58.254 CVE seguite
789 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.254 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più alto |
|---|---|---|---|---|
| CVE-2021-3049 | LOW 2.6 | paloaltonetworks cortex_xsoar An improper authorization vulnerability in the Palo Alto Networks Cortex XSOAR server enables an authenticated network-based attacker with investigation read permissions to download files from incident investigations of which they are aware but are not a part | 0,5% | — |
| CVE-2021-30480 | HIGH 8.5 | zoom chat Zoom Chat through 2021-04-09 on Windows and macOS allows certain remote authenticated attackers to execute arbitrary code without user interaction. An attacker must be within the same organization, or an external party who has been accepted as a contact. NOTE: | 5,8% | — |
| CVE-2021-3048 | MED 5.9 | paloaltonetworks pan-os Certain invalid URL entries contained in an External Dynamic List (EDL) cause the Device Server daemon (devsrvr) to stop responding. This condition causes subsequent commits on the firewall to fail and prevents administrators from performing commits and config | 0,8% | — |
| CVE-2021-3047 | MED 4.2 | paloaltonetworks pan-os A cryptographically weak pseudo-random number generator (PRNG) is used during authentication to the Palo Alto Networks PAN-OS web interface. This enables an authenticated attacker, with the capability to observe their own authentication secrets over a long dur | 0,5% | — |
| CVE-2021-30468 | HIGH 7.5 | apache cxf A vulnerability in the JsonMapObjectReaderWriter of Apache CXF allows an attacker to submit malformed JSON to a web service, which results in the thread getting stuck in an infinite loop, consuming CPU indefinitely. This issue affects Apache CXF versions prior | 7,0% | — |
| CVE-2021-3046 | MED 6.8 | paloaltonetworks pan-os An improper authentication vulnerability exists in Palo Alto Networks PAN-OS software that enables a SAML authenticated attacker to impersonate any other user in the GlobalProtect Portal and GlobalProtect Gateway when they are configured to use SAML authentica | 1,1% | — |
| CVE-2021-3045 | MED 4.9 | paloaltonetworks pan-os An OS command argument injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator to read any arbitrary file from the file system. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.19; PAN-OS 9.0 | 0,8% | — |
| CVE-2021-3044 | CRIT 9.8 | paloaltonetworks cortex_xsoar An improper authorization vulnerability in Palo Alto Networks Cortex XSOAR enables a remote unauthenticated attacker with network access to the Cortex XSOAR server to perform unauthorized actions through the REST API. This issue impacts: Cortex XSOAR 6.1.0 bui | 1,4% | — |
| CVE-2021-3043 | HIGH 7.5 | paloaltonetworks prisma_cloud A reflected cross-site scripting (XSS) vulnerability exists in the Prisma Cloud Compute web console that enables a remote attacker to execute arbitrary JavaScript code in the browser-based web console while an authenticated administrator is using that web inte | 0,6% | — |
| CVE-2021-3042 | HIGH 7.8 | paloaltonetworks cortex_xdr_agent A local privilege escalation (PE) vulnerability exists in the Palo Alto Networks Cortex XDR agent on Windows platforms that enables an authenticated local Windows user to execute programs with SYSTEM privileges. Exploiting this vulnerability requires the user | 0,2% | — |
| CVE-2021-3041 | HIGH 7.8 | paloaltonetworks cortex_xdr_agent A local privilege escalation vulnerability exists in the Palo Alto Networks Cortex XDR agent on Windows platforms that enables an authenticated local Windows user to execute programs with SYSTEM privileges. This requires the user to have the privilege to creat | 0,2% | — |
| CVE-2021-3040 | MED 6.7 | paloaltonetworks bridgecrew_checkov An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud allows arbitrary code execution when processing a malicious terraform file. This issue impacts Checkov 2.0 versions earlier than Checkov 2.0.139. Checkov 1.0 versions are not impacte | 1,3% | — |
| CVE-2021-3039 | LOW 3.8 | paloaltonetworks prisma_cloud An information exposure through log file vulnerability exists in the Palo Alto Networks Prisma Cloud Compute Console where a secret used to authorize the role of the authenticated user is logged to a debug log file. Authenticated Operator role and Auditor role | 0,5% | — |
| CVE-2021-3038 | MED 5.5 | paloaltonetworks globalprotect A denial-of-service (DoS) vulnerability in Palo Alto Networks GlobalProtect app on Windows systems allows a limited Windows user to send specifically-crafted input to the GlobalProtect app that results in a Windows blue screen of death (BSOD) error. This issue | 0,2% | — |
| CVE-2021-3037 | LOW 2.3 | paloaltonetworks pan-os An information exposure through log file vulnerability exists in Palo Alto Networks PAN-OS software where the connection details for a scheduled configuration export are logged in system logs. Logged information includes the cleartext username, password, and I | 0,3% | — |
| CVE-2021-3036 | MED 4.4 | paloaltonetworks pan-os An information exposure through log file vulnerability exists in Palo Alto Networks PAN-OS software where secrets in PAN-OS XML API requests are logged in cleartext to the web server logs when the API is used incorrectly. This vulnerability applies only to PAN | 0,2% | — |
| CVE-2021-30359 | HIGH 7.8 | checkpoint harmony_browse The Harmony Browse and the SandBlast Agent for Browsers installers must have admin privileges to execute some steps during the installation. Because the MS Installer allows regular users to repair their installation, an attacker running an installer before 90. | 3,9% | — |
| CVE-2021-3035 | MED 6.7 | paloaltonetworks bridgecrew_checkov An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud allows arbitrary code execution when processing a malicious terraform file. This issue impacts Checkov 2.0 versions earlier than Checkov 2.0.26. Checkov 1.0 versions are not impacted | 1,3% | — |
| CVE-2021-3034 | MED 5.1 | paloaltonetworks cortex_xsoar An information exposure through log file vulnerability exists in Cortex XSOAR software where the secrets configured for the SAML single sign-on (SSO) integration can be logged to the '/var/log/demisto/' server logs when testing the integration during setup. Th | 0,2% | — |
| CVE-2021-3033 | CRIT 9.1 | paloaltonetworks prisma_cloud An improper verification of cryptographic signature vulnerability exists in the Palo Alto Networks Prisma Cloud Compute console. This vulnerability enables an attacker to bypass signature validation during SAML authentication by logging in to the Prisma Cloud | 1,2% | — |
| CVE-2021-3032 | MED 4.4 | paloaltonetworks pan-os An information exposure through log file vulnerability exists in Palo Alto Networks PAN-OS software where configuration secrets for the “http”, “email”, and “snmptrap” v3 log forwarding server profiles can be logged to the logrcvr.log system log. Logged inform | 0,2% | — |
| CVE-2021-3031 | MED 4.3 | paloaltonetworks pan-os Padding bytes in Ethernet packets on PA-200, PA-220, PA-500, PA-800, PA-2000 Series, PA-3000 Series, PA-3200 Series, PA-5200 Series, and PA-7000 Series firewalls are not cleared before the data frame is created. This leaks a small amount of random information | 0,5% | — |
| CVE-2021-30245 | HIGH 8.8 | apache openoffice The project received a report that all versions of Apache OpenOffice through 4.1.8 can open non-http(s) hyperlinks. The problem has existed since about 2006 and the issue is also in 4.1.9. If the link is specifically crafted this could lead to untrusted code e | 4,9% | — |
| CVE-2021-30181 | CRIT 9.8 | apache dubbo Apache Dubbo prior to 2.6.9 and 2.7.9 supports Script routing which will enable a customer to route the request to the right server. These rules are used by the customers when making a request in order to find the right endpoint. When parsing these rules, Dubb | 60,6% | — |
| CVE-2021-30180 | CRIT 9.8 | apache dubbo Apache Dubbo prior to 2.7.9 support Tag routing which will enable a customer to route the request to the right server. These rules are used by the customers when making a request in order to find the right endpoint. When parsing these YAML rules, Dubbo custome | 60,4% | — |