56.706 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.706 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2021-38656 | HIGH 7.8 | microsoft 365_apps Microsoft Word Remote Code Execution Vulnerability | 6,7% | — |
| CVE-2007-3954 | MED 4.3 | microsoft internet_explorer Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with SeaMonkey installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metachara | 6,7% | — |
| CVE-2017-8531 | MED 6.5 | microsoft office Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, Windows Server 2016, Microsoft Office 2007 Service Pack 3, and Microsoft Office 2010 Service Pack 2 | 6,7% | — |
| CVE-2017-0170 | MED 6.5 | microsoft windows_10 Windows Performance Monitor in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an information disclosure vulnerability due to the | 6,7% | — |
| CVE-2018-0800 | MED 5.3 | microsoft chakracore Microsoft Edge in Microsoft Windows 10 1709 allows an attacker to obtain information to further compromise the user's system, due to how the scripting engine handles objects in memory, aka "Scripting Engine Information Disclosure Vulnerability". This CVE ID is | 6,7% | — |
| CVE-2007-1917 | HIGH 10.0 | sap rfc_library Buffer overflow in the SYSTEM_CREATE_INSTANCE function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: This information is based upon a vague initial disclosure. Details wil | 6,7% | — |
| CVE-2007-1916 | HIGH 10.0 | sap rfc_library Buffer overflow in the RFC_START_GUI function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: This information is based upon a vague initial disclosure. Details will be upda | 6,7% | — |
| CVE-2016-6432 | HIGH 8.1 | cisco adaptive_security_appliance_software A vulnerability in the Identity Firewall feature of Cisco ASA Software before 9.6(2.1) could allow an unauthenticated, remote attacker to cause a reload of the affected system or to remotely execute code. The vulnerability is due to a buffer overflow in the af | 6,7% | — |
| CVE-2007-0451 | MED 4.3 | apache spamassassin Apache SpamAssassin before 3.1.8 allows remote attackers to cause a denial of service via long URLs in malformed HTML, which triggers "massive memory usage." | 6,7% | — |
| CVE-2019-17133 | CRIT 9.8 | canonical ubuntu_linux In the Linux kernel through 5.3.2, cfg80211_mgd_wext_giwessid in net/wireless/wext-sme.c does not reject a long SSID IE, leading to a Buffer Overflow. | 6,7% | — |
| CVE-2014-0560 | HIGH 10.0 | adobe acrobat Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.12 and 11.x before 11.0.09 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors. | 6,7% | — |
| CVE-2020-11988 | HIGH 8.2 | apache xmlgraphics_commons Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to | 6,7% | — |
| CVE-2024-26170 | HIGH 7.8 | microsoft windows_10_21h2 Windows Composite Image File System (CimFS) Elevation of Privilege Vulnerability | 6,6% | — |
| CVE-2024-30280 | HIGH 7.8 | adobe acrobat Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerab | 6,6% | — |
| CVE-2015-0225 | HIGH 7.5 | apache cassandra The default configuration in Apache Cassandra 1.2.0 through 1.2.19, 2.0.0 through 2.0.13, and 2.1.0 through 2.1.3 binds an unauthenticated JMX/RMI interface to all network interfaces, which allows remote attackers to execute arbitrary Java code via an RMI requ | 6,6% | — |
| CVE-2014-2421 | HIGH 10.0 | canonical ubuntu_linux Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JavaFX 2.2.51; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. | 6,6% | — |
| CVE-2014-0456 | HIGH 10.0 | canonical ubuntu_linux Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot. | 6,6% | — |
| CVE-2020-17141 | HIGH 8.4 | microsoft exchange_server Microsoft Exchange Remote Code Execution Vulnerability | 6,6% | — |
| CVE-2016-1985 | CRIT 10.0 | hp operations_manager HPE Operations Manager 8.x and 9.0 on Windows allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library. | 6,6% | — |
| CVE-2011-5063 | MED 4.3 | apache tomcat The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check realm values, which might allow remote attackers to bypass intended access restrictions by leveraging the availab | 6,6% | — |
| CVE-2018-8340 | MED 6.5 | microsoft windows_server_2012 A security feature bypass vulnerability exists when Active Directory Federation Services (AD FS) improperly handles multi-factor authentication requests, aka "AD FS Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows Server 2012 R | 6,6% | — |
| CVE-2010-1689 | MED 6.4 | microsoft exchange_server The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier, Windows XP SP3 and earlier, Windows Server 2003 SP2 and earlier, Windows Server 2008 SP2 and earlier, Windows Server 2008 R2, Exchange Server 2003 SP3 and ear | 6,6% | — |
| CVE-2010-4395 | HIGH 9.3 | realnetworks realplayer Heap-based buffer overflow in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.5, and Linux RealPlayer 11.0.2.1744 allows remote attackers to execute arbitrary code via a crafted conditional component in AAC frame data. | 6,6% | — |
| CVE-2010-4389 | HIGH 9.3 | realnetworks realplayer Heap-based buffer overflow in the cook codec in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.5, and Linux RealPlayer 11.0.2.1744 allows remote attackers to execute arbitrary code via unspecified data in the initialization buffer. | 6,6% | — |
| CVE-2025-12428 | HIGH 8.8 | google chrome Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High) | 6,6% | — |