56.568 CVE seguite
773 Sfruttate ora
181 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.568 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2020-1350 | CRIT 10.0 | microsoft windows_server_2008 A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests, aka 'Windows DNS Server Remote Code Execution Vulnerability'. | 91,4% | |
| CVE-2024-27316 | HIGH 7.5 | apache http_server HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion. | 91,3% | — |
| CVE-2010-2568 | HIGH 7.8 | microsoft windows_7 Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users or remote attackers to execute arbitrary code via a crafted (1) .LNK or (2) .PIF shortcut file, which is not properly handle | 91,3% | |
| CVE-2026-39808 | CRIT 9.8 | fortinet fortisandbox A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here> | 91,2% | |
| CVE-2010-1870 | MED 5.0 | apache struts The OGNL extensive expression evaluation capability in XWork in Struts 2.0.0 through 2.1.8.1, as used in Atlassian Fisheye, Crucible, and possibly other products, uses a permissive whitelist, which allows remote attackers to modify server-side context objects | 91,1% | — |
| CVE-2018-0798 | HIGH 8.8 | microsoft office Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Office Memory Corruption Vulnerability". | 91,0% | |
| CVE-2009-3023 | HIGH 9.0 | microsoft internet_information_server Buffer overflow in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 6.0 allows remote authenticated users to execute arbitrary code via a crafted NLST (NAME LIST) command that uses wildcards, leading to memory corruption, aka "IIS F | 90,9% | — |
| CVE-2022-26809 | CRIT 9.8 | microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability | 90,9% | — |
| CVE-2024-45216 | CRIT 9.8 | apache solr Improper Authentication vulnerability in Apache Solr. Solr instances using the PKIAuthenticationPlugin, which is enabled by default when Solr Authentication is used, are vulnerable to Authentication bypass. A fake ending at the end of any Solr API URL path, w | 90,9% | — |
| CVE-2001-0333 | HIGH 7.5 | microsoft internet_information_server Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and "\" characters twice. | 90,8% | — |
| CVE-2007-0450 | MED 5.0 | apache http_server Directory traversal vulnerability in Apache HTTP Server and Tomcat 5.x before 5.5.22 and 6.x before 6.0.10, when using certain proxy modules (mod_proxy, mod_rewrite, mod_jk), allows remote attackers to read arbitrary files via a .. (dot dot) sequence with comb | 90,8% | — |
| CVE-2011-3368 | MED 5.0 | apache http_server The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows | 90,7% | — |
| CVE-2021-21315 | HIGH 7.1 | apache cordova The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware, system and OS information. In systeminformation before version 5.3.1 there is a command injection vulnerabilit | 90,7% | |
| CVE-2018-11759 | HIGH 7.5 | apache tomcat_jk_connector The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK (mod_jk) Connector 1.2.0 to 1.2.44 did not handle some edge cases correctly. If only a sub-set of the URLs supported by | 90,6% | — |
| CVE-2000-0402 | LOW 2.1 | microsoft sql_server The Mixed Mode authentication capability in Microsoft SQL Server 7.0 stores the System Administrator (sa) account in plaintext in a log file which is readable by any user, aka the "SQL Server 7.0 Service Pack Password" vulnerability. | 90,6% | — |
| CVE-2017-12636 | HIGH 7.2 | apache couchdb CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include paths for operating system-level binaries that are subsequently launched by CouchDB. This allows an admin user in Apache CouchDB before 1.7.0 | 90,6% | — |
| CVE-2013-6429 | MED 6.8 | pivotal_software spring_framework The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks | 90,5% | — |
| CVE-2023-37582 | CRIT 9.8 | apache rocketmq The RocketMQ NameServer component still has a remote command execution vulnerability as the CVE-2023-33246 issue was not completely fixed in version 5.1.1. When NameServer address are leaked on the extranet and lack permission verification, an attacker can e | 90,4% | — |
| CVE-2022-30522 | HIGH 7.5 | apache http_server If Apache HTTP Server 2.4.53 is configured to do transformations with mod_sed in contexts where the input to mod_sed may be very large, mod_sed may make excessively large memory allocations and trigger an abort. | 90,4% | — |
| CVE-2021-42321 | HIGH 8.8 | ransomware microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 90,4% | |
| CVE-2020-3952 | CRIT 9.8 | vmware vcenter_server Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not correctly implement access controls. | 90,4% | |
| CVE-2023-41763 | MED 5.3 | microsoft skype_for_business_server Skype for Business Elevation of Privilege Vulnerability | 90,4% | |
| CVE-2016-8735 | CRIT 9.8 | apache tomcat Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this list | 90,3% | |
| CVE-2006-2372 | HIGH 10.0 | microsoft dhcp_client_service Buffer overflow in the DHCP Client service for Microsoft Windows 2000 SP4, Windows XP SP1 and SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via a crafted DHCP response. | 90,2% | — |
| CVE-2009-3103 | HIGH 10.0 | microsoft windows_server_2008 Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC allows remote attackers to execute arbitrary code or cause a denial of service (system crash) v | 90,2% | — |