EN
58.046 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.046 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordinato dal più basso
CVE-2021-20239 LOW 3.3 fedoraproject fedora A flaw was found in the Linux kernel in versions before 5.4.92 in the BPF protocol. This flaw allows an attacker with a local account to leak information about kernel internal addresses. The highest threat from this vulnerability is to confidentiality. 0,3%
CVE-2021-20226 HIGH 7.8 linux linux_kernel A use-after-free flaw was found in the io_uring in Linux kernel, where a local attacker with a user privilege could cause a denial of service problem on the system The issue results from the lack of validating the existence of an object prior to performing ope 0,4%
CVE-2021-20219 MED 5.5 linux linux_kernel A denial of service vulnerability was found in n_tty_receive_char_special in drivers/tty/n_tty.c of the Linux kernel. In this flaw a local attacker with a normal user privilege could delay the loop (due to a changing ldata->read_head, and a missing sanity chec 0,4%
CVE-2021-20194 HIGH 7.8 linux linux_kernel There is a vulnerability in the linux kernel versions higher than 5.2 (if kernel compiled with config params CONFIG_BPF_SYSCALL=y , CONFIG_BPF=y , CONFIG_CGROUPS=y , CONFIG_CGROUP_BPF=y , CONFIG_HARDENED_USERCOPY not set, and BPF hook to getsockopt is register 0,4%
CVE-2021-20190 HIGH 8.1 apache nifi A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. 7,4%
CVE-2021-2018 HIGH 8.3 oracle adaptive_access_manager Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 18c and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advan 1,4%
CVE-2021-20177 MED 4.4 linux linux_kernel A flaw was found in the Linux kernel's implementation of string matching within a packet. A privileged user (with root or CAP_NET_ADMIN) when inserting iptables rules could insert a rule which can panic the system. Kernel before kernel 5.5-rc1 is affected. 0,3%
CVE-2021-20100 MED 6.7 tenable nessus Nessus Agent 8.2.4 and earlier for Windows were found to contain multiple local privilege escalation vulnerabilities which could allow an authenticated, local administrator to run specific Windows executables as the Nessus host. This is different than CVE-2021 0,5%
CVE-2021-20099 MED 6.7 tenable nessus Nessus Agent 8.2.4 and earlier for Windows were found to contain multiple local privilege escalation vulnerabilities which could allow an authenticated, local administrator to run specific Windows executables as the Nessus host. This is different than CVE-2021 0,4%
CVE-2021-20081 HIGH 7.2 zohocorp manageengine_servicedesk_plus Incomplete List of Disallowed Inputs in ManageEngine ServiceDesk Plus before version 11205 allows a remote, authenticated attacker to execute arbitrary commands with SYSTEM privileges. 52,4%
CVE-2021-1734 HIGH 7.5 microsoft windows_10 Windows Remote Procedure Call Information Disclosure Vulnerability 3,6%
CVE-2021-1733 HIGH 7.8 microsoft psexec Sysinternals PsExec Elevation of Privilege Vulnerability 0,5%
CVE-2021-1731 MED 5.5 microsoft windows_10 PFX Encryption Security Feature Bypass Vulnerability 0,8%
CVE-2021-1730 MED 5.4 microsoft exchange_server <p>A spoofing vulnerability exists in Microsoft Exchange Server which could result in an attack that would allow a malicious actor to impersonate the user.</p> <p>This update addresses this vulnerability.</p> <p>To prevent these types of attacks, Microsoft rec 1,8%
CVE-2021-1729 HIGH 7.1 microsoft windows_10 Windows Update Stack Setup Elevation of Privilege Vulnerability 0,9%
CVE-2021-1728 HIGH 8.8 microsoft system_center_operations_manager System Center Operations Manager Elevation of Privilege Vulnerability 1,8%
CVE-2021-1727 HIGH 7.8 microsoft windows_10 Windows Installer Elevation of Privilege Vulnerability 0,8%
CVE-2021-1726 HIGH 8.0 microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability 2,0%
CVE-2021-1725 MED 5.5 microsoft bot_framework_software_development_kit Bot Framework SDK Information Disclosure Vulnerability 1,1%
CVE-2021-1724 MED 6.1 microsoft dynamics_365_business_central Microsoft Dynamics Business Central Cross-site Scripting Vulnerability 1,2%
CVE-2021-1723 HIGH 7.5 fedoraproject fedora ASP.NET Core and Visual Studio Denial of Service Vulnerability 4,9%
CVE-2021-1722 HIGH 8.1 microsoft windows_10 Windows Fax Service Remote Code Execution Vulnerability 2,3%
CVE-2021-1721 MED 6.5 microsoft .net .NET Core and Visual Studio Denial of Service Vulnerability 3,3%
CVE-2021-1719 HIGH 8.0 microsoft sharepoint_enterprise_server Microsoft SharePoint Elevation of Privilege Vulnerability 2,2%
CVE-2021-1718 HIGH 8.0 microsoft sharepoint_foundation Microsoft SharePoint Server Tampering Vulnerability 2,6%