58.254 CVE seguite
789 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.254 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più alto |
|---|---|---|---|---|
| CVE-2021-34441 | HIGH 7.8 | microsoft windows_10 Microsoft Windows Media Foundation Remote Code Execution Vulnerability | 2,2% | — |
| CVE-2021-34440 | MED 5.5 | microsoft windows_10 GDI+ Information Disclosure Vulnerability | 0,9% | — |
| CVE-2021-3444 | HIGH 7.8 | canonical ubuntu_linux The bpf verifier in the Linux kernel did not properly handle mod32 destination register truncation when the source register was known to be 0. A local attacker with the ability to load bpf programs could use this gain out-of-bounds reads in kernel memory leadi | 0,6% | — |
| CVE-2021-34439 | HIGH 7.8 | microsoft windows_10 Microsoft Windows Media Foundation Remote Code Execution Vulnerability | 2,6% | — |
| CVE-2021-34438 | HIGH 7.8 | microsoft windows_10 Windows Font Driver Host Remote Code Execution Vulnerability | 2,2% | — |
| CVE-2021-34426 | MED 5.3 | keybase keybase A vulnerability was discovered in the Keybase Client for Windows before version 5.6.0 when a user executed the "keybase git lfs-config" command on the command-line. In versions prior to 5.6.0, a malicious actor with write access to a user\'s Git repository cou | 0,2% | — |
| CVE-2021-34425 | MED 4.7 | zoom meetings The Zoom Client for Meetings before version 5.7.3 (for Android, iOS, Linux, macOS, and Windows) contain a server side request forgery vulnerability in the chat\'s "link preview" functionality. In versions prior to 5.7.3, if a user were to enable the chat\'s "l | 0,8% | — |
| CVE-2021-34424 | HIGH 7.5 | zoom android_meeting_sdk A vulnerability was discovered in the Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Client for Meetings for Blackberry (for Android and iOS) before version 5.8.1, Zoom Client for Meetings for intune (for Andr | 1,7% | — |
| CVE-2021-34423 | CRIT 9.8 | zoom android_meeting_sdk A buffer overflow vulnerability was discovered in Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Client for Meetings for Blackberry (for Android and iOS) before version 5.8.1, Zoom Client for Meetings for intu | 3,3% | — |
| CVE-2021-34400 | MED 4.1 | nvidia dgx-1_p100 NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to gain access to information from unscrubbed memory, which may lead to information disclosure. | 0,2% | — |
| CVE-2021-34399 | MED 4.1 | nvidia dgx-1_p100 NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to gain access to information from unscrubbed registers, which may lead to information disclosure. | 0,2% | — |
| CVE-2021-3428 | MED 5.5 | linux linux_kernel A flaw was found in the Linux kernel. A denial of service problem is identified if an extent tree is corrupted in a crafted ext4 filesystem in fs/ext4/extents.c in ext4_es_cache_extent. Fabricating an integer overflow, A local attacker with a special user priv | 0,3% | — |
| CVE-2021-3411 | MED 6.7 | linux linux_kernel A flaw was found in the Linux kernel in versions prior to 5.10. A violation of memory access was found while detecting a padding of int3 in the linking state. The highest threat from this vulnerability is to data confidentiality and integrity as well as system | 0,4% | — |
| CVE-2021-33909 | HIGH 7.8 | debian debian_linux fs/seq_file.c in the Linux kernel 3.16 through 5.13.x before 5.13.4 does not properly restrict seq buffer allocations, leading to an integer overflow, an Out-of-bounds Write, and escalation to root by an unprivileged user, aka CID-8cae8cd89f05. | 9,7% | — |
| CVE-2021-33900 | HIGH 7.5 | apache directory_studio While investigating DIRSTUDIO-1219 it was noticed that configured StartTLS encryption was not applied when any SASL authentication mechanism (DIGEST-MD5, GSSAPI) was used. While investigating DIRSTUDIO-1220 it was noticed that any configured SASL confidentiali | 0,8% | — |
| CVE-2021-33850 | MED 5.4 | microsoft clarity There is a Cross-Site Scripting vulnerability in Microsoft Clarity version 0.3. The XSS payload executes whenever the user changes the clarity configuration in Microsoft Clarity version 0.3. The payload is stored on the configuring project Id page. | 1,6% | — |
| CVE-2021-33813 | HIGH 7.5 | apache solr An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request. | 19,4% | — |
| CVE-2021-33788 | HIGH 7.5 | microsoft windows_10 Windows LSA Denial of Service Vulnerability | 3,3% | — |
| CVE-2021-33786 | HIGH 8.1 | microsoft windows_server_2008 Windows LSA Security Feature Bypass Vulnerability | 2,1% | — |
| CVE-2021-33785 | HIGH 7.5 | microsoft windows_10 Windows AF_UNIX Socket Provider Denial of Service Vulnerability | 3,3% | — |
| CVE-2021-33784 | HIGH 7.8 | microsoft windows_10 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2021-33783 | MED 6.5 | microsoft windows_10 Windows SMB Information Disclosure Vulnerability | 2,8% | — |
| CVE-2021-33782 | MED 5.5 | microsoft windows_10 Windows Authenticode Spoofing Vulnerability | 2,2% | — |
| CVE-2021-33781 | HIGH 8.1 | microsoft windows_10 Azure AD Security Feature Bypass Vulnerability | 2,4% | — |
| CVE-2021-33780 | HIGH 8.8 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 2,7% | — |