57.057 CVE seguite
777 Sfruttate ora
184 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.057 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2019-10080 | MED 6.5 | apache nifi The XMLFileLookupService in NiFi versions 1.3.0 to 1.9.2 allowed trusted users to inadvertently configure a potentially malicious XML file. The XML file has the ability to make external calls to services (via XXE) and reveal information such as the versions of | 2,3% | — |
| CVE-2022-24483 | MED 5.5 | microsoft windows_10 Windows Kernel Information Disclosure Vulnerability | 2,3% | — |
| CVE-2020-13417 | CRIT 9.8 | aviatrix controller An Elevation of Privilege issue was discovered in Aviatrix VPN Client before 2.10.7, because of an incomplete fix for CVE-2020-7224. This affects Linux, macOS, and Windows installations for certain OpenSSL parameters. | 2,3% | — |
| CVE-2019-9489 | HIGH 7.5 | trendmicro apex_one A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (versions XG and 11.0), and Worry-Free Business Security (versions 10.0, 9.5 and 9.0) could allow an attacker to modify arbitrary files on the affected product's management console. | 2,3% | — |
| CVE-2018-8568 | MED 5.4 | microsoft sharepoint_enterprise_server An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft | 2,3% | — |
| CVE-2018-6967 | HIGH 8.1 | vmware esxi VMware ESXi (6.7 before ESXi670-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x before 10.1.2) contain an out-of-bounds read vulnerability in the shader translator. Successful exploitation of this issue may lead to information disclosure or m | 2,3% | — |
| CVE-2018-6966 | HIGH 8.1 | vmware esxi VMware ESXi (6.7 before ESXi670-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x before 10.1.2) contain an out-of-bounds read vulnerability in the shader translator. Successful exploitation of this issue may lead to information disclosure or m | 2,3% | — |
| CVE-2013-3899 | HIGH 7.2 | microsoft windows_server_2003 win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly validate addresses, which allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Vulnerability." | 2,3% | — |
| CVE-2021-1433 | HIGH 8.1 | cisco ios_xe A vulnerability in the vDaemon process in Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected device. This vulnerability is due to insufficient bounds checking when the device processes traffic | 2,3% | — |
| CVE-2018-8498 | MED 5.4 | microsoft sharepoint_enterprise_server An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft | 2,3% | — |
| CVE-2018-8488 | MED 5.4 | microsoft sharepoint_enterprise_server An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft | 2,3% | — |
| CVE-2018-8480 | MED 5.4 | microsoft sharepoint_enterprise_server_2016 An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft | 2,3% | — |
| CVE-2000-0089 | LOW 2.1 | microsoft windows_nt The rdisk utility in Microsoft Terminal Server Edition and Windows NT 4.0 stores registry hive information in a temporary file with permissions that allow local users to read it, aka the "RDISK Registry Enumeration File" vulnerability. | 2,3% | — |
| CVE-2014-8000 | MED 5.0 | cisco unified_communications_manager_im_and_presence_service Cisco Unified Communications Manager IM and Presence Service 9.1(1) produces different returned messages for URL requests depending on whether a username exists, which allows remote attackers to enumerate user accounts via a series of requests, aka Bug ID CSCu | 2,3% | — |
| CVE-2014-3279 | MED 5.0 | cisco unified_communications_domain_manager The Administration GUI in the web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 9.0(.1) and earlier does not properly implement access control, which allows remote attackers to enumerate account names via a crafted URL, aka Bug IDs CSC | 2,3% | — |
| CVE-2023-36764 | HIGH 8.8 | microsoft sharepoint_server Microsoft SharePoint Server Elevation of Privilege Vulnerability | 2,3% | — |
| CVE-2015-8555 | HIGH 8.6 | citrix xenserver Xen 4.6.x, 4.5.x, 4.4.x, 4.3.x, and earlier do not initialize x86 FPU stack and XMM registers when XSAVE/XRSTOR are not used to manage guest extended register state, which allows local guest domains to obtain sensitive information from other domains via unspec | 2,3% | — |
| CVE-2024-43602 | CRIT 9.9 | microsoft azure_cyclecloud Azure CycleCloud Remote Code Execution Vulnerability | 2,3% | — |
| CVE-2021-31940 | HIGH 7.8 | microsoft 365_apps Microsoft Office Graphics Remote Code Execution Vulnerability | 2,3% | — |
| CVE-2021-31192 | HIGH 7.8 | microsoft windows_10 Windows Media Foundation Core Remote Code Execution Vulnerability | 2,3% | — |
| CVE-2021-28470 | HIGH 7.8 | microsoft visual_studio_code_github_pull_requests_and_issues Visual Studio Code GitHub Pull Requests and Issues Extension Remote Code Execution Vulnerability | 2,3% | — |
| CVE-2021-28466 | HIGH 7.8 | microsoft raw_image_extension Raw Image Extension Remote Code Execution Vulnerability | 2,3% | — |
| CVE-2021-28464 | HIGH 7.8 | microsoft vp9_video_extensions VP9 Video Extensions Remote Code Execution Vulnerability | 2,3% | — |
| CVE-2018-8431 | MED 5.4 | microsoft sharepoint_enterprise_server An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft | 2,3% | — |
| CVE-2018-8426 | MED 5.4 | microsoft sharepoint_enterprise_server_2013 A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft Office SharePoint XSS Vulnerability." This affects Microsoft SharePoi | 2,3% | — |