58.507 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.507 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2024-37079 | CRIT 9.8 | vmware cloud_foundation vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remo | 22,4% | |
| CVE-2017-0210 | HIGH 8.8 | microsoft internet_explorer An elevation of privilege vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain, aka "Internet Explorer Elevation of Pr | 22,3% | |
| CVE-2014-0546 | CRIT 9.8 | adobe acrobat Adobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows allow attackers to bypass a sandbox protection mechanism, and consequently execute native code in a privileged context, via unspecified vectors. | 22,3% | |
| CVE-2025-14174 | HIGH 8.8 | apple ipados Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) | 22,3% | |
| CVE-2016-1019 | CRIT 9.8 | ransomware adobe air_desktop_runtime Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, as exploited in the wild in April 2016. | 22,3% | |
| CVE-2021-31956 | HIGH 7.8 | microsoft windows_10_1507 Windows NTFS Elevation of Privilege Vulnerability | 22,3% | |
| CVE-2018-8639 | HIGH 7.8 | ransomware microsoft windows_10_1507 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 20 | 22,2% | |
| CVE-2016-0162 | MED 4.3 | microsoft internet_explorer Microsoft Internet Explorer 9 through 11 allows remote attackers to determine the existence of files via crafted JavaScript code, aka "Internet Explorer Information Disclosure Vulnerability." | 22,0% | |
| CVE-2021-34484 | HIGH 7.8 | microsoft windows_10_1507 Windows User Profile Service Elevation of Privilege Vulnerability | 21,8% | |
| CVE-2019-1297 | HIGH 8.8 | microsoft excel A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. | 21,8% | |
| CVE-2019-0903 | HIGH 8.8 | microsoft windows_10_1507 A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'. | 21,7% | |
| CVE-2023-29360 | HIGH 8.4 | microsoft windows_10_1607 Microsoft Streaming Service Elevation of Privilege Vulnerability | 21,6% | |
| CVE-2017-6742 | HIGH 8.8 | cisco ios A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute code. An attacker could exploit this vulnerability by sending a crafted SNMP packet to the affected devi | 21,4% | |
| CVE-2024-7971 | CRIT 9.6 | google chrome Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 21,1% | |
| CVE-2012-1854 | HIGH 7.8 | microsoft office Untrusted search path vulnerability in VBE6.dll in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Microsoft Visual Basic for Applications (VBA); and Summit Microsoft Visual Basic for Applications SDK allows local users to gain privileges v | 21,0% | |
| CVE-2014-9163 | HIGH 7.8 | adobe flash_player Stack-based buffer overflow in Adobe Flash Player before 13.0.0.259 and 14.x and 15.x before 15.0.0.246 on Windows and OS X and before 11.2.202.425 on Linux allows attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in Decembe | 20,7% | |
| CVE-2023-36563 | MED 6.5 | microsoft windows_10_1507 Microsoft WordPad Information Disclosure Vulnerability | 20,7% | |
| CVE-2016-3309 | HIGH 7.8 | ransomware microsoft windows_10_1507 The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted appl | 20,5% | |
| CVE-2014-8439 | HIGH 8.8 | adobe air Adobe Flash Player before 13.0.0.258 and 14.x and 15.x before 15.0.0.239 on Windows and OS X and before 11.2.202.424 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allow attackers to execu | 20,4% | |
| CVE-2016-4171 | CRIT 9.8 | adobe flash_player Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in June 2016. | 20,1% | |
| CVE-2025-7775 | CRIT 9.8 | citrix netscaler_application_delivery_controller Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server (OR) NetScaler ADC a | 19,6% | |
| CVE-2023-36761 | MED 6.5 | microsoft 365_apps Microsoft Word Information Disclosure Vulnerability | 19,6% | |
| CVE-2021-41379 | MED 5.5 | ransomware microsoft windows_10_1507 Windows Installer Elevation of Privilege Vulnerability | 19,5% | |
| CVE-2024-20359 | MED 6.0 | cisco adaptive_security_appliance_software A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, l | 19,4% | |
| CVE-2016-1010 | HIGH 8.8 | adobe air Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 | 19,3% |