57.056 CVE seguite
777 Sfruttate ora
184 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.056 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2022-26779 | HIGH 7.5 | apache cloudstack Apache CloudStack prior to 4.16.1.0 used insecure random number generation for project invitation tokens. If a project invite is created based only on an email address, a random token is generated. An attacker with knowledge of the project ID and the fact that | 2,9% | — |
| CVE-2012-3552 | MED 5.9 | linux linux_kernel Race condition in the IP implementation in the Linux kernel before 3.0 might allow remote attackers to cause a denial of service (slab corruption and system crash) by sending packets to an application that sets socket options during the handling of network tra | 2,9% | — |
| CVE-2018-5314 | HIGH 7.5 | citrix netscaler_application_delivery_controller Command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway 11.0 before build 70.16, 11.1 before build 55.13, and 12.0 before build 53.13; and the NetScaler Load Balancing instance distributed with NetScaler SD-WAN/CloudBridge 4000, 4100, 500 | 2,8% | — |
| CVE-2023-28935 | HIGH 8.8 | apache unstructured_information_management_architecture ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache UIMA DUCC. When using the "Distributed UIMA Cluster Computing" (DUCC) module of Apache UIMA | 2,8% | — |
| CVE-2019-19070 | HIGH 7.5 | fedoraproject fedora A memory leak in the spi_gpio_probe() function in drivers/spi/spi-gpio.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering devm_add_action_or_reset() failures, aka CID-d3b0ffa1d75d. NOTE: third | 2,8% | — |
| CVE-2018-8514 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when Remote Procedure Call runtime improperly initializes objects in memory, aka "Remote Procedure Call runtime Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1 | 2,8% | — |
| CVE-2018-3992 | HIGH 8.8 | foxitsoftware phantompdf An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader, version 9.2.0.9297. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code exe | 2,8% | — |
| CVE-2017-12632 | HIGH 7.5 | apache nifi A malicious host header in an incoming HTTP request could cause NiFi to load resources from an external server. The fix to sanitize host headers and compare to a controlled whitelist was applied on the Apache NiFi 1.5.0 release. Users running a prior 1.x relea | 2,8% | — |
| CVE-2004-2176 | MED 4.6 | microsoft windows_xp The Internet Connection Firewall (ICF) in Microsoft Windows XP SP2 is configured by default to trust sessmgr.exe, which allows local users to use sessmgr.exe to create a local listening port that bypasses the ICF access controls. | 2,8% | — |
| CVE-2008-5536 | HIGH 9.3 | pandasecurity panda_antivirus Panda Antivirus 9.0.0.4, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .tx | 2,8% | — |
| CVE-2022-24515 | MED 6.5 | microsoft azure_site_recovery Azure Site Recovery Elevation of Privilege Vulnerability | 2,8% | — |
| CVE-2023-21744 | HIGH 8.8 | microsoft sharepoint_foundation Microsoft SharePoint Server Remote Code Execution Vulnerability | 2,8% | — |
| CVE-2021-34499 | MED 6.5 | microsoft windows_server_2008 Windows DNS Server Denial of Service Vulnerability | 2,8% | — |
| CVE-2021-33758 | HIGH 7.7 | microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability | 2,8% | — |
| CVE-2021-33745 | MED 6.5 | microsoft windows_server_2008 Windows DNS Server Denial of Service Vulnerability | 2,8% | — |
| CVE-2021-24114 | MED 5.7 | microsoft teams Microsoft Teams iOS Information Disclosure Vulnerability | 2,8% | — |
| CVE-2018-6342 | CRIT 9.8 | facebook react-dev-utils react-dev-utils on Windows allows developers to run a local webserver for accepting various commands, including a command to launch an editor. The input to that command was not properly sanitized, allowing an attacker who can make a network request to the serv | 2,8% | — |
| CVE-2000-1088 | MED 4.6 | microsoft data_engine The xp_SetSQLSecurity function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows | 2,8% | — |
| CVE-2026-62737 | HIGH 7.8 | microsoft windows_11_24h2 Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally. | 2,8% | — |
| CVE-2022-34224 | HIGH 7.8 | adobe acrobat Adobe Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 17.012.30229 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of | 2,8% | — |
| CVE-2018-19723 | HIGH 7.5 | adobe acrobat_dc Adobe Acrobat and Reader versions 2018.011.20058 and earlier, 2017.011.30099 and earlier, and 2015.006.30448 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. Note: A different vulnerability tha | 2,8% | — |
| CVE-2018-0743 | HIGH 7.0 | microsoft windows_10 Windows Subsystem for Linux in Windows 10 version 1703, Windows 10 version 1709, and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka "Windows Subsystem for Linux Elevation of Privile | 2,8% | — |
| CVE-2010-0571 | HIGH 8.5 | cisco digital_media_manager Unspecified vulnerability in Cisco Digital Media Manager (DMM) 5.0.x and 5.1.x allows remote authenticated users to gain privileges via unknown vectors, and consequently execute arbitrary code via a crafted web application, aka Bug ID CSCtc46008. | 2,8% | — |
| CVE-2021-26867 | CRIT 9.9 | microsoft windows_10 Windows Hyper-V Remote Code Execution Vulnerability | 2,8% | — |
| CVE-2017-6609 | HIGH 7.7 | cisco adaptive_security_appliance_software A vulnerability in the IPsec code of Cisco ASA Software could allow an authenticated, remote attacker to cause a reload of the affected system. The vulnerability is due to improper parsing of malformed IPsec packets. An attacker could exploit this vulnerabilit | 2,8% | — |