57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.971 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2021-34698 | HIGH 8.6 | cisco asyncos A vulnerability in the proxy service of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to exhaust system memory and cause a denial of service (DoS) condition on an affected device. This vulnerability is due | 1,4% | — |
| CVE-2021-34697 | MED 5.8 | cisco ios_xe A vulnerability in the Protection Against Distributed Denial of Service Attacks feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct denial of service (DoS) attacks to or through the affected device. This vulnerability is | 1,3% | — |
| CVE-2021-34696 | MED 5.8 | cisco ios_xe A vulnerability in the access control list (ACL) programming of Cisco ASR 900 and ASR 920 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to incorrect programming of hard | 1,0% | — |
| CVE-2021-34693 | MED 5.5 | debian debian_linux net/can/bcm.c in the Linux kernel through 5.12.10 allows local users to obtain sensitive information from kernel stack memory because parts of a data structure are uninitialized. | 0,5% | — |
| CVE-2021-34692 | HIGH 7.8 | idrive remotepc iDrive RemotePC before 7.6.48 on Windows allows privilege escalation. A local and low-privileged user can force RemotePC to execute an attacker-controlled executable with SYSTEM privileges. | 0,3% | — |
| CVE-2021-34691 | HIGH 7.5 | idrive remotepc iDrive RemotePC before 4.0.1 on Linux allows denial of service. A remote and unauthenticated attacker can disconnect a valid user session by connecting to an ephemeral port. | 1,0% | — |
| CVE-2021-34690 | CRIT 9.8 | idrive remotepc iDrive RemotePC before 7.6.48 on Windows allows authentication bypass. A remote and unauthenticated attacker can bypass cloud authentication to connect and control a system via TCP port 5970 and 5980. | 1,2% | — |
| CVE-2021-34689 | MED 5.5 | idrive remotepc iDrive RemotePC before 7.6.48 on Windows allows information disclosure. A locally authenticated attacker can read the system's Personal Key in world-readable %PROGRAMDATA% log files. | 0,3% | — |
| CVE-2021-34688 | LOW 3.3 | idrive remotepc iDrive RemotePC before 7.6.48 on Windows allows information disclosure. A locally authenticated attacker can read an encrypted version of the system's Personal Key in world-readable %PROGRAMDATA% log files. The encryption is done using a hard-coded static key | 0,2% | — |
| CVE-2021-34687 | MED 5.3 | idrive remotepc iDrive RemotePC before 7.6.48 on Windows allows information disclosure. A man in the middle can recover a system's Personal Key when a client attempts to make a LAN connection. The Personal Key is transmitted over the network while only being encrypted via a s | 0,2% | — |
| CVE-2021-34556 | MED 5.5 | debian debian_linux In the Linux kernel through 5.13.7, an unprivileged BPF program can obtain sensitive information from kernel memory via a Speculative Store Bypass side-channel attack because the protection mechanism neglects the possibility of uninitialized memory locations o | 0,4% | — |
| CVE-2021-34551 | HIGH 8.1 | fedoraproject fedora PHPMailer before 6.5.0 on Windows allows remote code execution if lang_path is untrusted data and has a UNC pathname. | 2,8% | — |
| CVE-2021-34538 | HIGH 7.5 | apache hive Apache Hive before 3.1.3 "CREATE" and "DROP" function operations does not check for necessary authorization of involved entities in the query. It was found that an unauthorized user can manipulate an existing UDF without having the privileges to do so. This al | 1,8% | — |
| CVE-2021-34537 | HIGH 7.8 | microsoft windows_10 Windows Bluetooth Driver Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2021-34536 | HIGH 7.8 | microsoft windows_10 Windows Storage Spaces Controller Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2021-34535 | HIGH 8.8 | microsoft remote_desktop_client Remote Desktop Client Remote Code Execution Vulnerability | 21,7% | — |
| CVE-2021-34534 | MED 6.8 | microsoft windows_10 Windows MSHTML Platform Remote Code Execution Vulnerability | 2,2% | — |
| CVE-2021-34533 | HIGH 7.8 | microsoft windows_10 Windows Graphics Component Font Parsing Remote Code Execution Vulnerability | 2,4% | — |
| CVE-2021-34532 | MED 5.5 | microsoft asp.net_core ASP.NET Core and Visual Studio Information Disclosure Vulnerability | 1,2% | — |
| CVE-2021-34530 | HIGH 7.8 | microsoft windows_10 Windows Graphics Component Remote Code Execution Vulnerability | 2,4% | — |
| CVE-2021-34529 | HIGH 7.8 | microsoft visual_studio_code Visual Studio Code Remote Code Execution Vulnerability | 5,1% | — |
| CVE-2021-34528 | HIGH 7.8 | microsoft visual_studio_code Visual Studio Code Remote Code Execution Vulnerability | 3,1% | — |
| CVE-2021-34525 | HIGH 8.8 | microsoft windows_server_2012 Windows DNS Server Remote Code Execution Vulnerability | 2,2% | — |
| CVE-2021-34524 | HIGH 8.1 | microsoft dynamics_365 Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability | 3,6% | — |
| CVE-2021-34522 | HIGH 7.8 | microsoft malware_protection_engine Microsoft Defender Remote Code Execution Vulnerability | 2,7% | — |