EN
57.057 CVE seguite
777 Sfruttate ora
184 Usate dai ransomware
Ultima sincronia

CVE Tracker

57.057 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più alto In KEV dal, ordina dal più alto
CVE-2021-39829 HIGH 7.8 adobe framemaker Adobe Framemaker versions 2019 Update 8 (and earlier) and 2020 Release Update 2 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requ 2,2%
CVE-2020-3411 HIGH 7.5 cisco catalyst_center A vulnerability in Cisco DNA Center software could allow an unauthenticated remote attacker access to sensitive information on an affected system. The vulnerability is due to improper handling of authentication tokens by the affected software. An attacker coul 2,2%
CVE-2018-15448 HIGH 7.5 cisco registered_envelope_service A vulnerability in the user management functions of Cisco Registered Envelope Service could allow an unauthenticated, remote attacker to discover sensitive user information. The attacker could use this information to conduct additional reconnaissance attacks. 2,2%
CVE-2022-35838 HIGH 7.5 microsoft windows_11 HTTP V3 Denial of Service Vulnerability 2,2%
CVE-2021-25642 HIGH 8.8 apache hadoop ZKConfigurationStore which is optionally used by CapacityScheduler of Apache Hadoop YARN deserializes data obtained from ZooKeeper without validation. An attacker having access to ZooKeeper can run arbitrary commands as YARN user by exploiting this. Users shou 2,2%
CVE-2021-24117 MED 4.9 apache teaclave_sgx_sdk In Apache Teaclave Rust SGX SDK 1.1.3, a side-channel vulnerability in base64 PEM file decoding allows system-level (administrator) attackers to obtain information about secret RSA keys via a controlled-channel and side-channel attack on software running in is 2,2%
CVE-2009-4420 HIGH 7.8 f5 big-ip_application_security_manager Buffer overflow in the bd daemon in F5 Networks BIG-IP Application Security Manager (ASM) 9.4.4 through 9.4.7 and 10.0.0 through 10.0.1, and Protocol Security Manager (PSM) 9.4.5 through 9.4.7 and 10.0.0 through 10.0.1, allows remote attackers to cause a denia 2,2%
CVE-2008-0751 MED 4.3 s9y serendipity_event_freetag Cross-site scripting (XSS) vulnerability in the Freetag before 2.96 plugin for S9Y Serendipity, when using Internet Explorer 6 or 7, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to plugin/tag/. 2,2%
CVE-2023-33141 HIGH 7.5 microsoft yet_another_reverse_proxy Yet Another Reverse Proxy (YARP) Denial of Service Vulnerability 2,2%
CVE-2023-32030 HIGH 7.5 microsoft .net_framework .NET and Visual Studio Denial of Service Vulnerability 2,2%
CVE-2024-43565 HIGH 7.5 microsoft windows_10_1507 Windows Network Address Translation (NAT) Denial of Service Vulnerability 2,2%
CVE-2024-43562 HIGH 7.5 microsoft windows_10_1507 Windows Network Address Translation (NAT) Denial of Service Vulnerability 2,2%
CVE-2024-43545 HIGH 7.5 microsoft windows_server_2008 Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability 2,2%
CVE-2024-43544 HIGH 7.5 microsoft windows_server_2008 Microsoft Simple Certificate Enrollment Protocol Denial of Service Vulnerability 2,2%
CVE-2021-26422 HIGH 7.2 microsoft lync_server Skype for Business and Lync Remote Code Execution Vulnerability 2,2%
CVE-2021-1719 HIGH 8.0 microsoft sharepoint_enterprise_server Microsoft SharePoint Elevation of Privilege Vulnerability 2,2%
CVE-2007-5460 MED 4.6 microsoft windows_mobile Microsoft ActiveSync 4.1, as used in Windows Mobile 5.0, uses weak encryption (XOR obfuscation with a fixed key) when sending the user's PIN/Password over the USB connection from the host to the device, which might make it easier for attackers to decode a PIN/ 2,2%
CVE-2022-30206 HIGH 7.8 microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability 2,2%
CVE-2019-15901 HIGH 8.8 doas_project doas An issue was discovered in slicer69 doas before 6.2 on certain platforms other than OpenBSD. A setusercontext(3) call with flags to change the UID, primary GID, and secondary GIDs was replaced (on certain platforms: Linux and possibly NetBSD) with a single set 2,2%
CVE-2018-0007 CRIT 9.8 juniper junos An unauthenticated network-based attacker able to send a maliciously crafted LLDP packet to the local segment, through a local segment broadcast, may be able to cause a Junos device to enter an improper boundary check condition allowing a memory corruption to 2,2%
CVE-2005-0176 MED 5.0 linux linux_kernel The shmctl function in Linux 2.6.9 and earlier allows local users to unlock the memory of other processes, which could cause sensitive memory to be swapped to disk, which could allow it to be read by other users once it has been released. 2,2%
CVE-2024-26202 HIGH 7.2 microsoft windows_server_2012 DHCP Server Service Remote Code Execution Vulnerability 2,2%
CVE-2024-26195 HIGH 7.2 microsoft windows_server_2008 DHCP Server Service Remote Code Execution Vulnerability 2,2%
CVE-2020-1523 HIGH 8.9 microsoft sharepoint_server <p>A tampering vulnerability exists when Microsoft SharePoint Server fails to properly handle profile data. An attacker who successfully exploited this vulnerability could modify a targeted user's profile data.</p> <p>To exploit the vulnerability, an attacker 2,2%
CVE-2002-0507 LOW 2.1 microsoft exchange_server An interaction between Microsoft Outlook Web Access (OWA) with RSA SecurID allows local users to bypass the SecurID authentication for a previous user via several submissions of an OWA Authentication request with the proper OWA password for the previous user, 2,2%