EN
57.977 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

57.977 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordinato dal più basso
CVE-2021-26421 MED 6.5 microsoft lync_server Skype for Business and Lync Spoofing Vulnerability 1,4%
CVE-2021-26420 HIGH 7.1 microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability 3,0%
CVE-2021-26419 HIGH 7.5 microsoft internet_explorer Scripting Engine Memory Corruption Vulnerability 22,8%
CVE-2021-26418 MED 4.6 microsoft sharepoint_foundation Microsoft SharePoint Server Spoofing Vulnerability 1,2%
CVE-2021-26417 MED 5.5 microsoft windows_10 Windows Overlay Filter Information Disclosure Vulnerability 0,8%
CVE-2021-26416 HIGH 7.7 microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability 3,9%
CVE-2021-26415 HIGH 7.8 microsoft windows_10 Windows Installer Elevation of Privilege Vulnerability 3,6%
CVE-2021-26414 MED 4.8 microsoft windows_10 Windows DCOM Server Security Feature Bypass 49,8%
CVE-2021-26413 MED 6.2 microsoft windows_10 Windows Installer Spoofing Vulnerability 0,7%
CVE-2021-26412 CRIT 9.1 microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability 33,0%
CVE-2021-26334 CRIT 9.9 amd amd_uprof The AMDPowerProfiler.sys driver of AMD μProf tool may allow lower privileged users to access MSRs in kernel which may lead to privilege escalation and ring-0 code execution by the lower privileged user. 1,2%
CVE-2021-26296 HIGH 7.5 apache myfaces In the default configuration, Apache MyFaces Core versions 2.2.0 to 2.2.13, 2.3.0 to 2.3.7, 2.3-next-M1 to 2.3-next-M4, and 3.0.0-RC1 use cryptographically weak implicit and explicit cross-site request forgery (CSRF) tokens. Due to that limitation, it is possi 3,0%
CVE-2021-26295 CRIT 9.8 apache ofbiz Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to successfully take over Apache OFBiz. 97,8%
CVE-2021-26291 CRIT 9.1 apache maven Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting in potential risk if a malicious actor takes over that repository or is able to insert themselves into a positi 8,7%
CVE-2021-26118 HIGH 7.5 apache artemis While investigating ARTEMIS-2964 it was found that the creation of advisory messages in the OpenWire protocol head of Apache ActiveMQ Artemis 2.15.0 bypassed policy based access control for the entire session. Production of advisory messages was not subject to 3,9%
CVE-2021-26117 HIGH 7.5 apache activemq The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to v 11,3%
CVE-2021-26116 MED 6.7 fortinet fortiauthenticator An improper neutralization of special elements used in an OS command vulnerability in the command line interpreter of FortiAuthenticator before 6.3.1 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to exi 0,6%
CVE-2021-26115 HIGH 7.8 fortinet fortiwan An OS command injection (CWE-78) vulnerability in FortiWAN version 4.5.7 and below Command Line Interface may allow a local, authenticated and unprivileged attacker to escalate their privileges to root via executing a specially-crafted command.An OS command in 0,8%
CVE-2021-26114 CRIT 9.8 fortinet fortiwan Multiple improper neutralization of special elements used in an SQL command vulnerabilities in FortiWAN before 4.5.9 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests. 1,6%
CVE-2021-26113 MED 6.2 fortinet fortiwan A use of a one-way hash with a predictable salt vulnerability [CWE-760] in FortiWAN before 4.5.9 may allow an attacker who has previously come in possession of the password file to potentially guess passwords therein stored. 0,4%
CVE-2021-26112 HIGH 8.1 fortinet fortiwan Multiple stack-based buffer overflow vulnerabilities [CWE-121] both in network daemons and in the command line interpreter of FortiWAN before 4.5.9 may allow an unauthenticated attacker to potentially corrupt control data in memory and execute arbitrary code v 1,7%
CVE-2021-26111 MED 6.5 fortinet fortiswitch A missing release of memory after effective lifetime vulnerability in FortiSwitch 6.4.0 to 6.4.6, 6.2.0 to 6.2.6, 6.0.0 to 6.0.6, 3.6.11 and below may allow an attacker on an adjacent network to exhaust available memory by sending specifically crafted LLDP/CDP 0,4%
CVE-2021-26110 HIGH 7.8 fortinet fortios An improper access control vulnerability [CWE-284] in FortiOS autod daemon 7.0.0, 6.4.6 and below, 6.2.9 and below, 6.0.12 and below and FortiProxy 2.0.1 and below, 1.2.9 and below may allow an authenticated low-privileged attacker to escalate their privileges 0,2%
CVE-2021-26109 HIGH 8.1 fortinet fortios An integer overflow or wraparound vulnerability in the memory allocator of SSLVPN in FortiOS before 7.0.1 may allow an unauthenticated attacker to corrupt control data on the heap via specifically crafted requests to SSLVPN, resulting in potentially arbitrary 1,8%
CVE-2021-26108 HIGH 7.5 fortinet fortios A use of hard-coded cryptographic key vulnerability in the SSLVPN of FortiOS before 7.0.1 may allow an attacker to retrieve the key by reverse engineering. 1,0%