56.807 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.807 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2020-9749 | HIGH 7.8 | adobe animate Adobe Animate version 20.5 (and earlier) is affected by an out-of-bounds read vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted .fla file | 4,1% | — |
| CVE-2020-9747 | HIGH 7.8 | adobe animate Adobe Animate version 20.5 (and earlier) is affected by a double free vulnerability when parsing a crafted .fla file, which could result in arbitrary code execution in the context of the current user. This vulnerability requires user interaction to exploit. | 4,1% | — |
| CVE-2019-19044 | HIGH 7.5 | broadcom brocade_fabric_operating_system_firmware Two memory leaks in the v3d_submit_cl_ioctl() function in drivers/gpu/drm/v3d/v3d_gem.c in the Linux kernel before 5.3.11 allow attackers to cause a denial of service (memory consumption) by triggering kcalloc() or v3d_job_init() failures, aka CID-29cd13cfd762 | 4,1% | — |
| CVE-2019-1255 | HIGH 7.5 | microsoft forefront_endpoint_protection_2010 A denial of service vulnerability exists when Microsoft Defender improperly handles files, aka 'Microsoft Defender Denial of Service Vulnerability'. | 4,1% | — |
| CVE-2013-4350 | MED 5.0 | linux linux_kernel The IPv6 SCTP implementation in net/sctp/ipv6.c in the Linux kernel through 3.11.1 uses data structures and function calls that do not trigger an intended configuration of IPsec encryption, which allows remote attackers to obtain sensitive information by sniff | 4,1% | — |
| CVE-2026-20871 | HIGH 7.8 | microsoft windows_10_21h2 Use after free in Desktop Windows Manager allows an authorized attacker to elevate privileges locally. | 4,1% | — |
| CVE-2016-7216 | MED 5.5 | microsoft windows_7 The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 mishandles permissions, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Elevation of Privilege Vulnerability." | 4,1% | — |
| CVE-2008-1451 | HIGH 7.2 | microsoft windows_2000 The WINS service on Microsoft Windows 2000 SP4, and Server 2003 SP1 and SP2, does not properly validate data structures in WINS network packets, which allows local users to gain privileges via a crafted packet, aka "Memory Overwrite Vulnerability." | 4,1% | — |
| CVE-2018-6809 | CRIT 9.8 | citrix netscaler_application_delivery_controller_firmware NetScaler ADC 10.5, 11.0, 11.1, and 12.0, and NetScaler Gateway 10.5, 11.0, 11.1, and 12.0 allow remote attackers to gain privilege on a target system. | 4,1% | — |
| CVE-2021-30610 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30610 Use after free in Extensions API | 4,1% | — |
| CVE-2020-1192 | HIGH 7.8 | microsoft python A remote code execution vulnerability exists in Visual Studio Code when the Python extension loads workspace settings from a notebook file. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If | 4,1% | — |
| CVE-2018-0231 | HIGH 8.6 | cisco adaptive_security_appliance_software A vulnerability in the Transport Layer Security (TLS) library of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of the affected device, resu | 4,1% | — |
| CVE-2003-0664 | HIGH 7.5 | microsoft word Microsoft Word 2002, 2000, 97, and 98(J) does not properly check certain properties of a document, which allows attackers to bypass the macro security model and automatically execute arbitrary macros via a malicious document. | 4,1% | — |
| CVE-2018-16045 | HIGH 8.8 | adobe acrobat_dc Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have a secu | 4,1% | — |
| CVE-2017-8474 | MED 5.0 | microsoft windows_10 The kernel in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a specially c | 4,1% | — |
| CVE-2019-8013 | HIGH 8.8 | adobe acrobat_dc Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an use after free vulnerability. Successful exploi | 4,1% | — |
| CVE-2020-17066 | HIGH 7.8 | microsoft excel Microsoft Excel Remote Code Execution Vulnerability | 4,1% | — |
| CVE-2020-17065 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 4,1% | — |
| CVE-2020-17062 | HIGH 7.8 | microsoft 365_apps Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability | 4,1% | — |
| CVE-2018-0895 | MED 4.7 | microsoft windows_10 The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information discl | 4,1% | — |
| CVE-2022-34728 | MED 5.5 | microsoft windows_10 Windows Graphics Component Information Disclosure Vulnerability | 4,1% | — |
| CVE-2019-12806 | HIGH 8.8 | crosscert unisign UniSign 2.0.4.0 and earlier version contains a stack-based buffer overflow vulnerability which can overwrite the stack with arbitrary data, due to a buffer overflow in a library. That leads remote attacker to execute arbitrary code via crafted https packets. | 4,1% | — |
| CVE-2003-0232 | HIGH 7.2 | microsoft data_engine Microsoft SQL Server 7, 2000, and MSDE allows local users to execute arbitrary code via a certain request to the Local Procedure Calls (LPC) port that leads to a buffer overflow. | 4,1% | — |
| CVE-2021-30624 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30624 Use after free in Autofill | 4,1% | — |
| CVE-2021-30620 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30620 Insufficient policy enforcement in Blink | 4,1% | — |