57.056 CVE seguite
777 Sfruttate ora
184 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.056 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2019-0949 | MED 5.7 | microsoft sharepoint_foundation A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0950, CVE-2019- | 2,5% | — |
| CVE-1999-0585 | LOW 2.1 | microsoft windows_2000 A Windows NT administrator account has the default name of Administrator. | 2,5% | — |
| CVE-2019-0670 | MED 6.1 | microsoft sharepoint_enterprise_server A spoofing vulnerability exists in Microsoft SharePoint when the application does not properly parse HTTP content, aka 'Microsoft SharePoint Spoofing Vulnerability'. | 2,5% | — |
| CVE-2018-0454 | HIGH 8.8 | cisco cloud_services_platform_2100_firmware A vulnerability in the web-based management interface of Cisco Cloud Services Platform 2100 could allow an authenticated, remote attacker to perform command injection. The vulnerability is due to insufficient input validation of command input. An attacker coul | 2,5% | — |
| CVE-2017-5055 | HIGH 8.8 | google chrome A use after free in printing in Google Chrome prior to 57.0.2987.133 for Linux and Windows allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. | 2,5% | — |
| CVE-2024-22393 | CRIT 9.1 | apache answer Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1. Pixel Flood Attack by uploading large pixel files will cause server out of memory. A logged-in user can cause such an attack by upl | 2,5% | — |
| CVE-2021-39858 | LOW 3.3 | adobe acrobat Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of arbitrary memory information in the context of the curre | 2,5% | — |
| CVE-2021-26472 | CRIT 10.0 | vembu bdr_suite In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1 installed on Windows, the http API located at /consumerweb/secure/download.php. Using this command argument an unauthenticated attacker can execute arbitrary OS commands with SYSTEM privileges. | 2,5% | — |
| CVE-2010-1965 | HIGH 7.5 | hp insight_orchestration Unspecified vulnerability in HP Insight Orchestration for Windows before 6.1 allows remote attackers to read or modify data via unknown vectors. | 2,5% | — |
| CVE-2023-36786 | HIGH 7.2 | microsoft skype_for_business_server Skype for Business Remote Code Execution Vulnerability | 2,5% | — |
| CVE-2023-36395 | HIGH 7.5 | microsoft windows_server_2008 Windows Deployment Services Denial of Service Vulnerability | 2,5% | — |
| CVE-2023-36392 | HIGH 7.5 | microsoft windows_server_2012 DHCP Server Service Denial of Service Vulnerability | 2,5% | — |
| CVE-2021-44743 | HIGH 7.8 | adobe bridge Adobe Bridge version 11.1.2 (and earlier) and version 12.0 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction | 2,5% | — |
| CVE-2020-1926 | MED 5.9 | apache hive Apache Hive cookie signature verification used a non constant time comparison which is known to be vulnerable to timing attacks. This could allow recovery of another users cookie signature. The issue was addressed in Apache Hive 2.3.8 | 2,5% | — |
| CVE-2014-0562 | MED 4.3 | adobe acrobat Cross-site scripting (XSS) vulnerability in Adobe Reader and Acrobat 10.x before 10.1.12 and 11.x before 11.0.09 on OS X allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Universal XSS (UXSS)." | 2,5% | — |
| CVE-2012-1517 | HIGH 9.0 | vmware esx The VMX process in VMware ESXi 4.1 and ESX 4.1 does not properly handle RPC commands, which allows guest OS users to cause a denial of service (memory overwrite and process crash) or possibly execute arbitrary code on the host OS via vectors involving function | 2,5% | — |
| CVE-2024-38146 | HIGH 7.5 | microsoft windows_10_1507 Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability | 2,5% | — |
| CVE-2024-38145 | HIGH 7.5 | microsoft windows_10_1507 Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability | 2,5% | — |
| CVE-2019-10094 | HIGH 7.8 | apache tika A carefully crafted package/compressed file that, when unzipped/uncompressed yields the same file (a quine), causes a StackOverflowError in Apache Tika's RecursiveParserWrapper in versions 1.7-1.21. Apache Tika users should upgrade to 1.22 or later. | 2,5% | — |
| CVE-2018-1258 | HIGH 8.8 | netapp oncommand_insight Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted. | 2,5% | — |
| CVE-2015-2529 | LOW 2.1 | microsoft windows_10 The kernel in Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, and Windows 10 allows local users to bypass the ASLR protection mechanism via a crafted application, aka "Kernel ASLR Bypass Vulnerability." | 2,5% | — |
| CVE-2013-6968 | MED 5.0 | cisco webex_training_center Cisco WebEx Training Center provides different error messages for registration attempts depending on whether the e-mail address exists, which allows remote attackers to enumerate attendees via a series of requests, aka Bug ID CSCul36003. | 2,5% | — |
| CVE-2024-38474 | CRIT 9.8 | apache http_server Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be execu | 2,5% | — |
| CVE-2018-17186 | HIGH 7.2 | apache syncope An administrator with workflow definition entitlements can use DTD to perform malicious operations, including but not limited to file read, file write, and code execution. | 2,5% | — |
| CVE-2018-11792 | CRIT 9.8 | apache impala In Apache Impala before 3.0.1, ALTER TABLE/VIEW RENAME required ALTER on the old table. This may pose a potential security risk, such as having ALTER on a table and ALL on a particular database allows a user to move the table to a database with ALL, which will | 2,5% | — |