registration application Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2021-36926 | HIGH 7.5 | microsoft windows_10 Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability | 3,5% | — |
| CVE-2021-3679 | MED 5.5 | debian debian_linux A lack of CPU resource in the Linux kernel tracing module functionality in versions prior to 5.14-rc3 was found in the way user uses trace ring buffer in a specific way. Only privileged local users (with CAP_SYS_ADMIN capability) could use this flaw to starve | 0,7% | — |
| CVE-2021-36774 | MED 6.5 | apache kylin Apache Kylin allows users to read data from other database systems using JDBC. The MySQL JDBC driver supports certain properties, which, if left unmitigated, can allow an attacker to execute arbitrary code from a hacker-controlled malicious MySQL server within | 1,9% | — |
| CVE-2021-36749 | MED 6.5 | apache druid In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSource allows authenticated users to read data from other sources than intended, such as the local file system, with the privileges of th | 80,9% | — |
| CVE-2021-36744 | HIGH 7.8 | trendmicro maximum_security_2019 Trend Micro Security (Consumer) 2021 and 2020 are vulnerable to a directory junction vulnerability which could allow an attacker to exploit the system to escalate privileges and create a denial of service. | 0,5% | — |
| CVE-2021-36739 | MED 6.1 | apache pluto The "first name" and "last name" fields of the Apache Pluto 3.1.0 MVCBean JSP portlet maven archetype are vulnerable to Cross-Site Scripting (XSS) attacks. | 2,3% | — |
| CVE-2021-36738 | MED 6.1 | apache pluto The input fields in the JSP version of the Apache Pluto Applicant MVCBean CDI portlet are vulnerable to Cross-Site Scripting (XSS) attacks. Users should migrate to version 3.1.1 of the applicant-mvcbean-cdi-jsp-portlet.war artifact | 2,3% | — |
| CVE-2021-36737 | MED 6.1 | apache pluto The input fields of the Apache Pluto UrlTestPortlet are vulnerable to Cross-Site Scripting (XSS) attacks. Users should migrate to version 3.1.1 of the v3-demo-portlet.war artifact | 2,3% | — |
| CVE-2021-3669 | MED 5.5 | debian debian_linux A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segment counts which could lead to resource exhaustion and DoS. | 0,3% | — |
| CVE-2021-3659 | MED 5.5 | fedoraproject fedora A NULL pointer dereference flaw was found in the Linux kernel’s IEEE 802.15.4 wireless networking subsystem in the way the user closes the LR-WPAN connection. This flaw allows a local user to crash the system. The highest threat from this vulnerability is to s | 0,3% | — |
| CVE-2021-3656 | HIGH 8.8 | fedoraproject fedora A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due to improper validation of the "virt_ext" | 0,7% | — |
| CVE-2021-3655 | LOW 3.3 | debian debian_linux A vulnerability was found in the Linux kernel in versions prior to v5.14-rc1. Missing size validations on inbound SCTP packets may allow the kernel to read uninitialized memory. | 0,3% | — |
| CVE-2021-3653 | HIGH 8.8 | debian debian_linux A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due to improper validation of the "int_ctl" | 0,4% | — |
| CVE-2021-3641 | MED 6.1 | bitdefender gravityzone Improper Link Resolution Before File Access ('Link Following') vulnerability in the EPAG component of Bitdefender Endpoint Security Tools for Windows allows a local attacker to cause a denial of service. This issue affects: Bitdefender GravityZone version 7.1. | 0,4% | — |