57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.971 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2024-30075 | HIGH 8.0 | microsoft windows_server_2008 Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability | 0,9% | — |
| CVE-2023-29178 | MED 4.3 | fortinet fortios A access of uninitialized pointer vulnerability [CWE-824] in Fortinet FortiProxy version 7.2.0 through 7.2.3 and before 7.0.9 and FortiOS version 7.2.0 through 7.2.4 and before 7.0.11 allows an authenticated attacker to repetitively crash the httpsd process v | 0,9% | — |
| CVE-2023-28346 | HIGH 7.3 | faronics insight An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for a remote attacker to communicate with the private API endpoints exposed at /login, /consoleSettings, /console, etc. despite Virtual Host Routing being used to block this acce | 0,9% | — |
| CVE-2023-21795 | HIGH 8.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 0,9% | — |
| CVE-2021-26633 | HIGH 7.5 | maxb maxboard SQL injection and Local File Inclusion (LFI) vulnerabilities in MaxBoard can cause information leakage and privilege escalation. This vulnerabilities can be exploited by manipulating a variable with a desired value and inserting and arbitrary file. | 0,9% | — |
| CVE-2022-30990 | HIGH 7.5 | acronis agent Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect 15 (Linux) before build 29240, Acronis Agent (Linux) before build 28037 | 0,9% | — |
| CVE-2021-26434 | HIGH 7.8 | microsoft visual_studio_2017 Visual Studio Elevation of Privilege Vulnerability | 0,9% | — |
| CVE-2019-1028 | HIGH 7.8 | microsoft windows_10 An elevation of privilege exists in Windows Audio Service. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges. To exploit the vulnerability, an attacker could run a specially crafted application that coul | 0,9% | — |
| CVE-2019-1027 | HIGH 7.8 | microsoft windows_10 An elevation of privilege exists in Windows Audio Service. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges. To exploit the vulnerability, an attacker could run a specially crafted application that coul | 0,9% | — |
| CVE-2019-1026 | HIGH 7.8 | microsoft windows_10 An elevation of privilege exists in Windows Audio Service. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges. To exploit the vulnerability, an attacker could run a specially crafted application that coul | 0,9% | — |
| CVE-2019-1022 | HIGH 7.8 | microsoft windows_10 An elevation of privilege exists in Windows Audio Service. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges. To exploit the vulnerability, an attacker could run a specially crafted application that coul | 0,9% | — |
| CVE-2019-1021 | HIGH 7.8 | microsoft windows_10 An elevation of privilege exists in Windows Audio Service. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges. To exploit the vulnerability, an attacker could run a specially crafted application that coul | 0,9% | — |
| CVE-2010-0144 | HIGH 7.8 | cisco ironport_encryption_appliance Unspecified vulnerability in the WebSafe DistributorServlet in the embedded HTTPS server on the Cisco IronPort Encryption Appliance 6.2.x before 6.2.9.1 and 6.5.x before 6.5.2, and the IronPort PostX MAP before 6.2.9.1, allows remote attackers to read arbitrar | 0,9% | — |
| CVE-2010-0143 | HIGH 7.8 | cisco ironport_encryption_appliance Unspecified vulnerability in the administrative interface in the embedded HTTPS server on the Cisco IronPort Encryption Appliance 6.2.x before 6.2.9.1 and 6.5.x before 6.5.2, and the IronPort PostX MAP before 6.2.9.1, allows remote attackers to read arbitrary | 0,9% | — |
| CVE-2006-7051 | MED 4.9 | linux linux_kernel The sys_timer_create function in posix-timers.c for Linux kernel 2.6.x allows local users to cause a denial of service (memory consumption) and possibly bypass memory limits or cause other processes to be killed by creating a large number of posix timers, whic | 0,9% | — |
| CVE-2025-27743 | HIGH 7.8 | microsoft system_center_data_protection_manager Untrusted search path in System Center allows an authorized attacker to elevate privileges locally. | 0,9% | — |
| CVE-2024-30018 | HIGH 7.8 | microsoft windows_10_1809 Windows Kernel Elevation of Privilege Vulnerability | 0,9% | — |
| CVE-2022-3646 | LOW 3.1 | debian debian_linux A vulnerability, which was classified as problematic, has been found in Linux Kernel. This issue affects the function nilfs_attach_log_writer of the file fs/nilfs2/segment.c of the component BPF. The manipulation leads to memory leak. The attack may be initiat | 0,9% | — |
| CVE-2018-15331 | HIGH 7.8 | f5 big-ip_application_acceleration_manager On BIG-IP AAM 13.0.0 or 12.1.0-12.1.3.7, the dcdb_convert utility used by BIG-IP AAM fails to drop group permissions when executing helper scripts, which could be used to leverage attacks against the BIG-IP system. | 0,9% | — |
| CVE-2017-10611 | MED 6.5 | juniper junos If extended statistics are enabled via 'set chassis extended-statistics', when executing any operation that fetches interface statistics, including but not limited to SNMP GET requests, the pfem process or the FPC may crash and restart. Repeated crashes of PFE | 0,9% | — |
| CVE-2011-1821 | MED 4.0 | ibm tivoli_directory_server IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0010 on Windows allows remote authenticated users to cause a denial of service (daemon hang) via a cn=changelog search. | 0,9% | — |
| CVE-2024-39804 | HIGH 7.1 | microsoft powerpoint A library injection vulnerability exists in Microsoft PowerPoint 16.83 for macOS. A specially crafted library can leverage PowerPoint's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to t | 0,9% | — |
| CVE-2021-1483 | MED 6.4 | cisco catalyst_sd-wan_manager A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system. This vulnerability is due to improper handling of XML External | 0,9% | — |
| CVE-2024-21619 | MED 5.3 | juniper junos A Missing Authentication for Critical Function vulnerability combined with a Generation of Error Message Containing Sensitive Information vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an unauthenticated, network-based a | 0,9% | — |
| CVE-2023-33132 | MED 6.3 | microsoft sharepoint_server Microsoft SharePoint Server Spoofing Vulnerability | 0,9% | — |