56.571 CVE seguite
773 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.571 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più basso | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2022-38378 | MED 4.2 | fortinet fortios An improper privilege management vulnerability [CWE-269] in Fortinet FortiOS version 7.2.0 and before 7.0.7 and FortiProxy version 7.2.0 through 7.2.1 and before 7.0.7 allows an attacker that has access to the admin profile section (System subsection Administr | 0,2% | — |
| CVE-2022-29127 | MED 4.2 | microsoft windows_10 BitLocker Security Feature Bypass Vulnerability | 0,8% | — |
| CVE-2022-22456 | MED 4.2 | ibm security_verify_governance IBM Security Verify Governance, Identity Manager 10.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclos | 0,3% | — |
| CVE-2022-21931 | MED 4.2 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 1,2% | — |
| CVE-2022-21930 | MED 4.2 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 1,2% | — |
| CVE-2021-43221 | MED 4.2 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 1,1% | — |
| CVE-2021-42279 | MED 4.2 | microsoft windows_10 Chakra Scripting Engine Memory Corruption Vulnerability | 2,2% | — |
| CVE-2021-41363 | MED 4.2 | microsoft intune_management_extension Intune Management Extension Security Feature Bypass Vulnerability | 0,5% | — |
| CVE-2021-39011 | MED 4.2 | ibm cloud_pak_for_security IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.6.0 stores potentially sensitive information in log files that could be read by a privileged user. IBM X-Force ID: 213645. | 0,6% | — |
| CVE-2021-36195 | MED 4.2 | fortinet fortiweb Multiple command injection vulnerabilities in the command line interpreter of FortiWeb versions 6.4.1, 6.4.0, 6.3.0 through 6.3.15, 6.2.0 through 6.2.6, and 6.1.0 through 6.1.2 may allow an authenticated attacker to execute arbitrary commands on the underlying | 1,1% | — |
| CVE-2021-36177 | MED 4.2 | fortinet fortiauthenticator An improper access control vulnerability [CWE-284] in FortiAuthenticator HA service 6.3.2 and below, 6.2.x, 6.1.x, 6.0.x may allow an attacker on the same vlan as the HA management interface to make an unauthenticated direct connection to the FAC's database. | 0,3% | — |
| CVE-2021-36169 | MED 4.2 | fortinet fortios A Hidden Functionality in Fortinet FortiOS 7.x before 7.0.1, FortiOS 6.4.x before 6.4.7 allows attacker to Execute unauthorized code or commands via specific hex read/write operations. | 0,3% | — |
| CVE-2021-3047 | MED 4.2 | paloaltonetworks pan-os A cryptographically weak pseudo-random number generator (PRNG) is used during authentication to the Palo Alto Networks PAN-OS web interface. This enables an authenticated attacker, with the capability to observe their own authentication secrets over a long dur | 0,5% | — |
| CVE-2021-28316 | MED 4.2 | microsoft windows_10 Windows WLAN AutoConfig Service Security Feature Bypass Vulnerability | 1,1% | — |
| CVE-2021-1705 | MED 4.2 | microsoft edge Microsoft Edge (HTML-based) Memory Corruption Vulnerability | 1,9% | — |
| CVE-2020-7252 | MED 4.2 | mcafee data_exchange_layer Unquoted service executable path in DXL Broker in McAfee Data eXchange Layer (DXL) Framework 6.0.0 and earlier allows local users to cause a denial of service and malicious file execution via carefully crafted and named executable files. | 0,5% | — |
| CVE-2020-26558 | MED 4.2 | bluetooth bluetooth_core_specification Bluetooth LE and BR/EDR secure pairing in Bluetooth Core Specification 2.1 through 5.2 may permit a nearby man-in-the-middle attacker to identify the Passkey used during pairing (in the Passkey authentication procedure) by reflection of the public key and the | 0,9% | — |
| CVE-2020-1988 | MED 4.2 | paloaltonetworks globalprotect An unquoted search path vulnerability in the Windows release of Global Protect Agent allows an authenticated local user with file creation privileges on the root of the OS disk (C:\) or to Program Files directory to gain system privileges. This issue affects P | 0,4% | — |
| CVE-2020-17131 | MED 4.2 | microsoft chakracore Chakra Scripting Engine Memory Corruption Vulnerability | 1,8% | — |
| CVE-2020-17054 | MED 4.2 | microsoft chakracore Chakra Scripting Engine Memory Corruption Vulnerability | 2,1% | — |
| CVE-2020-17048 | MED 4.2 | microsoft chakracore Chakra Scripting Engine Memory Corruption Vulnerability | 1,6% | — |
| CVE-2020-16884 | MED 4.2 | microsoft edge <p>A remote code execution vulnerability exists in the way that the IEToEdge Browser Helper Object (BHO) plugin on Internet Explorer handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code i | 1,8% | — |
| CVE-2020-1567 | MED 4.2 | microsoft internet_explorer A remote code execution vulnerability exists in the way that the MSHTML engine improperly validates input. An attacker could execute arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacke | 3,7% | — |
| CVE-2020-1566 | MED 4.2 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, | 1,7% | — |
| CVE-2020-14416 | MED 4.2 | linux linux_kernel In the Linux kernel before 5.4.16, a race condition in tty->disc_data handling in the slip and slcan line discipline could lead to a use-after-free, aka CID-0ace17d56824. This affects drivers/net/slip/slip.c and drivers/net/can/slcan.c. | 0,3% | — |