57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.971 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2021-31949 | HIGH 7.3 | microsoft 365_apps Microsoft Outlook Remote Code Execution Vulnerability | 2,6% | — |
| CVE-2021-31948 | HIGH 7.6 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability | 1,3% | — |
| CVE-2021-31947 | HIGH 7.8 | microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability | 2,5% | — |
| CVE-2021-31946 | HIGH 7.8 | microsoft paint_3d Paint 3D Remote Code Execution Vulnerability | 2,9% | — |
| CVE-2021-31945 | HIGH 7.8 | microsoft paint_3d Paint 3D Remote Code Execution Vulnerability | 2,3% | — |
| CVE-2021-31944 | MED 5.0 | microsoft 3d_viewer 3D Viewer Information Disclosure Vulnerability | 2,8% | — |
| CVE-2021-31943 | HIGH 7.8 | microsoft 3d_viewer 3D Viewer Remote Code Execution Vulnerability | 2,4% | — |
| CVE-2021-31942 | HIGH 7.8 | microsoft 3d_viewer 3D Viewer Remote Code Execution Vulnerability | 2,2% | — |
| CVE-2021-31941 | HIGH 7.8 | microsoft 365_apps Microsoft Office Graphics Remote Code Execution Vulnerability | 2,9% | — |
| CVE-2021-31940 | HIGH 7.8 | microsoft 365_apps Microsoft Office Graphics Remote Code Execution Vulnerability | 2,3% | — |
| CVE-2021-31939 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 13,3% | — |
| CVE-2021-31938 | HIGH 7.3 | microsoft kubernetes_tools Microsoft VsCode Kubernetes Tools Extension Elevation of Privilege Vulnerability | 2,0% | — |
| CVE-2021-31937 | HIGH 8.2 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 0,9% | — |
| CVE-2021-31936 | HIGH 7.4 | microsoft accessibility_insights_for_web Microsoft Accessibility Insights for Web Information Disclosure Vulnerability | 3,3% | — |
| CVE-2021-31916 | MED 6.7 | debian debian_linux An out-of-bounds (OOB) memory write flaw was found in list_devices in drivers/md/dm-ioctl.c in the Multi-device driver module in the Linux kernel before 5.12. A bound check failure allows an attacker with special user (CAP_SYS_ADMIN) privilege to gain access t | 0,7% | — |
| CVE-2021-31914 | CRIT 9.8 | jetbrains teamcity In JetBrains TeamCity before 2020.2.4 on Windows, arbitrary code execution on TeamCity Server was possible. | 2,3% | — |
| CVE-2021-31850 | MED 6.1 | mcafee database_security A denial-of-service vulnerability in Database Security (DBS) prior to 4.8.4 allows a remote authenticated administrator to trigger a denial-of-service attack against the DBS server. The configuration of Archiving through the User interface incorrectly allowed | 1,0% | — |
| CVE-2021-31844 | HIGH 8.2 | mcafee data_loss_prevention_endpoint A buffer overflow vulnerability in McAfee Data Loss Prevention (DLP) Endpoint for Windows prior to 11.6.200 allows a local attacker to execute arbitrary code with elevated privileges through placing carefully constructed Ami Pro (.sam) files onto the local sys | 0,4% | — |
| CVE-2021-31829 | MED 5.5 | debian debian_linux kernel/bpf/verifier.c in the Linux kernel through 5.12.1 performs undesirable speculative loads, leading to disclosure of stack content via side-channel attacks, aka CID-801c6058d14a. The specific concern is not protecting the BPF stack area against speculativ | 0,3% | — |
| CVE-2021-31822 | HIGH 7.8 | octopus tentacle When Octopus Tentacle is installed on a Linux operating system, the systemd service file permissions are misconfigured. This could lead to a local unprivileged user modifying the contents of the systemd service file to gain privileged access. | 0,2% | — |
| CVE-2021-31821 | MED 5.5 | octopus tentacle When the Windows Tentacle docker image starts up it logs all the commands that it runs along with the arguments, which writes the Octopus Server API key in plaintext. This does not affect the Linux Docker image | 0,2% | — |
| CVE-2021-31820 | HIGH 7.5 | octopus octopus_server In Octopus Server after version 2018.8.2 if the Octopus Server Web Request Proxy is configured with authentication, the password is shown in plaintext in the UI. | 0,6% | — |
| CVE-2021-31812 | MED 5.5 | apache pdfbox In Apache PDFBox, a carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions. | 3,1% | — |
| CVE-2021-31811 | MED 5.5 | apache pdfbox In Apache PDFBox, a carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions. | 3,4% | — |
| CVE-2021-31805 | CRIT 9.8 | apache struts The fix issued for CVE-2020-17530 was incomplete. So from Apache Struts 2.0.0 to 2.5.29, still some of the tag’s attributes could perform a double evaluation if a developer applied forced OGNL evaluation by using the %{...} syntax. Using forced OGNL evaluation | 85,4% | — |