58.306 CVE seguite
790 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.306 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2020-26077 | MED 4.3 | cisco iot_field_network_director A vulnerability in the access control functionality of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to view lists of users from different domains that are configured on an affected system. The vulnerability is due to imp | 0,8% | — |
| CVE-2020-26076 | HIGH 7.5 | cisco iot_field_network_director A vulnerability in Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to view sensitive database information on an affected device. The vulnerability is due to the absence of authentication for sensitive information. An atta | 1,3% | — |
| CVE-2020-26075 | HIGH 8.8 | cisco iot_field_network_director A vulnerability in the REST API of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to gain access to the back-end database of an affected device. The vulnerability is due to insufficient input validation of REST API request | 1,6% | — |
| CVE-2020-26074 | HIGH 7.8 | cisco catalyst_sd-wan_manager A vulnerability in system file transfer functions of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to gain escalated privileges on the underlying operating system. The vulnerability is due to improper validation of path input | 0,2% | — |
| CVE-2020-26073 | HIGH 7.5 | cisco catalyst_sd-wan_manager A vulnerability in the application data endpoints of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper validation of directory traversal character s | 12,6% | — |
| CVE-2020-26072 | HIGH 8.7 | cisco iot_field_network_director A vulnerability in the SOAP API of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to access and modify information on devices that belong to a different domain. The vulnerability is due to insufficient authorization in the | 1,0% | — |
| CVE-2020-26071 | HIGH 8.4 | cisco catalyst_sd-wan_manager A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to create or overwrite arbitrary files on an affected device, which could result in a denial of service (DoS) condition. The vulnerability is due to insuffic | 0,2% | — |
| CVE-2020-26070 | HIGH 8.6 | cisco ios_xr A vulnerability in the ingress packet processing function of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vu | 1,9% | — |
| CVE-2020-26068 | MED 5.5 | cisco roomos A vulnerability in the xAPI service of Cisco Telepresence CE Software and Cisco RoomOS Software could allow an authenticated, remote attacker to generate an access token for an affected device. The vulnerability is due to insufficient access authorization. An | 0,7% | — |
| CVE-2020-26067 | MED 5.4 | cisco webex_teams A vulnerability in the web-based interface of Cisco Webex Teams could allow an authenticated, remote attacker to conduct cross-site scripting attacks. The vulnerability is due to improper validation of usernames. An attacker could exploit this vulnerabil | 0,8% | — |
| CVE-2020-26066 | MED 6.5 | cisco catalyst_sd-wan_manager A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system. The vulnerability is due to improper handling of XML External | 0,6% | — |
| CVE-2020-26065 | MED 6.5 | cisco catalyst_sd-wan_manager A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct path traversal attacks and obtain read access to sensitive files on an affected system. The vulnerability is due t | 1,7% | — |
| CVE-2020-26064 | HIGH 8.1 | cisco catalyst_sd-wan_manager A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system. The vulnerability is due to improper handling of XML External Enti | 0,7% | — |
| CVE-2020-26062 | MED 5.3 | cisco unified_computing_system A vulnerability in Cisco Integrated Management Controller could allow an unauthenticated, remote attacker to enumerate valid usernames within the vulnerable application. The vulnerability is due to differences in authentication responses sent back from t | 0,8% | — |
| CVE-2020-25967 | HIGH 8.8 | fastadmin fastadmin The member center function in fastadmin V1.0.0.20200506_beta is vulnerable to a Server-Side Template Injection (SSTI) vulnerability. | 1,3% | — |
| CVE-2020-25775 | MED 6.3 | trendmicro antivirus\+_2020 The Trend Micro Security 2020 (v16) consumer family of products is vulnerable to a security race condition arbitrary file deletion vulnerability that could allow an unprivileged user to manipulate the product's secure erase feature to delete files with a highe | 0,3% | — |
| CVE-2020-25774 | MED 4.3 | trendmicro apex_one A vulnerability in the Trend Micro Apex One ServerMigrationTool component could allow an attacker to trigger an out-of-bounds red information disclosure which would disclose sensitive information to an unprivileged account. User interaction is required to expl | 2,1% | — |
| CVE-2020-25773 | HIGH 7.8 | trendmicro apex_one A vulnerability in the Trend Micro Apex One ServerMigrationTool component could allow an attacker to execute arbitrary code on affected products. User interaction is required to exploit this vulnerability in that the target must import a corrupted configuratio | 2,4% | — |
| CVE-2020-25772 | MED 5.5 | trendmicro apex_one An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installations of the product. An attacker must first obtain the ability t | 1,3% | — |
| CVE-2020-25771 | MED 5.5 | trendmicro apex_one An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installations of the product. An attacker must first obtain the ability t | 1,3% | — |
| CVE-2020-25770 | MED 5.5 | trendmicro apex_one An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installations of the product. An attacker must first obtain the ability t | 1,3% | — |
| CVE-2020-25737 | HIGH 7.8 | hackolade hackolade An elevation of privilege vulnerability exists in Hackolade versions prior 4.2.0 on Windows has an issue in specific deployment scenarios that could allow local users to gain elevated privileges during an uninstall of the application. | 0,3% | — |
| CVE-2020-25705 | HIGH 7.4 | linux linux_kernel A flaw in ICMP packets in the Linux kernel may allow an attacker to quickly scan open UDP ports. This flaw allows an off-path remote attacker to effectively bypass source port UDP randomization. Software that relies on UDP source port randomization are indirec | 6,7% | — |
| CVE-2020-25704 | MED 5.5 | debian debian_linux A flaw memory leak in the Linux kernel performance monitoring subsystem was found in the way if using PERF_EVENT_IOC_SET_FILTER. A local user could use this flaw to starve the resources causing denial of service. | 0,4% | — |
| CVE-2020-25673 | MED 5.5 | fedoraproject fedora A vulnerability was found in Linux kernel where non-blocking socket in llcp_sock_connect() leads to leak and eventually hanging-up the system. | 0,5% | — |