56.658 CVE seguite
776 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.658 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più basso | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2021-27363 | MED 4.4 | debian debian_linux An issue was discovered in the Linux kernel through 5.11.3. A kernel pointer leak can be used to determine the address of the iscsi_transport structure. When an iSCSI transport is registered with the iSCSI subsystem, the transport's handle is available to unpr | 0,7% | — |
| CVE-2021-27094 | MED 4.4 | microsoft windows_10 Windows Early Launch Antimalware Driver Security Feature Bypass Vulnerability | 1,0% | — |
| CVE-2021-26428 | MED 4.4 | microsoft azure_sphere Azure Sphere Information Disclosure Vulnerability | 0,9% | — |
| CVE-2021-26099 | MED 4.4 | fortinet fortimail Missing cryptographic steps in the Identity-Based Encryption service of FortiMail before 7.0.0 may allow an attacker who comes in possession of the encrypted master keys to compromise their confidentiality by observing a few invariant properties of the ciphert | 0,5% | — |
| CVE-2021-20317 | MED 4.4 | debian debian_linux A flaw was found in the Linux kernel. A corrupted timer tree caused the task wakeup to be missing in the timerqueue_add function in lib/timerqueue.c. This flaw allows a local attacker with special user privileges to cause a denial of service, slowing and event | 0,4% | — |
| CVE-2021-20177 | MED 4.4 | linux linux_kernel A flaw was found in the Linux kernel's implementation of string matching within a packet. A privileged user (with root or CAP_NET_ADMIN) when inserting iptables rules could insert a rule which can panic the system. Kernel before kernel 5.5-rc1 is affected. | 0,3% | — |
| CVE-2021-1583 | MED 4.4 | cisco nx-os A vulnerability in the fabric infrastructure file system access control of Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an authenticated, local attacker to read arbitrary files on an affected system. This | 0,2% | — |
| CVE-2021-1436 | MED 4.4 | cisco ios_xe A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to conduct path traversal attacks and obtain read access to sensitive files on an affected system. This vulnerability is due to insufficient validation of u | 0,3% | — |
| CVE-2021-1434 | MED 4.4 | cisco ios_xe A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to overwrite arbitrary files in the underlying file system. This vulnerability is due to insufficient validation of the parameters of a specific CLI command | 0,2% | — |
| CVE-2021-1423 | MED 4.4 | cisco aironet_access_point_software A vulnerability in the implementation of a CLI command in Cisco Aironet Access Points (AP) could allow an authenticated, local attacker to overwrite files in the flash memory of the device. This vulnerability is due to insufficient input validation for a speci | 0,2% | — |
| CVE-2021-1306 | MED 4.4 | cisco evolved_programmable_network_manager A vulnerability in the restricted shell of Cisco Evolved Programmable Network (EPN) Manager, Cisco Identity Services Engine (ISE), and Cisco Prime Infrastructure could allow an authenticated, local attacker to identify directories and write arbitrary files to | 0,2% | — |
| CVE-2021-1233 | MED 4.4 | cisco catalyst_sd-wan_manager A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to access sensitive information on an affected device. The vulnerability is due to insufficient input validation of requests that are sent to the iperf tool. An at | 0,3% | — |
| CVE-2020-9497 | MED 4.4 | apache guacamole Apache Guacamole 1.1.0 and older do not properly validate datareceived from RDP servers via static virtual channels. If a userconnects to a malicious or compromised RDP server, specially-craftedPDUs could result in disclosure of information within the memory o | 0,8% | — |
| CVE-2020-5021 | MED 4.4 | ibm spectrum_protect_plus IBM Spectrum Protect Plus 10.1.0 through 10.1.6 does not invalidate session after a password reset which could allow a local user to impersonate another user on the system. IBM X-Force ID: 193657. | 0,2% | — |
| CVE-2020-4976 | MED 4.4 | ibm db2 IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to read and write specific files due to weak file permissions. IBM X-Force ID: 192469. | 0,3% | — |
| CVE-2020-4606 | MED 4.4 | ibm security_verify_privilege_manager IBM Security Verify Privilege Manager 10.8 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A local attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 1 | 0,3% | — |
| CVE-2020-4604 | MED 4.4 | ibm security_guardium_insights IBM Security Guardium Insights 2.0.2 stores user credentials in plain in clear text which can be read by a local privileged user. IBM X-Force ID: 184861. | 0,2% | — |
| CVE-2020-4602 | MED 4.4 | ibm security_guardium_insights IBM Security Guardium Insights 2.0.2 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 184836. | 0,3% | — |
| CVE-2020-4593 | MED 4.4 | ibm security_guardium_insights IBM Security Guardium Insights 2.0.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 184747. | 0,3% | — |
| CVE-2020-4414 | MED 4.4 | ibm db2 IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local attacker to perform unauthorized actions on the system, caused by improper usage of shared memory. By sending a specially-crafted request, an | 0,3% | — |
| CVE-2020-4191 | MED 4.4 | ibm security_guardium IBM Security Guardium 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 174852. | 0,2% | — |
| CVE-2020-3601 | MED 4.4 | cisco staros A vulnerability in the CLI of Cisco StarOS operating system for Cisco ASR 5000 Series Routers could allow an authenticated, local attacker to elevate privileges on an affected device. The vulnerability is due to insufficient input validation of CLI commands. A | 0,4% | — |
| CVE-2020-3541 | MED 4.4 | cisco webex_meetings A vulnerability in the media engine component of Cisco Webex Meetings Client for Windows, Cisco Webex Meetings Desktop App for Windows, and Cisco Webex Teams for Windows could allow an authenticated, local attacker to gain access to sensitive information. The | 0,3% | — |
| CVE-2020-3389 | MED 4.4 | cisco hyperflex_hx-series_software A vulnerability in the installation component of Cisco Hyperflex HX-Series Software could allow an authenticated, local attacker to retrieve the password that was configured at installation on an affected device. The vulnerability exists because sensitive info | 0,2% | — |
| CVE-2020-3301 | MED 4.4 | cisco secure_firewall_management_center Multiple vulnerabilities in Cisco Firepower Management Center (FMC) Software and Cisco Firepower User Agent Software could allow an attacker to access a sensitive part of an affected system with a high-privileged account. For more information about these vulne | 0,8% | — |