58.535 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.535 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2015-2509 | HIGH 9.3 | microsoft windows_7 Windows Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8, and Windows 8.1 allows user-assisted remote attackers to execute arbitrary code via a crafted Media Center link (mcl) file, aka "Windows Media Center RCE Vulnerability." | 71,0% | — |
| CVE-2018-8229 | HIGH 7.5 | microsoft chakracore A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique | 71,0% | — |
| CVE-2019-0887 | HIGH 8.0 | microsoft remote_desktop_client A remote code execution vulnerability exists in Remote Desktop Services - formerly known as Terminal Services - when an authenticated attacker abuses clipboard redirection, aka 'Remote Desktop Services Remote Code Execution Vulnerability'. | 71,0% | — |
| CVE-2015-0096 | HIGH 9.3 | microsoft windows_7 Untrusted search path vulnerability in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain priv | 71,0% | — |
| CVE-1999-0513 | MED 5.0 | digital unix ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service. | 70,9% | — |
| CVE-2019-5620 | CRIT 9.8 | hitachienergy microscada_pro_sys600 ABB MicroSCADA Pro SYS600 version 9.3 suffers from an instance of CWE-306: Missing Authentication for Critical Function. | 70,9% | — |
| CVE-2018-8279 | HIGH 7.5 | microsoft chakracore A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8125, CVE-2018-8262, CVE- | 70,7% | — |
| CVE-2014-1762 | HIGH 7.5 | microsoft internet_explorer Unspecified vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code with medium-integrity privileges and bypass a sandbox protection mechanism via unknown vectors, as demonstrated by ZDI during a Pwn4Fun comp | 70,7% | — |
| CVE-2020-17143 | HIGH 8.8 | microsoft exchange_server Microsoft Exchange Server Information Disclosure Vulnerability | 70,6% | — |
| CVE-2023-43622 | HIGH 7.5 | apache http_server An attacker, opening a HTTP/2 connection with an initial window size of 0, was able to block handling of that connection indefinitely in Apache HTTP Server. This could be used to exhaust worker resources in the server, similar to the well known "slow loris" at | 70,6% | — |
| CVE-2024-38063 | CRIT 9.8 | microsoft windows_10_1507 Windows TCP/IP Remote Code Execution Vulnerability | 70,6% | — |
| CVE-2007-6750 | MED 5.0 | apache http_server The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris, related to the lack of the mod_reqtimeout module in versions before 2.2.15. | 70,5% | — |
| CVE-2001-1243 | MED 5.0 | microsoft internet_information_server Scripting.FileSystemObject in asp.dll for Microsoft IIS 4.0 and 5.0 allows local or remote attackers to cause a denial of service (crash) via (1) creating an ASP program that uses Scripting.FileSystemObject to open a file with an MS-DOS device name, or (2) rem | 70,5% | — |
| CVE-2015-0336 | HIGH 9.3 | adobe flash_player Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than CVE-2015- | 70,4% | — |
| CVE-2023-20864 | CRIT 9.8 | vmware aria_operations_for_logs VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with network access to VMware Aria Operations for Logs may be able to execute arbitrary code as root. | 70,4% | — |
| CVE-2016-7288 | HIGH 7.5 | microsoft edge The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-72 | 70,4% | — |
| CVE-2022-23270 | HIGH 8.1 | microsoft windows_10 Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | 70,3% | — |
| CVE-2005-0045 | HIGH 7.5 | microsoft windows_2000 The Server Message Block (SMB) implementation for Windows NT 4.0, 2000, XP, and Server 2003 does not properly validate certain SMB packets, which allows remote attackers to execute arbitrary code via Transaction responses containing (1) Trans or (2) Trans2 com | 70,3% | — |
| CVE-2017-8634 | HIGH 7.5 | microsoft edge Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render content when handling objects in memory, aka "Scripting Engine Memory Co | 70,3% | — |
| CVE-2006-1185 | HIGH 7.5 | canon network_camera_server_vb101 Unspecified vulnerability in Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via certain invalid HTML that causes memory corruption. | 70,3% | — |
| CVE-2019-1184 | MED 6.7 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows Core Shell COM Server Registrar improperly handles COM calls. An attacker who successfully exploited this vulnerability could potentially set certain items to run at a higher level and thereby elevate | 70,2% | — |
| CVE-2013-2134 | HIGH 9.3 | apache struts Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted action name that is not properly handled during wildcard matching, a different vulnerability than CVE-2013-2135. | 70,2% | — |
| CVE-2011-0105 | HIGH 9.3 | microsoft excel Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac obtain a certain length value from an uninitialized memory location, which allows remote attackers to trigger a buffer overflow and execute arbitrary code via a | 70,2% | — |
| CVE-2006-2370 | HIGH 7.5 | microsoft windows_2000 Buffer overflow in the Routing and Remote Access service (RRAS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote unauthenticated or authenticated attackers to execute arbitrary code via certain crafted "RPC related r | 70,1% | — |
| CVE-2024-53677 | CRIT 9.8 | apache struts File upload logic in Apache Struts is flawed. An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution. This issue affec | 70,1% | — |