57.080 CVE seguite
777 Sfruttate ora
184 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.080 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più basso | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2021-26884 | MED 5.5 | microsoft windows_10 Windows Media Photo Codec Information Disclosure Vulnerability | 1,0% | — |
| CVE-2021-26869 | MED 5.5 | microsoft windows_10 Windows ActiveX Installer Service Information Disclosure Vulnerability | 1,0% | — |
| CVE-2021-26437 | MED 5.5 | microsoft visual_studio_code Visual Studio Code Spoofing Vulnerability | 2,3% | — |
| CVE-2021-26417 | MED 5.5 | microsoft windows_10 Windows Overlay Filter Information Disclosure Vulnerability | 0,8% | — |
| CVE-2021-25252 | MED 5.5 | trendmicro apex_central Trend Micro's Virus Scan API (VSAPI) and Advanced Threat Scan Engine (ATSE) - are vulnerable to a memory exhaustion vulnerability that may lead to denial-of-service or system freeze if exploited by an attacker using a specially crafted file. | 0,6% | — |
| CVE-2021-25248 | MED 5.5 | trendmicro apex_one An out-of-bounds read information disclosure vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security (10.0 SP1 and Services) could allow an attacker to disclose sensitive information about a named pipe. Ple | 0,9% | — |
| CVE-2021-24107 | MED 5.5 | microsoft windows_10 Windows Event Tracing Information Disclosure Vulnerability | 1,0% | — |
| CVE-2021-24106 | MED 5.5 | microsoft windows_10 Windows DirectX Information Disclosure Vulnerability | 0,9% | — |
| CVE-2021-24098 | MED 5.5 | microsoft windows_10 Windows Console Driver Denial of Service Vulnerability | 1,5% | — |
| CVE-2021-24084 | MED 5.5 | microsoft windows_10 Windows Mobile Device Management Information Disclosure Vulnerability | 2,8% | — |
| CVE-2021-24079 | MED 5.5 | microsoft windows_10 Windows Backup Engine Information Disclosure Vulnerability | 0,9% | — |
| CVE-2021-24076 | MED 5.5 | microsoft windows_10 Microsoft Windows VMSwitch Information Disclosure Vulnerability | 0,9% | — |
| CVE-2021-23827 | MED 5.5 | keybase keybase Keybase Desktop Client before 5.6.0 on Windows and macOS, and before 5.6.1 on Linux, allows an attacker to obtain potentially sensitive media (such as private pictures) in the Cache and uploadtemps directories. It fails to effectively clear cached pictures, ev | 0,3% | — |
| CVE-2021-23021 | MED 5.5 | f5 nginx_controller The Nginx Controller 3.x before 3.7.0 agent configuration file /etc/controller-agent/agent.conf is world readable with current permission bits set to 644. | 0,2% | — |
| CVE-2021-23020 | MED 5.5 | f5 nginx_controller The NAAS 3.x before 3.10.0 API keys were generated using an insecure pseudo-random string and hashing algorithm which could lead to predictable keys. | 0,3% | — |
| CVE-2021-22020 | MED 5.5 | vmware cloud_foundation The vCenter Server contains a denial-of-service vulnerability in the Analytics service. Successful exploitation of this issue may allow an attacker to create a denial-of-service condition on vCenter Server. | 0,2% | — |
| CVE-2021-22007 | MED 5.5 | vmware cloud_foundation The vCenter Server contains a local information disclosure vulnerability in the Analytics service. An authenticated user with non-administrative privilege may exploit this issue to gain access to sensitive information. | 0,2% | — |
| CVE-2021-21997 | MED 5.5 | vmware tools VMware Tools for Windows (11.x.y prior to 11.3.0) contains a denial-of-service vulnerability in the VM3DMP driver. A malicious actor with local user privileges in the Windows guest operating system, where VMware Tools is installed, can trigger a PANIC in the V | 0,7% | — |
| CVE-2021-21292 | MED 5.5 | traccar traccar Traccar is an open source GPS tracking system. In Traccar before version 4.12 there is an unquoted Windows binary path vulnerability. Only Windows versions are impacted. Attacker needs write access to the filesystem on the host machine. If Java path includes a | 0,4% | — |
| CVE-2021-21096 | MED 5.5 | adobe bridge Adobe Bridge versions 10.1.1 (and earlier) and 11.0.1 (and earlier) are affected by an Improper Authorization vulnerability in the Genuine Software Service. A low-privileged attacker could leverage this vulnerability to achieve application denial-of-service in | 0,7% | — |
| CVE-2021-20490 | MED 5.5 | ibm spectrum_protect_plus IBM Spectrum Protect Plus 10.1.0 through 10.1.8 could allow a local user to cause a denial of service due to insecure file permission settings. IBM X-Force ID: 197791. | 0,2% | — |
| CVE-2021-20408 | MED 5.5 | ibm security_verify_information_queue IBM Security Verify Information Queue 1.0.6 and 1.0.7 could disclose highly sensitive information to a local user due to inproper storage of a plaintext cryptographic key. IBM X-Force ID: 198187. | 0,2% | — |
| CVE-2021-20320 | MED 5.5 | fedoraproject fedora A flaw was found in s390 eBPF JIT in bpf_jit_insn in arch/s390/net/bpf_jit_comp.c in the Linux kernel. In this flaw, a local attacker with special user privilege can circumvent the verifier and may lead to a confidentiality problem. | 0,3% | — |
| CVE-2021-20265 | MED 5.5 | linux linux_kernel A flaw was found in the way memory resources were freed in the unix_stream_recvmsg function in the Linux kernel when a signal was pending. This flaw allows an unprivileged local user to crash the system by exhausting available memory. The highest threat from t | 0,3% | — |
| CVE-2021-20219 | MED 5.5 | linux linux_kernel A denial of service vulnerability was found in n_tty_receive_char_special in drivers/tty/n_tty.c of the Linux kernel. In this flaw a local attacker with a normal user privilege could delay the loop (due to a changing ldata->read_head, and a missing sanity chec | 0,4% | — |