57.056 CVE seguite
777 Sfruttate ora
184 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.056 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2018-0389 | HIGH 7.5 | cisco spa514g_firmware A vulnerability in the implementation of Session Initiation Protocol (SIP) processing in Cisco Small Business SPA514G IP Phones could allow an unauthenticated, remote attacker to cause an affected device to become unresponsive, resulting in a denial of service | 2,5% | — |
| CVE-2012-2381 | LOW 3.5 | apache roller Multiple cross-site scripting (XSS) vulnerabilities in Apache Roller before 5.0.1 allow remote authenticated users to inject arbitrary web script or HTML by leveraging the blogger role. | 2,5% | — |
| CVE-2010-4573 | HIGH 9.3 | vmware esxi The Update Installer in VMware ESXi 4.1, when a modified sfcb.cfg is present, does not properly configure the SFCB authentication mode, which allows remote attackers to obtain access via an arbitrary username and password. | 2,5% | — |
| CVE-2010-2984 | HIGH 10.0 | cisco unified_wireless_network_solution_software Cisco Unified Wireless Network (UWN) Solution 7.x before 7.0.98.0 on 4404 series controllers does not properly implement the WEBAUTH_REQD state, which allows remote attackers to bypass intended access restrictions via WLAN traffic, aka Bug ID CSCtb75305. | 2,5% | — |
| CVE-2010-0042 | MED 4.3 | apple safari ImageIO in Apple Safari before 4.0.5 and iTunes before 9.1 on Windows does not ensure that memory access is associated with initialized memory, which allows remote attackers to obtain potentially sensitive information from process memory via a crafted TIFF ima | 2,5% | — |
| CVE-2010-0041 | MED 4.3 | apple safari ImageIO in Apple Safari before 4.0.5 and iTunes before 9.1 on Windows does not ensure that memory access is associated with initialized memory, which allows remote attackers to obtain potentially sensitive information from process memory via a crafted BMP imag | 2,5% | — |
| CVE-2023-32258 | HIGH 8.1 | linux linux_kernel A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the processing of SMB2_LOGOFF and SMB2_CLOSE commands. The issue results from the lack of proper locking when performing operations on an obj | 2,5% | — |
| CVE-2021-32566 | HIGH 7.5 | apache traffic_server Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1. | 2,5% | — |
| CVE-2018-0213 | HIGH 8.8 | cisco identity_services_engine A vulnerability in the credential reset functionality for Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to gain elevated privileges. The vulnerability is due to a lack of proper input validation. An attacker could exploit t | 2,5% | — |
| CVE-2009-0618 | HIGH 8.5 | cisco application_networking_manager Unspecified vulnerability in the Java agent in Cisco Application Networking Manager (ANM) before 2.0 Update A allows remote attackers to gain privileges, and cause a denial of service (service outage) by stopping processes, or obtain sensitive information by r | 2,5% | — |
| CVE-2022-30303 | HIGH 8.8 | fortinet fortiweb An improper neutralization of special elements used in an os command ('OS Command Injection') [CWE-78] in FortiWeb 7.0.0 through 7.0.1, 6.3.0 through 6.3.19, 6.4 all versions may allow an authenticated attacker to execute arbitrary shell code as `root` user vi | 2,5% | — |
| CVE-2021-38295 | HIGH 7.3 | apache couchdb In Apache CouchDB, a malicious user with permission to create documents in a database is able to attach a HTML attachment to a document. If a CouchDB admin opens that attachment in a browser, e.g. via the CouchDB admin interface Fauxton, any JavaScript code em | 2,5% | — |
| CVE-2021-34797 | HIGH 7.5 | apache geode Apache Geode versions up to 1.12.4 and 1.13.4 are vulnerable to a log file redaction of sensitive information flaw when using values that begin with characters other than letters or numbers for passwords and security properties with the prefix "sysprop-", "jav | 2,5% | — |
| CVE-2018-0121 | CRIT 9.8 | cisco elastic_services_controller A vulnerability in the authentication functionality of the web-based service portal of Cisco Elastic Services Controller Software could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrator privileg | 2,5% | — |
| CVE-2017-6629 | MED 5.3 | cisco unity_connection A vulnerability in the ImageID parameter of Cisco Unity Connection 10.5(2) could allow an unauthenticated, remote attacker to access files in arbitrary locations on the filesystem of an affected device. The issue is due to improper sanitization of user-supplie | 2,5% | — |
| CVE-2016-6445 | CRIT 9.1 | cisco meeting_server A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) service of the Cisco Meeting Server (CMS) before 2.0.6 and Acano Server before 1.8.18 and 1.9.x before 1.9.6 could allow an unauthenticated, remote attacker to masquerade as a legitimate | 2,5% | — |
| CVE-2012-2449 | HIGH 9.0 | vmware esx VMware Workstation 8.x before 8.0.3, VMware Player 4.x before 4.0.3, VMware Fusion 4.x through 4.1.2, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 do not properly configure the virtual floppy device, which allows guest OS users to cause a denial | 2,5% | — |
| CVE-2010-0590 | HIGH 7.8 | cisco unified_communications_manager The CMSIPUtility component in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 7.x before 7.1(3a)su1 and 8.x before 8.0(1) allows remote attackers to cause a denial of service (process failure) via a malformed SIP Register message, aka Bug | 2,5% | — |
| CVE-2010-0587 | HIGH 7.8 | cisco unified_communications_manager Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x before 4.3(2)SR2, 6.x before 6.1(5), 7.x before 7.1(3a)su1, and 8.x before 8.0(1) allows remote attackers to cause a denial of service (process failure) via a malformed SCCP StationCapab | 2,5% | — |
| CVE-2001-0757 | HIGH 7.5 | cisco 6400_nrp_2 Cisco 6400 Access Concentrator Node Route Processor 2 (NRP2) 12.1DC card does not properly disable access when a password has not been set for vtys, which allows remote attackers to obtain access via telnet. | 2,5% | — |
| CVE-2026-55009 | HIGH 7.8 | microsoft exchange_server Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally. | 2,5% | — |
| CVE-2024-21409 | HIGH 7.3 | microsoft .net .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability | 2,5% | — |
| CVE-2023-36585 | HIGH 7.5 | microsoft windows_10_1507 Windows upnphost.dll Denial of Service Vulnerability | 2,5% | — |
| CVE-2021-40452 | HIGH 7.8 | microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability | 2,5% | — |
| CVE-2021-36008 | LOW 3.3 | adobe illustrator Adobe Illustrator version 25.2.3 (and earlier) is affected by an Use-after-free vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to read arbitrary file system information in the context of the c | 2,5% | — |