57.061 CVE seguite
777 Sfruttate ora
184 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.061 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2023-21709 | CRIT 9.8 | microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability | 2,0% | — |
| CVE-2019-1962 | HIGH 8.6 | cisco nx-os A vulnerability in the Cisco Fabric Services component of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause process crashes, which can result in a denial of service (DoS) condition on an affected system. The vulnerability is due to | 2,0% | — |
| CVE-2019-12657 | HIGH 7.5 | cisco ios_xe A vulnerability in Unified Threat Defense (UTD) in Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to improper validation of IPv6 packets through the UTD feature. An attacker | 2,0% | — |
| CVE-2019-0874 | MED 6.1 | microsoft azure_devops_server A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server does not properly sanitize user provided input, aka 'Azure DevOps Server Cross-site Scripting Vulnerability'. | 2,0% | — |
| CVE-2017-14010 | HIGH 7.8 | spidercontrol scada_microbrowser In SpiderControl MicroBrowser Windows XP, Vista 7, 8 and 10, Versions 1.6.30.144 and prior, an uncontrolled search path element vulnerability has been identified which could be exploited by placing a specially crafted DLL file in the search path. If the malic | 2,0% | — |
| CVE-2015-4328 | MED 4.0 | cisco telepresence_video_communication_server_software Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 improperly checks for a user account's read-only attribute, which allows remote authenticated users to execute arbitrary OS commands via crafted HTTP requests, as demonstrated by read or wri | 2,0% | — |
| CVE-2015-2829 | HIGH 7.8 | citrix netscaler_application_delivery_controller_firmware Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.5 Build 53.9 through 55.8 and 10.5.e Build 53-9010.e allow remote attackers to cause a denial of service (reboot) via unspecified vectors. | 2,0% | — |
| CVE-2011-0355 | HIGH 7.8 | cisco 1000v_virtual_ethernet_module_\(vem\) Cisco Nexus 1000V Virtual Ethernet Module (VEM) 4.0(4) SV1(1) through SV1(3b), as used in VMware ESX 4.0 and 4.1 and ESXi 4.0 and 4.1, does not properly handle dropped packets, which allows guest OS users to cause a denial of service (ESX or ESXi host OS crash | 2,0% | — |
| CVE-2008-4540 | LOW 2.1 | microsoft windows_mobile Windows Mobile 6 on the HTC Hermes device makes WLAN passwords available to an auto-completion mechanism for the password input field, which allows physically proximate attackers to bypass password authentication and obtain WLAN access. | 2,0% | — |
| CVE-2007-1069 | HIGH 7.8 | vmware workstation The memory management in VMware Workstation before 5.5.4 allows attackers to cause a denial of service (Windows virtual machine crash) by triggering certain general protection faults (GPF). | 2,0% | — |
| CVE-2023-25696 | CRIT 9.8 | apache apache-airflow-providers-apache-hive Improper Input Validation vulnerability in the Apache Airflow Hive Provider. This issue affects Apache Airflow Hive Provider versions before 5.1.3. | 2,0% | — |
| CVE-2022-41056 | HIGH 7.5 | microsoft windows_10 Network Policy Server (NPS) RADIUS Protocol Denial of Service Vulnerability | 2,0% | — |
| CVE-2020-3241 | MED 6.5 | cisco ucs_director A vulnerability in the orchestration tasks of Cisco UCS Director could allow an authenticated, remote attacker to perform a path traversal attack on an affected device. The vulnerability is due to insufficient validation of user-supplied input on the web-based | 2,0% | — |
| CVE-2019-1266 | MED 6.1 | microsoft exchange_server A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web App (OWA) fails to properly handle web requests, aka 'Microsoft Exchange Spoofing Vulnerability'. | 2,0% | — |
| CVE-2015-4291 | HIGH 7.8 | cisco ios_xe Cisco IOS XE 2.x before 2.4.3 and 2.5.x before 2.5.1 on ASR 1000 devices allows remote attackers to cause a denial of service (Embedded Services Processor crash) via a crafted series of fragmented (1) IPv4 or (2) IPv6 packets, aka Bug ID CSCtd72617. | 2,0% | — |
| CVE-2024-49019 | HIGH 7.8 | microsoft windows_server_2008 Active Directory Certificate Services Elevation of Privilege Vulnerability | 2,0% | — |
| CVE-2023-29330 | HIGH 8.8 | microsoft teams Microsoft Teams Remote Code Execution Vulnerability | 2,0% | — |
| CVE-2022-25598 | HIGH 7.5 | apache dolphinscheduler Apache DolphinScheduler user registration is vulnerable to Regular express Denial of Service (ReDoS) attacks, Apache DolphinScheduler users should upgrade to version 2.0.5 or higher. | 2,0% | — |
| CVE-2021-21984 | CRIT 9.8 | vmware vrealize_business_for_cloud VMware vRealize Business for Cloud 7.x prior to 7.6.0 contains a remote code execution vulnerability due to an unauthorised end point. A malicious actor with network access may exploit this issue causing unauthorised remote code execution on vRealize Business | 2,0% | — |
| CVE-2020-5903 | MED 6.1 | f5 big-ip_access_policy_manager In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, a Cross-Site Scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility. | 2,0% | — |
| CVE-2022-35774 | MED 4.9 | microsoft azure_site_recovery_vmware_to_azure Azure Site Recovery Elevation of Privilege Vulnerability | 2,0% | — |
| CVE-2021-43255 | MED 5.5 | microsoft 365_apps Microsoft Office Trust Center Spoofing Vulnerability | 2,0% | — |
| CVE-2021-42732 | HIGH 7.8 | adobe indesign Access of Memory Location After End of Buffer (CWE-788) | 2,0% | — |
| CVE-2025-24991 | MED 5.5 | microsoft windows_10_1507 Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. | 2,0% | |
| CVE-2024-21307 | HIGH 7.5 | microsoft windows_10_1507 Remote Desktop Client Remote Code Execution Vulnerability | 2,0% | — |