EN
58.387 CVE seguite
792 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.387 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordinato dal più basso
CVE-2020-1290 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. 1,3% —
CVE-2020-12899 HIGH 7.1 amd radeon_software Arbitrary Read in AMD Graphics Driver for Windows 10 may lead to KASLR bypass or denial of service. 0,2% —
CVE-2020-12898 HIGH 7.8 amd radeon_software Stack Buffer Overflow in AMD Graphics Driver for Windows 10 may lead to escalation of privilege or denial of service. 0,3% —
CVE-2020-12897 MED 5.5 amd radeon_software Kernel Pool Address disclosure in AMD Graphics Driver for Windows 10 may lead to KASLR bypass. 0,2% —
CVE-2020-12895 HIGH 7.8 amd radeon_software Pool/Heap Overflow in AMD Graphics Driver for Windows 10 in Escape 0x110037 may lead to escalation of privilege, information disclosure or denial of service. 0,3% —
CVE-2020-12894 HIGH 7.1 amd radeon_software Arbitrary Write in AMD Graphics Driver for Windows 10 in Escape 0x40010d may lead to arbitrary write to kernel memory or denial of service. 0,2% —
CVE-2020-12893 HIGH 7.8 amd radeon_software Stack Buffer Overflow in AMD Graphics Driver for Windows 10 in Escape 0x15002a may lead to escalation of privilege or denial of service. 0,3% —
CVE-2020-12892 HIGH 7.8 amd radeon_software An untrusted search path in AMD Radeon settings Installer may lead to a privilege escalation or unauthorized code execution. 0,3% —
CVE-2020-1289 MED 5.4 microsoft sharepoint_foundation A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2020-1148. 1,5% —
CVE-2020-12888 MED 5.3 canonical ubuntu_linux The VFIO PCI driver in the Linux kernel through 5.6.13 mishandles attempts to access disabled memory space. 0,4% —
CVE-2020-12876 HIGH 7.5 veritas aptare Veritas APTARE versions prior to 10.4 allowed remote users to access several unintended files on the server. This vulnerability only impacts Windows server deployments. 1,1% —
CVE-2020-1287 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows WalletService handles objects in memory, aka 'Windows WalletService Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1294. 3,0% —
CVE-2020-1286 HIGH 8.8 microsoft windows_10 A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths.An attacker who successfully exploited this vulnerability could run arbitrary code in the context of the current user, aka 'Windows Shell Remote Code Exec 11,8% —
CVE-2020-1285 HIGH 8.4 microsoft windows_10 <p>A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could th 4,0% —
CVE-2020-1284 MED 6.5 microsoft windows_10 A denial of service vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Denial of Service Vulnerability'. 6,9% —
CVE-2020-1283 MED 6.5 microsoft windows_10 A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'. 8,8% —
CVE-2020-12826 MED 5.3 canonical ubuntu_linux A signal access-control issue was discovered in the Linux kernel before 5.6.5, aka CID-7395ea4e65c2. Because exec_id in include/linux/sched.h is only 32 bits, an integer overflow can interfere with a do_notify_parent protection mechanism. A child process can s 0,7% —
CVE-2020-12820 MED 5.4 fortinet fortios Under non-default configuration, a stack-based buffer overflow in FortiOS version 6.0.10 and below, version 5.6.12 and below may allow a remote attacker authenticated to the SSL VPN to crash the FortiClient NAC daemon (fcnacd) and potentially execute arbitrary 0,9% —
CVE-2020-1282 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1231, CVE-2020-1233, CVE-2020-1235, CVE-2020-1265, CVE 3,3% —
CVE-2020-12819 MED 5.4 fortinet fortios A heap-based buffer overflow vulnerability in the processing of Link Control Protocol messages in FortiGate versions 5.6.12, 6.0.10, 6.2.4 and 6.4.1 and earlier may allow a remote attacker with valid SSL VPN credentials to crash the SSL VPN daemon by sending a 0,8% —
CVE-2020-12818 MED 5.3 fortinet fortios An insufficient logging vulnerability in FortiGate before 6.4.1 may allow the traffic from an unauthenticated attacker to Fortinet owned IP addresses to go unnoticed. 0,9% —
CVE-2020-12817 HIGH 8.8 fortinet fortianalyzer An improper neutralization of input vulnerability in FortiAnalyzer before 6.4.1 and 6.2.5 may allow a remote authenticated attacker to inject script related HTML tags via Name parameter of Storage Connectors. 2,3% —
CVE-2020-12816 MED 6.1 fortinet fortinac An improper neutralization of input vulnerability in FortiNAC before 8.7.2 may allow a remote authenticated attacker to perform a stored cross site scripting attack (XSS) via the UserID of Admin Users. 1,2% —
CVE-2020-12815 MED 5.4 fortinet fortianalyzer An improper neutralization of input vulnerability in FortiTester before 3.9.0 may allow a remote authenticated attacker to inject script related HTML tags via IPv4/IPv6 address fields. 0,9% —
CVE-2020-12814 MED 4.1 fortinet fortianalyzer A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiAnalyzer version 6.0.6 and below, version 6.4.4 allows attacker to execute unauthorized code or commands via specifically crafted requests to the web GUI. 0,5% —