58.306 CVE seguite
790 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.306 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più alto |
|---|---|---|---|---|
| CVE-2021-26691 | CRIT 9.8 | apache http_server In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a heap overflow | 68,3% | — |
| CVE-2021-26690 | HIGH 7.5 | apache http_server Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Cookie header handled by mod_session can cause a NULL pointer dereference and crash, leading to a possible Denial Of Service | 65,3% | — |
| CVE-2021-26677 | HIGH 7.8 | arubanetworks clearpass_policy_manager A local authenticated escalation of privilege vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in ClearPass OnGuard could allow local authenticated users on a Windows platform to | 0,3% | — |
| CVE-2021-26644 | HIGH 8.8 | mangboard mangboard_wp SQL-Injection vulnerability caused by the lack of verification of input values for the table name of DB used by the Mangboard bulletin board. A remote attacker can use this vulnerability to execute arbitrary code on the server where the bulletin board is runni | 0,9% | — |
| CVE-2021-26642 | HIGH 8.8 | xpressengine xpressengine When uploading an image file to a bulletin board developed with XpressEngine, a vulnerability in which an arbitrary file can be uploaded due to insufficient verification of the file. A remote attacker can use this vulnerability to execute arbitrary code on the | 1,2% | — |
| CVE-2021-26639 | HIGH 8.1 | wisa smart_wing_cms This vulnerability is caused by the lack of validation of input values for specific functions if WISA Smart Wing CMS. Remote attackers can use this vulnerability to leak all files in the server without logging in system. | 0,5% | — |
| CVE-2021-26636 | HIGH 8.8 | maxb maxboard Stored XSS and SQL injection vulnerability in MaxBoard could lead to occur Remote Code Execution, which could lead to information exposure and privilege escalation. | 1,5% | — |
| CVE-2021-26634 | CRIT 9.8 | maxb maxboard SQL injection and file upload attacks are possible due to insufficient validation of input values in some parameters and variables of files compromising Maxboard, which may lead to arbitrary code execution or privilege escalation. Attackers can use these vulne | 1,3% | — |
| CVE-2021-26633 | HIGH 7.5 | maxb maxboard SQL injection and Local File Inclusion (LFI) vulnerabilities in MaxBoard can cause information leakage and privilege escalation. This vulnerabilities can be exploited by manipulating a variable with a desired value and inserting and arbitrary file. | 0,9% | — |
| CVE-2021-26630 | HIGH 7.8 | handysoft groupware Improper input validation vulnerability in HANDY Groupware’s ActiveX moudle allows attackers to download or execute arbitrary files. This vulnerability can be exploited by using the file download or execution path as the parameter value of the vulnerable funct | 0,8% | — |
| CVE-2021-26629 | HIGH 8.8 | tobesoft xplatform A path traversal vulnerability in XPLATFORM's runtime archive function could lead to arbitrary file creation. When the .xzip archive file is decompressed, an arbitrary file can be d in the parent path by using the path traversal pattern ‘..\’. | 1,6% | — |
| CVE-2021-26626 | HIGH 8.1 | tobesoft xplatform Improper input validation vulnerability in XPLATFORM's execBrowser method can cause execute arbitrary commands. IF the second parameter value of the execBrowser function is ‘default’, the first parameter value could be passed to the ShellExecuteW API. The pass | 1,3% | — |
| CVE-2021-26625 | HIGH 8.8 | tobesoft nexacro Insufficient Verification of input Data leading to arbitrary file download and execute was discovered in Nexacro platform. This vulnerability is caused by an automatic update function that does not verify input data except version information. Remote attackers | 0,6% | — |
| CVE-2021-26623 | HIGH 7.8 | bandisoft bandizip A remote code execution vulnerability due to incomplete check for 'xheader_decode_path_record' function's parameter length value in the ark library. Remote attackers can induce exploit malicious code using this function. | 1,1% | — |
| CVE-2021-26622 | CRIT 9.6 | genians genian_nac An remote code execution vulnerability due to SSTI vulnerability and insufficient file name parameter validation was discovered in Genian NAC. Remote attackers are able to execute arbitrary malicious code with SYSTEM privileges on all connected nodes in NAC th | 3,0% | — |
| CVE-2021-26619 | HIGH 7.1 | bigfile bigfileagent An path traversal vulnerability leading to delete arbitrary files was discovered in BigFileAgent. Remote attackers can use this vulnerability to delete arbitrary files of unspecified number of users. | 0,9% | — |
| CVE-2021-26618 | HIGH 7.1 | tmax tooffice An improper input validation leading to arbitrary file creation was discovered in ToWord of ToOffice. Remote attackers use this vulnerability to execute arbitrary file included malicious code. | 1,0% | — |
| CVE-2021-26617 | HIGH 8.1 | firstmall firstmall This issues due to insufficient verification of the various input values from user’s input. The vulnerability allows remote attackers to execute malicious code in Firstmall via navercheckout_add function. | 1,3% | — |
| CVE-2021-26615 | HIGH 7.8 | bandisoft ark_library ARK library allows attackers to execute remote code via the parameter(path value) of Ark_NormalizeAndDupPAthNameW function because of an integer overflow. | 0,7% | — |
| CVE-2021-26613 | HIGH 8.1 | tobesoft nexacro improper input validation vulnerability in nexacro permits copying file to the startup folder using rename method. | 0,8% | — |
| CVE-2021-26612 | HIGH 8.1 | tobesoft nexacro An improper input validation leading to arbitrary file creation was discovered in copy method of Nexacro platform. Remote attackers use copy method to execute arbitrary command after the file creation included malicious code. | 1,2% | — |
| CVE-2021-26610 | HIGH 7.2 | nhn-commerce godomall5 The move_uploaded_file function in godomall5 does not perform an integrity check of extension or authority when user upload file. This vulnerability allows an attacker to execute an remote arbitrary code. | 0,5% | — |
| CVE-2021-26608 | HIGH 8.8 | handysoft hshell An arbitrary file download and execution vulnerability was found in the HShell.dll of handysoft Co., Ltd groupware ActiveX module. This issue is due to missing support for integrity check of download URL or downloaded file hash. | 0,6% | — |
| CVE-2021-26607 | HIGH 8.1 | tobesoft nexacro An Improper input validation in execDefaultBrowser method of NEXACRO17 allows a remote attacker to execute arbitrary command on affected systems. | 1,9% | — |
| CVE-2021-26606 | CRIT 9.8 | dreamsecurity magicline4nx.exe A vulnerability in PKI Security Solution of Dream Security could allow arbitrary command execution. This vulnerability is due to insufficient validation of the authorization certificate. An attacker could exploit this vulnerability by sending a crafted HTTP re | 2,4% | — |