56.569 CVE seguite
773 Sfruttate ora
181 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.569 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2010-4398 | HIGH 7.8 | microsoft windows_7 Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges | 8,7% | |
| CVE-2021-34484 | HIGH 7.8 | microsoft windows_10_1507 Windows User Profile Service Elevation of Privilege Vulnerability | 21,7% | |
| CVE-2022-22965 | CRIT 9.8 | cisco cx_cloud_agent A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot | 99,7% | |
| CVE-2021-31166 | CRIT 9.8 | microsoft windows_10_2004 HTTP Protocol Stack Remote Code Execution Vulnerability | 99,7% | |
| CVE-2017-0148 | HIGH 8.1 | ransomware microsoft server_message_block The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute ar | 99,4% | |
| CVE-2021-42287 | HIGH 7.5 | ransomware microsoft windows_server_2004 Active Directory Domain Services Elevation of Privilege Vulnerability | 74,3% | |
| CVE-2021-42278 | HIGH 7.5 | ransomware microsoft windows_server_2004 Active Directory Domain Services Elevation of Privilege Vulnerability | 70,2% | |
| CVE-2021-22600 | MED 6.6 | debian debian_linux A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user through crafted syscalls to escalate privileges or deny service. We recommend upgrading kernel past the effected versions or rebuilding past ec6af094ea28f0f2dda1a | 5,9% | |
| CVE-2022-24521 | HIGH 7.8 | ransomware microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 7,3% | |
| CVE-2015-5123 | CRIT 9.8 | adobe flash_player Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through | 18,5% | |
| CVE-2015-5122 | CRIT 9.8 | adobe flash_player Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x thro | 93,7% | |
| CVE-2015-3113 | CRIT 9.8 | adobe flash_player Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild | 99,9% | |
| CVE-2015-2502 | HIGH 8.8 | microsoft internet_explorer Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," as exploited in the wild in August 2015. | 38,7% | |
| CVE-2015-0313 | CRIT 9.8 | adobe flash_player Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wil | 95,7% | |
| CVE-2015-0311 | CRIT 9.8 | adobe flash_player Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through 11.2.202.438 on Linux allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild | 85,8% | |
| CVE-2014-9163 | HIGH 7.8 | adobe flash_player Stack-based buffer overflow in Adobe Flash Player before 13.0.0.259 and 14.x and 15.x before 15.0.0.246 on Windows and OS X and before 11.2.202.425 on Linux allows attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in Decembe | 20,4% | |
| CVE-2022-22954 | CRIT 9.8 | ransomware vmware cloud_foundation VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution. | 100,0% | |
| CVE-2022-22960 | HIGH 7.8 | vmware cloud_foundation VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. A malicious actor with local access can escalate privileges to 'root'. | 35,8% | |
| CVE-2022-22718 | HIGH 7.8 | microsoft windows_10_1507 Windows Print Spooler Elevation of Privilege Vulnerability | 18,5% | |
| CVE-2022-26904 | HIGH 7.0 | microsoft windows_10_1507 Windows User Profile Service Elevation of Privilege Vulnerability | 9,8% | |
| CVE-2022-21919 | HIGH 7.0 | microsoft windows_10_1507 Windows User Profile Service Elevation of Privilege Vulnerability | 2,9% | |
| CVE-2022-0847 | HIGH 7.8 | fedoraproject fedora A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use th | 88,6% | |
| CVE-2021-41357 | HIGH 7.8 | microsoft windows_10_2004 Win32k Elevation of Privilege Vulnerability | 2,1% | |
| CVE-2021-40450 | HIGH 7.8 | microsoft windows_10_1809 Win32k Elevation of Privilege Vulnerability | 2,1% | |
| CVE-2014-4113 | HIGH 7.8 | microsoft windows_7 win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain pr | 87,0% |