57.057 CVE seguite
777 Sfruttate ora
184 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.057 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2017-8712 | MED 5.3 | microsoft windows_10 The Windows Hyper-V component on Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an information disclosure vulnerability when it fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Information D | 2,1% | — |
| CVE-2017-8711 | MED 5.3 | microsoft windows_10 The Windows Hyper-V component on Microsoft Windows 10 1607 and Windows Server 2016 allows an information disclosure vulnerability when it fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Information Disclosu | 2,1% | — |
| CVE-2017-3155 | MED 6.1 | apache atlas Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to cross frame scripting. | 2,1% | — |
| CVE-2001-0666 | LOW 2.1 | microsoft exchange_server Outlook Web Access (OWA) in Microsoft Exchange 2000 allows an authenticated user to cause a denial of service (CPU consumption) via a malformed OWA request for a deeply nested folder within the user's mailbox. | 2,1% | — |
| CVE-2023-31248 | HIGH 7.8 | canonical ubuntu_linux Linux Kernel nftables Use-After-Free Local Privilege Escalation Vulnerability; `nft_chain_lookup_byid()` failed to check whether a chain was active and CAP_NET_ADMIN is in any user or network namespace | 2,1% | — |
| CVE-2022-46764 | CRIT 9.8 | trueconf server A SQL injection issue in the web API in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows remote unauthenticated attackers to execute arbitrary SQL commands, ultimately leading to remote code execution. | 2,1% | — |
| CVE-2022-21983 | HIGH 7.5 | microsoft windows_10 Win32 Stream Enumeration Remote Code Execution Vulnerability | 2,1% | — |
| CVE-2017-0189 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows 10 when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode, aka "Win32k Elevatio | 2,1% | — |
| CVE-2016-4766 | HIGH 8.8 | apple iphone_os WebKit in Apple iOS before 10, tvOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2 | 2,1% | — |
| CVE-2009-2975 | MED 5.0 | mozilla firefox Mozilla Firefox 3.5.2 on Windows XP, in some situations possibly involving an incompletely configured protocol handler, does not properly implement setting the document.location property to a value specifying a protocol associated with an external application, | 2,1% | — |
| CVE-2005-4258 | HIGH 7.8 | cisco catalyst Unspecified Cisco Catalyst Switches allow remote attackers to cause a denial of service (device crash) via an IP packet with the same source and destination IPs and ports, and with the SYN flag set (aka LanD). NOTE: the provenance of this issue is unknown; the | 2,1% | — |
| CVE-2005-3809 | HIGH 7.8 | linux linux_kernel The nfattr_to_tcp function in ip_conntrack_proto_tcp.c in ctnetlink in Linux kernel 2.6.14 up to 2.6.14.3 allows attackers to cause a denial of service (kernel oops) via an update message without private protocol information, which triggers a null dereference. | 2,1% | — |
| CVE-2026-26127 | HIGH 7.5 | microsoft .net Out-of-bounds read in .NET allows an unauthorized attacker to deny service over a network. | 2,0% | — |
| CVE-2020-17015 | MED 4.3 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability | 2,0% | — |
| CVE-2019-0986 | MED 6.3 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks. An attacker who successfully exploited this vulnerability could delete files and folders in an elevated context. To exploit this vulnera | 2,0% | — |
| CVE-2015-6388 | MED 5.0 | cisco unified_computing_system_central_software Cisco Unified Computing System (UCS) Central software 1.3(0.1) allows remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted request, aka Bug ID CSCux33575. | 2,0% | — |
| CVE-2015-0590 | MED 5.0 | cisco webex_meeting_center Cisco WebEx Meeting Center allows remote attackers to activate disabled meeting attributes, and consequently obtain sensitive information, by providing crafted parameters during a meeting-join action, aka Bug ID CSCuo34165. | 2,0% | — |
| CVE-2012-4094 | MED 5.4 | cisco unified_computing_system Buffer overflow in the Smart Call Home feature in the fabric interconnect in Cisco Unified Computing System (UCS) allows remote attackers to cause a denial of service by reading and forging control messages associated with Smart Call Home reports, aka Bug ID C | 2,0% | — |
| CVE-2022-22024 | HIGH 7.8 | microsoft windows_10 Windows Fax Service Remote Code Execution Vulnerability | 2,0% | — |
| CVE-2018-0344 | HIGH 7.2 | cisco vbond_orchestrator A vulnerability in the vManage dashboard for the configuration and management service of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject and execute arbitrary commands with vmanage user privileges on an affected system. The vu | 2,0% | — |
| CVE-2016-9195 | MED 5.3 | cisco wireless_lan_controller A vulnerability in RADIUS Change of Authorization (CoA) request processing in the Cisco Wireless LAN Controller (WLC) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition by disconnecting a single connection. This vulner | 2,0% | — |
| CVE-2003-1463 | LOW 3.5 | alt-n webadmin Absolute path traversal vulnerability in Alt-N Technologies WebAdmin 2.0.0 through 2.0.2 allows remote attackers with administrator privileges to (1) determine the installation path by reading the contents of the Name parameter in a link, and (2) read arbitrar | 2,0% | — |
| CVE-2024-41835 | MED 5.5 | adobe acrobat Acrobat Reader versions 20.005.30636, 24.002.20965, 24.002.20964, 24.001.30123 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigation | 2,0% | — |
| CVE-2024-41832 | MED 5.5 | adobe acrobat Acrobat Reader versions 20.005.30636, 24.002.20965, 24.002.20964, 24.001.30123 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigation | 2,0% | — |
| CVE-2018-4212 | HIGH 8.8 | apple icloud In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks. | 2,0% | — |