56.565 CVE seguite
773 Sfruttate ora
181 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.565 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2020-17530 | CRIT 9.8 | apache struts Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25. | 95,6% | |
| CVE-2020-5410 | HIGH 7.5 | vmware spring_cloud_config Spring Cloud Config, versions 2.2.x prior to 2.2.3, versions 2.1.x prior to 2.1.9, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a | 95,6% | |
| CVE-2023-21554 | CRIT 9.8 | microsoft windows_10_1607 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 95,5% | — |
| CVE-2024-21412 | HIGH 8.1 | ransomware microsoft windows_10_1809 Internet Shortcut Files Security Feature Bypass Vulnerability | 95,4% | |
| CVE-2023-49070 | CRIT 9.8 | apache ofbiz Pre-auth RCE in Apache Ofbiz 18.12.09. It's due to XML-RPC no longer maintained still present. This issue affects Apache OFBiz: before 18.12.10. Users are recommended to upgrade to version 18.12.10 | 95,4% | — |
| CVE-2008-1447 | MED 6.8 | isc bind The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2; and other implementations allow remote attackers to spoof DNS traffic via a birthd | 95,2% | — |
| CVE-2002-0840 | MED 6.8 | apache http_server Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS is present, allows remote attackers to execute script as other web page visitors | 95,1% | — |
| CVE-2002-0392 | HIGH 7.5 | apache http_server Apache 1.3 through 1.3.24, and Apache 2.0 through 2.0.36, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a chunk-encoded HTTP request that causes Apache to use an incorrect size. | 95,0% | — |
| CVE-2017-9798 | HIGH 7.5 | apache http_server Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user's .htaccess file, or if httpd.conf has certain misconfigurations, aka Optionsbleed. This affects the Apache HTTP Server through 2.2.34 and | 95,0% | — |
| CVE-2014-6332 | HIGH 8.8 | microsoft windows_7 OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary co | 95,0% | |
| CVE-2024-47575 | CRIT 9.8 | fortinet fortimanager A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiManager 6.4.0 through 6.4.14, FortiManager 6.2.0 through 6.2.12, Fortinet FortiMan | 95,0% | |
| CVE-2006-3918 | MED 4.3 | apache http_server http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, and 2.2 before 2.2.2, does not sanitize the Expect header from an HTTP request when it is reflected back in an e | 94,9% | — |
| CVE-2024-9474 | HIGH 7.2 | ransomware paloaltonetworks pan-os A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access are not impacted by this | 94,8% | |
| CVE-2019-11478 | MED 5.3 | canonical ubuntu_linux Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP Selective Acknowledgment (SACK) sequences. A remote attacker could use this to cause a denial of servi | 94,7% | — |
| CVE-2023-24941 | CRIT 9.8 | microsoft windows_server_2012 Windows Network File System Remote Code Execution Vulnerability | 94,7% | — |
| CVE-2023-24489 | CRIT 9.8 | citrix sharefile_storage_zones_controller A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated attacker to remotely compromise the customer-managed ShareFile storage zones controller. | 94,7% | |
| CVE-2024-21413 | CRIT 9.8 | microsoft 365_apps Microsoft Outlook Remote Code Execution Vulnerability | 94,7% | |
| CVE-2013-2248 | MED 5.8 | apache struts Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in a parameter using the (1) redirect: or (2) redirectAction: prefix. | 94,7% | — |
| CVE-2024-31309 | HIGH 7.5 | apache traffic_server HTTP/2 CONTINUATION DoS attack can cause Apache Traffic Server to consume more resources on the server. Version from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.3 are affected. Users can set a new setting (proxy.config.http2.max_continuation_frames_per_minut | 94,6% | — |
| CVE-2014-0515 | HIGH 10.0 | adobe flash_player Buffer overflow in Adobe Flash Player before 11.7.700.279 and 11.8.x through 13.0.x before 13.0.0.206 on Windows and OS X, and before 11.2.202.356 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in | 94,6% | — |
| CVE-2025-8088 | HIGH 8.8 | ransomware dtsearch dtsearch A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and P | 94,6% | |
| CVE-2010-3972 | HIGH 10.0 | microsoft internet_information_services Heap-based buffer overflow in the TELNET_STREAM_CONTEXT::OnSendData function in ftpsvc.dll in Microsoft FTP Service 7.0 and 7.5 for Internet Information Services (IIS) 7.0, and IIS 7.5, allows remote attackers to execute arbitrary code or cause a denial of ser | 94,5% | — |
| CVE-2018-11784 | MED 4.3 | apache tomcat When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. redirecting to '/foo/' when the user requested '/foo') a specially crafted URL could be used to cause the redir | 94,5% | — |
| CVE-2009-0580 | MED 4.3 | apache tomcat Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when FORM authentication is used, allows remote attackers to enumerate valid usernames via requests to /j_security_check with malformed URL encoding of passwords, related to im | 94,4% | — |
| CVE-2020-1147 | HIGH 7.8 | microsoft .net_core A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulner | 94,3% |