57.056 CVE seguite
777 Sfruttate ora
184 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.056 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2019-10638 | MED 6.5 | linux linux_kernel In the Linux kernel before 5.1.7, a device can be tracked by an attacker using the IP ID values the kernel produces for connection-less protocols (e.g., UDP and ICMP). When such traffic is sent to multiple destination IP addresses, it is possible to obtain has | 2,6% | — |
| CVE-2018-4262 | HIGH 8.8 | apple icloud In Safari before 11.1.2, iTunes before 12.8 for Windows, iOS before 11.4.1, tvOS before 11.4.1, iCloud for Windows before 7.6, multiple memory corruption issues were addressed with improved memory handling. | 2,6% | — |
| CVE-2007-5352 | HIGH 7.2 | microsoft windows_2000 Unspecified vulnerability in Local Security Authority Subsystem Service (LSASS) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2 allows local users to gain privileges via a crafted local procedure call (LPC) request. | 2,6% | — |
| CVE-2007-0211 | HIGH 7.2 | microsoft windows_2003_server The hardware detection functionality in the Windows Shell in Microsoft Windows XP SP2 and Professional, and Server 2003 SP1 allows local users to gain privileges via an unvalidated parameter to a function related to the "detection and registration of new hardw | 2,6% | — |
| CVE-2020-8283 | HIGH 8.8 | citrix virtual_apps_and_desktops An authorised user on a Windows host running Citrix Universal Print Server can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU6 hotfix CTX285344 and 7.6 LTSR CU9. | 2,6% | — |
| CVE-2017-11830 | MED 5.3 | microsoft windows_10 Device Guard in Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016, and Windows Server, version 1709 allows an attacker to make an unsigned file appear to be signed, due to a security feature bypass, aka "Device Guard Security Feature Bypass Vuln | 2,6% | — |
| CVE-2015-5211 | CRIT 9.6 | debian debian_linux Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to a Reflected File Download (RFD) attack. The attack involves a malicious user crafting a URL with a batch script extensio | 2,6% | — |
| CVE-2011-3304 | HIGH 7.8 | cisco 5500_series_adaptive_security_appliance Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services module in Cisco Catalyst 6500 series devices, with software 7.2 before 7.2(5.3), 8.0 before 8.0(5.25), 8.1 before 8.1(2.50), 8.2 before 8.2(5.11), 8.3 before 8.3(2.23), 8.4 befo | 2,6% | — |
| CVE-2011-0391 | HIGH 7.8 | cisco telepresence_recording_server Cisco TelePresence Recording Server devices with software 1.6.x allow remote attackers to cause a denial of service (thread consumption and device outage) via a malformed request, related to an "ad hoc recording" issue, aka Bug ID CSCtf97205. | 2,6% | — |
| CVE-2011-0390 | HIGH 7.8 | cisco telepresence_multipoint_switch The XML-RPC implementation on Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, 1.6.x, and 1.7.0 allows remote attackers to cause a denial of service (process crash) via a crafted request, aka Bug ID CSCtj44534. | 2,6% | — |
| CVE-2012-4659 | HIGH 7.1 | cisco 5500_series_adaptive_security_appliance The AAA functionality in the IPv4 SSL VPN implementations on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 8.2 before 8.2(5.30) and 8.3 before 8.3(2.34) al | 2,6% | — |
| CVE-2012-4168 | MED 4.3 | adobe air Adobe Flash Player before 10.3.183.23 and 11.x before 11.4.402.265 on Windows and Mac OS X, before 10.3.183.23 and 11.x before 11.2.202.238 on Linux, before 11.1.111.16 on Android 2.x and 3.x, and before 11.1.115.17 on Android 4.x; Adobe AIR before 3.4.0.2540; | 2,6% | — |
| CVE-2007-4671 | MED 6.8 | apple safari Unspecified vulnerability in Safari in Apple iPhone 1.1.1, and Safari 3 before Beta Update 3.0.4 on Windows and Mac OS X 10.4 through 10.4.10, allows remote attackers to "alter or access" HTTPS content via an HTTP session with a crafted web page that causes Ja | 2,6% | — |
| CVE-2025-53773 | HIGH 7.8 | microsoft visual_studio_2022 Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to execute code locally. | 2,6% | — |
| CVE-2023-38243 | MED 5.5 | adobe acrobat Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by a Use-After-Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such a | 2,6% | — |
| CVE-2023-33134 | HIGH 8.8 | microsoft sharepoint_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 2,6% | — |
| CVE-2022-24498 | MED 6.5 | microsoft windows_10 Windows iSCSI Target Service Information Disclosure Vulnerability | 2,6% | — |
| CVE-2022-26919 | HIGH 8.1 | microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 2,6% | — |
| CVE-2022-23254 | MED 4.9 | microsoft powerbi-client_js_sdk Microsoft Power BI Information Disclosure Vulnerability | 2,6% | — |
| CVE-2022-22019 | HIGH 8.8 | microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability | 2,6% | — |
| CVE-2021-31949 | HIGH 7.3 | microsoft 365_apps Microsoft Outlook Remote Code Execution Vulnerability | 2,6% | — |
| CVE-2018-1000621 | HIGH 8.1 | mycroft mycroft-core Mycroft AI mycroft-core version 18.2.8b and earlier contains a Incorrect Access Control vulnerability in Websocket configuration that can result in code execution. This impacts ONLY the Mycroft for Linux and "non-enclosure" installs - Mark 1 and Picroft unaffe | 2,6% | — |
| CVE-2011-2538 | HIGH 7.2 | cisco telepresence_video_communication_server Cisco Video Communications Server (VCS) before X7.0.3 contains a command injection vulnerability which allows remote, authenticated attackers to execute arbitrary commands. | 2,6% | — |
| CVE-2026-20820 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | 2,6% | — |
| CVE-2021-0254 | CRIT 9.8 | juniper junos A buffer size validation vulnerability in the overlayd service of Juniper Networks Junos OS may allow an unauthenticated remote attacker to send specially crafted packets to the device, triggering a partial Denial of Service (DoS) condition, or leading to remo | 2,6% | — |