58.254 CVE seguite
789 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.254 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più alto |
|---|---|---|---|---|
| CVE-2021-31172 | HIGH 7.1 | microsoft sharepoint_foundation Microsoft SharePoint Server Spoofing Vulnerability | 1,8% | — |
| CVE-2021-31171 | MED 4.1 | microsoft sharepoint_foundation Microsoft SharePoint Information Disclosure Vulnerability | 0,6% | — |
| CVE-2021-31170 | HIGH 7.8 | microsoft windows_10 Windows Graphics Component Elevation of Privilege Vulnerability | 1,0% | — |
| CVE-2021-31169 | HIGH 7.8 | microsoft windows_10 Windows Container Manager Service Elevation of Privilege Vulnerability | 1,0% | — |
| CVE-2021-31168 | HIGH 7.8 | microsoft windows_10 Windows Container Manager Service Elevation of Privilege Vulnerability | 1,0% | — |
| CVE-2021-31167 | HIGH 7.8 | microsoft windows_10 Windows Container Manager Service Elevation of Privilege Vulnerability | 1,0% | — |
| CVE-2021-31165 | HIGH 7.8 | microsoft windows_10 Windows Container Manager Service Elevation of Privilege Vulnerability | 1,0% | — |
| CVE-2021-31164 | HIGH 7.5 | apache unomi Apache Unomi prior to version 1.5.5 allows CRLF log injection because of the lack of escaping in the log statements. | 2,3% | — |
| CVE-2021-3115 | HIGH 7.5 | fedoraproject fedora Go before 1.14.14 and 1.15.x before 1.15.7 on Windows is vulnerable to Command Injection and remote code execution when using the "go get" command to fetch modules that make use of cgo (for example, cgo can execute a gcc program from an untrusted download). | 6,5% | — |
| CVE-2021-30641 | MED 5.3 | apache http_server Apache HTTP Server versions 2.4.39 to 2.4.46 Unexpected matching behavior with 'MergeSlashes OFF' | 52,6% | — |
| CVE-2021-30640 | MED 6.5 | apache tomcat A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0-M1 to 10.0.5; 9.0.0.M1 to | 9,9% | — |
| CVE-2021-3064 | CRIT 9.8 | paloaltonetworks pan-os A memory corruption vulnerability exists in Palo Alto Networks GlobalProtect portal and gateway interfaces that enables an unauthenticated network-based attacker to disrupt system processes and potentially execute arbitrary code with root privileges. The attac | 20,1% | — |
| CVE-2021-30639 | HIGH 7.5 | apache tomcat A vulnerability in Apache Tomcat allows an attacker to remotely trigger a denial of service. An error introduced as part of a change to improve error handling during non-blocking I/O meant that the error flag associated with the Request object was not reset be | 6,9% | — |
| CVE-2021-30638 | HIGH 7.5 | apache tapestry Information Exposure vulnerability in context asset handling of Apache Tapestry allows an attacker to download files inside WEB-INF if using a specially-constructed URL. This was caused by an incomplete fix for CVE-2020-13953. This issue affects Apache Tapestr | 6,6% | — |
| CVE-2021-3063 | HIGH 7.5 | paloaltonetworks pan-os An improper handling of exceptional conditions vulnerability exists in Palo Alto Networks GlobalProtect portal and gateway interfaces that enables an unauthenticated network-based attacker to send specifically crafted traffic to a GlobalProtect interface that | 0,9% | — |
| CVE-2021-30624 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30624 Use after free in Autofill | 4,1% | — |
| CVE-2021-30623 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30623 Use after free in Bookmarks | 4,0% | — |
| CVE-2021-30622 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30622 Use after free in WebApp Installs | 4,1% | — |
| CVE-2021-30621 | MED 6.5 | fedoraproject fedora Chromium: CVE-2021-30621 UI Spoofing in Autofill | 3,5% | — |
| CVE-2021-30620 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30620 Insufficient policy enforcement in Blink | 4,1% | — |
| CVE-2021-3062 | HIGH 8.1 | paloaltonetworks pan-os An improper access control vulnerability in PAN-OS software enables an attacker with authenticated access to GlobalProtect portals and gateways to connect to the EC2 instance metadata endpoint for VM-Series firewalls hosted on Amazon AWS. Exploitation of this | 0,7% | — |
| CVE-2021-30619 | MED 6.5 | fedoraproject fedora Chromium: CVE-2021-30619 UI Spoofing in Autofill | 3,5% | — |
| CVE-2021-30618 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30618 Inappropriate implementation in DevTools | 4,1% | — |
| CVE-2021-30617 | MED 6.5 | fedoraproject fedora Chromium: CVE-2021-30617 Policy bypass in Blink | 3,7% | — |
| CVE-2021-30616 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30616 Use after free in Media | 4,1% | — |