56.580 CVE seguite
773 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.580 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2002-0026 | HIGH 7.5 | microsoft internet_explorer Internet Explorer 5.5 and 6.0 allows remote attackers to bypass restrictions for executing scripts via an object that processes asynchronous events after the initial security checks have been made. | 13,3% | — |
| CVE-2011-1275 | HIGH 9.3 | microsoft excel Microsoft Excel 2002 SP3; Office 2004, 2008, and 2011 for Mac; and Open XML File Format Converter for Mac do not properly validate record information during parsing of Excel spreadsheets, which allows remote attackers to execute arbitrary code or cause a denia | 13,3% | — |
| CVE-2011-1274 | HIGH 9.3 | microsoft excel Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 do not properly validate record inform | 13,3% | — |
| CVE-2013-4858 | MED 4.3 | microsoft windows_movie_maker Microsoft Windows Movie Maker 2.1.4026.0 on Windows XP SP3 allows remote attackers to cause a denial of service (application crash) via a crafted .wav file, as demonstrated by movieMaker.wav. | 13,3% | — |
| CVE-2013-7332 | MED 5.0 | microsoft windows_8 The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing | 13,3% | — |
| CVE-2002-0049 | MED 6.4 | microsoft exchange_server Microsoft Exchange Server 2000 System Attendant gives "Everyone" group privileges to the WinReg key, which could allow remote attackers to read or modify registry keys. | 13,3% | — |
| CVE-2006-5858 | MED 5.0 | adobe coldfusion Adobe ColdFusion MX 7 through 7.0.2, and JRun 4, when run on Microsoft IIS, allows remote attackers to read arbitrary files, list directories, or read source code via a double URL-encoded NULL byte in a ColdFusion filename, such as a CFM file. | 13,3% | — |
| CVE-2020-0970 | HIGH 7.5 | microsoft chakracore A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0968. | 13,3% | — |
| CVE-2020-0969 | HIGH 7.5 | microsoft chakracore A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based), aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. | 13,3% | — |
| CVE-2020-0827 | HIGH 7.5 | microsoft chakracore A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768, CVE-2020-0823, CVE-2020-0825, CVE-2020-082 | 13,3% | — |
| CVE-2020-0825 | HIGH 7.5 | microsoft chakracore A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768, CVE-2020-0823, CVE-2020-0826, CVE-2020-082 | 13,3% | — |
| CVE-2024-12284 | HIGH 8.8 | citrix netscaler_agent Authenticated privilege escalation in NetScaler Console and NetScaler Agent allows. | 13,3% | — |
| CVE-2009-2195 | HIGH 9.3 | apple safari Buffer overflow in WebKit in Apple Safari before 4.0.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted floating-point numbers. | 13,3% | — |
| CVE-2025-20284 | MED 6.5 | cisco identity_services_engine A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system as root. This vulnerability is due to insufficient validation of user-supplied input. | 13,3% | — |
| CVE-1999-0793 | LOW 2.6 | microsoft internet_explorer Internet Explorer allows remote attackers to read files by redirecting data to a Javascript applet. | 13,3% | — |
| CVE-1999-0487 | LOW 2.6 | microsoft internet_explorer The DHTML Edit ActiveX control in Internet Explorer allows remote attackers to read arbitrary files. | 13,3% | — |
| CVE-2011-1962 | MED 4.3 | microsoft internet_explorer Microsoft Internet Explorer 6 through 9 does not properly handle unspecified character sequences, which allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site that triggers "inactive filtering," aka "Shift JIS Ch | 13,3% | — |
| CVE-2007-4430 | MED 5.0 | cisco cbos Unspecified vulnerability in Cisco IOS 12.0 through 12.4 allows context-dependent attackers to cause a denial of service (device restart and BGP routing table rebuild) via certain regular expressions in a "show ip bgp regexp" command. NOTE: unauthenticated re | 13,3% | — |
| CVE-2025-0105 | CRIT 9.1 | paloaltonetworks expedition An arbitrary file deletion vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to delete arbitrary files accessible to the www-data user on the host filesystem. | 13,3% | — |
| CVE-2017-0271 | MED 5.9 | microsoft windows_10 Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way that Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, an | 13,3% | — |
| CVE-2015-0254 | HIGH 7.5 | apache standard_taglibs Apache Standard Taglibs before 1.2.3 allows remote attackers to execute arbitrary code or conduct external XML entity (XXE) attacks via a crafted XSLT extension in a (1) <x:parse> or (2) <x:transform> JSTL XML tag. | 13,3% | — |
| CVE-2014-3529 | MED 4.3 | apache poi The OPC SAX setup in Apache POI before 3.10.1 allows remote attackers to read arbitrary files via an OpenXML file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. | 13,3% | — |
| CVE-2020-0662 | HIGH 8.8 | microsoft windows_10 A remote code execution vulnerability exists in the way that Windows handles objects in memory, aka 'Windows Remote Code Execution Vulnerability'. | 13,3% | — |
| CVE-2016-8743 | HIGH 7.5 | apache http_server Apache HTTP Server, in all releases prior to 2.2.32 and 2.4.25, was liberal in the whitespace accepted from requests and sent in response lines and headers. Accepting these different behaviors represented a security concern when httpd participates in any chain | 13,3% | — |
| CVE-2013-4365 | HIGH 7.5 | apache mod_fcgid Heap-based buffer overflow in the fcgid_header_bucket_read function in fcgid_bucket.c in the mod_fcgid module before 2.3.9 for the Apache HTTP Server allows remote attackers to have an unspecified impact via unknown vectors. | 13,2% | — |