56.569 CVE seguite
773 Sfruttate ora
181 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.569 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2024-24576 | CRIT 10.0 | fedoraproject fedora Rust is a programming language. The Rust Security Response WG was notified that the Rust standard library prior to version 1.77.2 did not properly escape arguments when invoking batch files (with the `bat` and `cmd` extensions) on Windows using the `Command`. | 20,3% | — |
| CVE-2021-41355 | MED 5.7 | microsoft .net .NET Core and Visual Studio Information Disclosure Vulnerability | 20,3% | — |
| CVE-2017-8725 | HIGH 7.8 | microsoft publisher A remote code execution vulnerability exists in Microsoft Publisher 2007 Service Pack 3 and Microsoft Publisher 2010 Service Pack 2 when they fail to properly handle objects in memory, aka "Microsoft Office Publisher Remote Code Execution". | 20,3% | — |
| CVE-2017-8567 | HIGH 7.8 | microsoft excel_for_mac A remote code execution vulnerability exists in Microsoft Excel for Mac 2011 when it fails to properly handle objects in memory, aka "Microsoft Office Remote Code Execution". | 20,3% | — |
| CVE-2010-1881 | HIGH 9.3 | microsoft access The FieldList ActiveX control in the Microsoft Access Wizard Controls in ACCWIZ.dll in Microsoft Office Access 2003 SP3 does not properly interact with the memory-access approach used by Internet Explorer and Office during instantiation, which allows remote at | 20,3% | — |
| CVE-2005-0551 | HIGH 10.0 | microsoft windows_2000 Stack-based buffer overflow in WINSRV.DLL in the Client Server Runtime System (CSRSS) process of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application that provides co | 20,3% | — |
| CVE-2010-0816 | HIGH 9.3 | microsoft outlook_express Integer overflow in inetcomm.dll in Microsoft Outlook Express 5.5 SP2, 6, and 6 SP1; Windows Live Mail on Windows XP SP2 and SP3, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7; and Windows Mail on Windows Vista SP1 and SP2, Wi | 20,3% | — |
| CVE-2022-22951 | CRIT 9.1 | vmware carbon_black_app_control VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains an OS command injection vulnerability. An authenticated, high privileged malicious actor with network access to the VMware App | 20,3% | — |
| CVE-2014-0230 | HIGH 7.8 | apache tomcat Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle cases where an HTTP response occurs before finishing the reading of an entire request body, which allows remote attackers to cause a denial of service (thread con | 20,3% | — |
| CVE-2014-6331 | MED 5.0 | microsoft active_directory_federation_services Microsoft Active Directory Federation Services (AD FS) 2.0, 2.1, and 3.0, when a configured SAML Relying Party lacks a sign-out endpoint, does not properly process logoff actions, which makes it easier for remote attackers to obtain access by leveraging an una | 20,3% | — |
| CVE-2024-38200 | MED 6.5 | microsoft 365_apps Microsoft Office Spoofing Vulnerability | 20,3% | — |
| CVE-2012-0020 | HIGH 9.3 | microsoft visio_viewer Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitrary code via crafted attributes in a Visio file, aka "VSD File Format Memory Corruption Vulnerability," a diffe | 20,3% | — |
| CVE-2012-0019 | HIGH 9.3 | microsoft visio_viewer Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitrary code via crafted attributes in a Visio file, aka "VSD File Format Memory Corruption Vulnerability," a diffe | 20,3% | — |
| CVE-2010-1879 | HIGH 9.3 | microsoft directx Unspecified vulnerability in Quartz.dll for DirectShow; Windows Media Format Runtime 9, 9.5, and 11; Media Encoder 9; and the Asycfilt.dll COM component allows remote attackers to execute arbitrary code via a media file with crafted compression data, aka "Medi | 20,3% | — |
| CVE-2010-3234 | HIGH 9.3 | microsoft excel Microsoft Excel 2002 SP3 does not properly validate formula information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Formula Substream Memory Corruption Vulnerability." | 20,3% | — |
| CVE-2010-3231 | HIGH 9.3 | microsoft excel Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Excel Record Parsing Memo | 20,3% | — |
| CVE-2020-1439 | HIGH 8.8 | microsoft sharepoint_enterprise_server A remote code execution vulnerability exists in PerformancePoint Services for SharePoint Server when the software fails to check the source markup of XML file input, aka 'PerformancePoint Services Remote Code Execution Vulnerability'. | 20,3% | — |
| CVE-2014-1815 | HIGH 9.3 | microsoft internet_explorer Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, as exploited in the wild in May 2014, aka "Internet Explorer Memory Corruption Vulnerability," a | 20,3% | — |
| CVE-2006-5544 | MED 6.4 | microsoft ie Visual truncation vulnerability in Microsoft Internet Explorer 7 allows remote attackers to spoof the address bar and possibly conduct phishing attacks via a malicious URL containing non-breaking spaces (%A0), which causes the address bar to omit some characte | 20,3% | — |
| CVE-2002-0698 | HIGH 7.5 | microsoft exchange_server Buffer overflow in Internet Mail Connector (IMC) for Microsoft Exchange Server 5.5 allows remote attackers to execute arbitrary code via an EHLO request from a system with a long name as obtained through a reverse DNS lookup, which triggers the overflow in IMC | 20,3% | — |
| CVE-2026-45502 | MED 5.0 | microsoft exchange_server Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network. | 20,3% | — |
| CVE-2015-2542 | HIGH 9.3 | microsoft edge Microsoft Internet Explorer 10 and 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability." | 20,2% | — |
| CVE-2015-2494 | HIGH 9.3 | microsoft edge Microsoft Internet Explorer 7 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015 | 20,2% | — |
| CVE-2015-2486 | HIGH 9.3 | microsoft edge Microsoft Internet Explorer 7 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015 | 20,2% | — |
| CVE-2015-2372 | HIGH 9.3 | microsoft vbscript vbscript.dll in Microsoft VBScript 5.6 through 5.8, as used with Internet Explorer 6 through 11 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "VBScript Memory | 20,2% | — |