58.507 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.507 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2019-0604 | CRIT 9.8 | ransomware microsoft sharepoint_enterprise_server A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0594. | 99,9% | |
| CVE-2018-0296 | HIGH 7.5 | cisco adaptive_security_appliance_software A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. It is also possible on cer | 99,9% | |
| CVE-2021-22986 | CRIT 9.8 | ransomware f5 big-ip_access_policy_manager On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2, the iControl REST interface has an unauthenticated remote | 99,9% | |
| CVE-2023-46604 | CRIT 10.0 | ransomware apache activemq The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary shell commands by manipulating serialized clas | 99,9% | |
| CVE-2014-0497 | CRIT 9.8 | adobe flash_player Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors. | 99,9% | |
| CVE-2021-27065 | HIGH 7.8 | ransomware microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 99,9% | |
| CVE-2019-1653 | HIGH 7.5 | cisco rv320_firmware A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to retrieve sensitive information. The vulnerability is due to improper access controls f | 99,9% | |
| CVE-2021-31166 | CRIT 9.8 | microsoft windows_10_2004 HTTP Protocol Stack Remote Code Execution Vulnerability | 99,9% | |
| CVE-2021-21972 | CRIT 9.8 | ransomware vmware cloud_foundation The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system t | 99,9% | |
| CVE-2024-0012 | CRIT 9.8 | ransomware paloaltonetworks pan-os An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or | 99,8% | |
| CVE-2017-7269 | CRIT 9.8 | microsoft internet_information_services Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to execute arbitrary code via a long header beginning with "If: <http://" in a PRO | 99,8% | |
| CVE-2020-0796 | CRIT 10.0 | ransomware microsoft windows_10_1903 A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'. | 99,8% | |
| CVE-2021-34527 | HIGH 8.8 | ransomware microsoft windows_10_1507 A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could the | 99,8% | |
| CVE-2021-31207 | MED 6.6 | ransomware microsoft exchange_server Microsoft Exchange Server Security Feature Bypass Vulnerability | 99,8% | |
| CVE-2020-13927 | CRIT 9.8 | apache airflow The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to users who miss this fact. From Airflow 1.10.11 the default has been changed to deny all requests by default and i | 99,8% | |
| CVE-2025-25257 | CRIT 9.8 | fortinet fortiweb An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.7, FortiWeb 7.2.0 through 7.2.10, FortiWeb 7.0.0 through 7.0.10 al | 99,8% | |
| CVE-2023-3519 | CRIT 9.8 | ransomware citrix netscaler_application_delivery_controller Unauthenticated remote code execution | 99,7% | |
| CVE-2017-0147 | HIGH 7.5 | ransomware microsoft windows_10_1507 The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to obtain sen | 99,7% | |
| CVE-2021-22054 | HIGH 7.5 | vmware workspace_one_uem_console VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 contain an SSRF vulnerability. This issue may allow a malicious actor with network access to UEM to send their req | 99,7% | |
| CVE-2017-12615 | HIGH 8.1 | ransomware apache tomcat When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could the | 99,6% | |
| CVE-2022-22965 | CRIT 9.8 | cisco cx_cloud_agent A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot | 99,6% | |
| CVE-2024-9465 | CRIT 9.1 | paloaltonetworks expedition An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and | 99,6% | |
| CVE-2023-20198 | CRIT 10.0 | cisco ios_xe Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating the list of fixed releases and adding the Software Checker. Our investigation has determined that the actors e | 99,6% | |
| CVE-2017-0199 | HIGH 7.8 | ransomware microsoft office Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, Windows 8.1 allow remote attackers to execute arbitrary code via a crafted document, ak | 99,5% | |
| CVE-2018-0171 | CRIT 9.8 | cisco ios A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition, or to execute arbitrary co | 99,5% |