56.569 CVE seguite
773 Sfruttate ora
181 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.569 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più alto |
|---|---|---|---|---|
| CVE-2017-6742 | HIGH 8.8 | cisco ios A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute code. An attacker could exploit this vulnerability by sending a crafted SNMP packet to the affected devi | 21,4% | |
| CVE-2023-28252 | HIGH 7.8 | ransomware microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 49,0% | |
| CVE-2019-1388 | HIGH 7.8 | ransomware microsoft windows_10_1507 An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user privileges, aka 'Windows Certificate Dialog Elevation of Privilege Vulnerability'. | 8,6% | |
| CVE-2023-0266 | HIGH 7.9 | debian debian_linux A use after free vulnerability exists in the ALSA PCM package in the Linux Kernel. SNDRV_CTL_IOCTL_ELEM_{READ|WRITE}32 is missing locks that can be used in a use-after-free that can result in a priviledge escalation to gain ring0 access from the system user. W | 3,7% | |
| CVE-2013-3163 | HIGH 8.8 | microsoft internet_explorer Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013 | 70,7% | |
| CVE-2023-24880 | MED 4.4 | ransomware microsoft windows_10_1607 Windows SmartScreen Security Feature Bypass Vulnerability | 78,2% | |
| CVE-2023-23397 | CRIT 9.8 | microsoft 365_apps Microsoft Outlook Elevation of Privilege Vulnerability | 97,4% | |
| CVE-2022-41328 | MED 6.7 | fortinet fortios A improper limitation of a pathname to a restricted directory vulnerability ('path traversal') [CWE-22] in Fortinet FortiOS version 7.2.0 through 7.2.3, 7.0.0 through 7.0.9 and before 6.4.11 allows a privileged attacker to read and write files on the underlyin | 11,9% | |
| CVE-2020-5741 | HIGH 7.2 | plex media_server Deserialization of Untrusted Data in Plex Media Server on Windows allows a remote, authenticated attacker to execute arbitrary Python code. | 72,9% | |
| CVE-2022-33891 | HIGH 8.8 | apache spark The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the application. If ACLs are enabled, a code path in Ht | 93,1% | |
| CVE-2022-47986 | CRIT 9.8 | ransomware ibm aspera_faspex IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserialization flaw. By sending a specially crafted obsolete API call, an attacker could exploit this vulnerability to ex | 100,0% | |
| CVE-2023-23376 | HIGH 7.8 | ransomware microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 10,9% | |
| CVE-2023-21823 | HIGH 7.8 | microsoft windows_10_1507 Windows Graphics Component Remote Code Execution Vulnerability | 5,6% | |
| CVE-2023-21715 | HIGH 7.3 | microsoft 365_apps Microsoft Publisher Security Feature Bypass Vulnerability | 12,0% | |
| CVE-2015-2291 | HIGH 7.8 | ransomware intel ethernet_diagnostics_driver_iqvw32.sys (1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a denial of service or possibly execute arbitrary code with kernel privileges via a crafted (a) 0x80862013, (b) 0x8 | 9,0% | |
| CVE-2023-21674 | HIGH 8.8 | microsoft windows_10_1507 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability | 41,8% | |
| CVE-2022-41080 | HIGH 8.8 | ransomware microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability | 77,3% | |
| CVE-2022-44698 | MED 5.4 | ransomware microsoft windows_10_1607 Windows SmartScreen Security Feature Bypass Vulnerability | 76,3% | |
| CVE-2022-42475 | CRIT 9.8 | ransomware fortinet fortios A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier and FortiProxy SSL-VPN 7.2.0 through 7.2.1, 7.0.7 and earlier may allow a remote u | 99,5% | |
| CVE-2022-27518 | CRIT 9.8 | citrix application_delivery_controller_firmware Unauthenticated remote arbitrary code execution | 6,9% | |
| CVE-2022-4135 | CRIT 9.6 | google chrome Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 31,9% | |
| CVE-2022-41049 | MED 5.4 | microsoft windows_10_1507 Windows Mark of the Web Security Feature Bypass Vulnerability | 2,5% | |
| CVE-2022-41128 | HIGH 8.8 | microsoft windows_10_1507 Windows Scripting Languages Remote Code Execution Vulnerability | 24,6% | |
| CVE-2022-41125 | HIGH 7.8 | microsoft windows_10_1507 Windows CNG Key Isolation Service Elevation of Privilege Vulnerability | 3,0% | |
| CVE-2022-41091 | MED 5.4 | ransomware microsoft windows_10_1507 Windows Mark of the Web Security Feature Bypass Vulnerability | 2,0% |