56.801 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.801 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più basso | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2022-20686 | MED 5.3 | cisco ata_190_firmware Multiple vulnerabilities in the Link Layer Discovery Protocol (LLDP) functionality of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device and cause the LLDP serv | 0,9% | — |
| CVE-2022-20675 | MED 5.3 | cisco asyncos A vulnerability in the TCP/IP stack of Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), and Cisco Secure Email and Web Manager, formerly Security Management Appliance, could allow an unauthenticated, remote attacker to crash the Simple | 1,3% | — |
| CVE-2022-20633 | MED 5.3 | cisco enterprise_chat_and_email A vulnerability in the web-based management interface of Cisco ECE could allow an unauthenticated, remote attacker to perform a username enumeration attack against an affected device. This vulnerability is due to differences in authentication responses | 0,8% | — |
| CVE-2022-1901 | MED 5.3 | octopus octopus_server In affected versions of Octopus Deploy it is possible to unmask sensitive variables by using variable preview. | 0,5% | — |
| CVE-2022-0564 | MED 5.3 | qlik qlik_sense A vulnerability in Qlik Sense Enterprise on Windows could allow an remote attacker to enumerate domain user accounts. An attacker could exploit this vulnerability by sending authentication requests to an affected system. A successful exploit could allow the at | 1,4% | — |
| CVE-2021-47482 | MED 5.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: batman-adv: fix error handling Syzbot reported ODEBUG warning in batadv_nc_mesh_free(). The problem was in wrong error handling in batadv_mesh_init(). Before this patch batadv_mesh_ini | 0,7% | — |
| CVE-2021-47467 | MED 5.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: kunit: fix reference count leak in kfree_at_end The reference counting issue happens in the normal path of kfree_at_end(). When kunit_alloc_and_get_resource() is invoked, the function forget | 0,5% | — |
| CVE-2021-47384 | MED 5.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: hwmon: (w83793) Fix NULL pointer dereference by removing unnecessary structure field If driver read tmp value sufficient for (tmp & 0x08) && (!(tmp & 0x80)) && ((tmp & 0x7) == ((tmp >> 4) & | 1,0% | — |
| CVE-2021-47192 | MED 5.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: scsi: core: sysfs: Fix hang when device state is set via sysfs This fixes a regression added with: commit f0f82e2476f6 ("scsi: core: Fix capacity set to zero after offlinining device") The | 0,6% | — |
| CVE-2021-47140 | MED 5.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Clear DMA ops when switching domain Since commit 08a27c1c3ecf ("iommu: Add support to change default domain of an iommu group") a user can switch a device between IOMMU and direct | 0,6% | — |
| CVE-2021-47075 | MED 5.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvmet: fix memory leak in nvmet_alloc_ctrl() When creating ctrl in nvmet_alloc_ctrl(), if the cntlid_min is larger than cntlid_max of the subsystem, and jumps to the "out_free_changed_ns_lis | 0,9% | — |
| CVE-2021-47064 | MED 5.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mt76: fix potential DMA mapping leak With buf uninitialized in mt76_dma_tx_queue_skb_raw, its field skip_unmap could potentially inherit a non-zero value from stack garbage. If this happens, | 0,8% | — |
| CVE-2021-46873 | MED 5.3 | wireguard wireguard WireGuard, such as WireGuard 0.5.3 on Windows, does not fully account for the possibility that an adversary might be able to set a victim's system time to a future value, e.g., because unauthenticated NTP is used. This can lead to an outcome in which one stati | 0,5% | — |
| CVE-2021-43410 | MED 5.3 | apache airavata_django_portal Apache Airavata Django Portal allows CRLF log injection because of lack of escaping log statements. In particular, some HTTP request parameters are logged without first being escaped. Versions affected: master branch before commit 3c5d8c7 [1] of airavata-djang | 2,4% | — |
| CVE-2021-41831 | MED 5.3 | apache openoffice It is possible for an attacker to manipulate the timestamp of signed documents. All versions of Apache OpenOffice up to 4.1.10 are affected. Users are advised to update to version 4.1.11. See CVE-2021-25634 for the LibreOffice advisory. | 1,5% | — |
| CVE-2021-41532 | MED 5.3 | apache ozone In Apache Ozone before 1.2.0, Recon HTTP endpoints provide access to OM, SCM and Datanode metadata. Due to a bug, any unauthenticated user can access the data from these endpoints. | 2,3% | — |
| CVE-2021-41346 | MED 5.3 | microsoft windows_10 Console Window Host Security Feature Bypass Vulnerability | 0,6% | — |
| CVE-2021-41013 | MED 5.3 | fortinet fortiweb An improper access control vulnerability [CWE-284] in FortiWeb versions 6.4.1 and below and 6.3.15 and below in the Report Browse section of Log & Report may allow an unauthorized and unauthenticated user to access the Log reports via their URLs. | 0,9% | — |
| CVE-2021-40482 | MED 5.3 | microsoft sharepoint_server Microsoft SharePoint Server Information Disclosure Vulnerability | 2,3% | — |
| CVE-2021-40456 | MED 5.3 | microsoft windows_server Windows AD FS Security Feature Bypass Vulnerability | 2,3% | — |
| CVE-2021-4040 | MED 5.3 | apache artemis A flaw was found in AMQ Broker. This issue can cause a partial interruption to the availability of AMQ Broker via an Out of memory (OOM) condition. This flaw allows an attacker to partially disrupt availability to the broker through a sustained attack of malic | 3,1% | — |
| CVE-2021-40128 | MED 5.3 | cisco webex_meetings A vulnerability in the account activation feature of Cisco Webex Meetings could allow an unauthenticated, remote attacker to send an account activation email with an activation link that points to an arbitrary domain. This vulnerability is due to insufficient | 1,0% | — |
| CVE-2021-40127 | MED 5.3 | cisco sf200-24_firmware A vulnerability in the web-based management interface of Cisco Small Business 200 Series Smart Switches, Cisco Small Business 300 Series Managed Switches, and Cisco Small Business 500 Series Stackable Managed Switches could allow an unauthenticated, remote att | 1,3% | — |
| CVE-2021-40125 | MED 5.3 | cisco adaptive_security_appliance_software A vulnerability in the Internet Key Exchange Version 2 (IKEv2) implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to trigger a denial of service (Do | 1,0% | — |
| CVE-2021-39086 | MED 5.3 | ibm sterling_file_gateway IBM Sterling File Gateway 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be | 0,9% | — |