58.535 CVE seguite
797 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.535 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2018-8397 | HIGH 8.8 | microsoft windows_7 A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka "GDI+ Remote Code Execution Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2. | 67,9% | — |
| CVE-2018-0775 | HIGH 7.5 | microsoft chakracore Microsoft Edge in Windows 10 1709 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE | 67,9% | — |
| CVE-2018-0774 | HIGH 7.5 | microsoft chakracore Microsoft Edge in Windows 10 1709 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE | 67,9% | — |
| CVE-2013-4547 | HIGH 7.5 | f5 nginx nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to bypass intended restrictions via an unescaped space character in a URI. | 67,7% | — |
| CVE-2018-8353 | HIGH 7.5 | microsoft internet_explorer A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer | 67,7% | — |
| CVE-2005-0803 | MED 5.0 | microsoft windows_2000 The GetEnhMetaFilePaletteEntries API in GDI32.DLL in Windows 2000 allows remote attackers to cause a denial of service (application crash) via a crafted Enhanced Metafile (EMF) file that causes invalid (1) end, (2) emreof, or (3) palent offsets to be used, aka | 67,7% | — |
| CVE-2010-3970 | HIGH 9.3 | microsoft windows_server_2003 Stack-based buffer overflow in the CreateSizedDIBSECTION function in shimgvw.dll in the Windows Shell graphics processor (aka graphics rendering engine) in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2 allow | 67,7% | — |
| CVE-2012-1447 | MED 4.3 | aladdin esafe The ELF file parser in Fortinet Antivirus 4.2.254.0, eSafe 7.0.17.0, Dr.Web 5.0.2.03300, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified e_version field. NOTE: this may later be SPLIT into multi | 67,7% | — |
| CVE-2025-30676 | MED 6.1 | apache ofbiz Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.19. Users are recommended to upgrade to version 18.12.19, which fixes the issue. | 67,6% | — |
| CVE-2017-8548 | HIGH 7.5 | microsoft edge Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to obtain information to further compromise the user's system when Microsoft Edge improperly handles objects in memory, aka "Scripting Engine Memory C | 67,6% | — |
| CVE-2020-0610 | CRIT 9.8 | microsoft windows_server_2012 A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Gateway (RD Gateway) Remote C | 67,6% | — |
| CVE-2023-3765 | CRIT 10.0 | lfprojects mlflow Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.5.0. | 67,5% | — |
| CVE-2022-41034 | HIGH 7.8 | microsoft visual_studio_code Visual Studio Code Remote Code Execution Vulnerability | 67,5% | — |
| CVE-2023-24950 | MED 6.5 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability | 67,5% | — |
| CVE-2006-2086 | HIGH 7.5 | juniper junipersetup_control Buffer overflow in JuniperSetupDLL.dll, loaded from JuniperSetup.ocx by the Juniper SSL-VPN Client when accessing a Juniper NetScreen IVE device running IVE OS before 4.2r8.1, 5.0 before 5.0r6.1, 5.1 before 5.1r8, 5.2 before 5.2r4.1, or 5.3 before 5.3r2.1, all | 67,3% | — |
| CVE-2010-1681 | HIGH 7.6 | microsoft visio Buffer overflow in VISIODWG.DLL before 10.0.6880.4 in Microsoft Office Visio allows user-assisted remote attackers to execute arbitrary code via a crafted DXF file, a different vulnerability than CVE-2010-0254 and CVE-2010-0256. | 67,3% | — |
| CVE-2022-25813 | HIGH 7.5 | apache ofbiz In Apache OFBiz, versions 18.12.05 and earlier, an attacker acting as an anonymous user of the ecommerce plugin, can insert a malicious content in a message “Subject” field from the "Contact us" page. Then a party manager needs to list the communications in th | 67,3% | — |
| CVE-2023-36606 | HIGH 7.5 | microsoft windows_10 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | 67,2% | — |
| CVE-2023-34039 | CRIT 9.8 | vmware aria_operations_for_networks Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key generation. A malicious actor with network access to Aria Operations for Networks could bypass SSH authentication to gain access to the Aria | 67,2% | — |
| CVE-2018-8145 | HIGH 7.5 | microsoft chakracore An information disclosure vulnerability exists when Chakra improperly discloses the contents of its memory, which could provide an attacker with information to further compromise the user's computer or data, aka "Chakra Scripting Engine Memory Corruption Vulne | 67,2% | — |
| CVE-2004-1050 | HIGH 10.0 | avaya definity_one_media_server Heap-based buffer overflow in Internet Explorer 6 allows remote attackers to execute arbitrary code via long (1) SRC or (2) NAME attributes in IFRAME, FRAME, and EMBED elements, as originally discovered using the mangleme utility, aka "the IFRAME vulnerability | 67,1% | — |
| CVE-2009-0133 | HIGH 10.0 | microsoft html_help_workshop Buffer overflow in Microsoft HTML Help Workshop 4.74 and earlier allows context-dependent attackers to execute arbitrary code via a .hhp file with a long "Index file" field, possibly a related issue to CVE-2006-0564. | 67,0% | — |
| CVE-2019-0618 | HIGH 8.8 | microsoft windows_10 A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0662. | 67,0% | — |
| CVE-2006-1016 | HIGH 7.5 | microsoft internet_explorer Buffer overflow in the IsComponentInstalled method in Internet Explorer 6.0, when used on Windows 2000 before SP4 or Windows XP before SP1, allows remote attackers to execute arbitrary code via JavaScript that calls IsComponentInstalled with a long first argum | 67,0% | — |
| CVE-2016-7237 | MED 6.5 | microsoft windows_10 Local Security Authority Subsystem Service (LSASS) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows | 66,9% | — |