57.056 CVE seguite
777 Sfruttate ora
184 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.056 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2021-1586 | HIGH 8.6 | cisco nx-os A vulnerability in the Multi-Pod or Multi-Site network configurations for Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, remote attacker to unexpectedly restart the device, resulting in | 2,5% | — |
| CVE-2019-12629 | HIGH 7.2 | cisco sd-wan_firmware A vulnerability in the WebUI of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject and execute arbitrary commands with vmanage user privileges on an affected system. The vulnerability is due to insufficient input validation of da | 2,5% | — |
| CVE-2004-1322 | HIGH 7.5 | cisco unity_server Cisco Unity 2.x, 3.x, and 4.x, when integrated with Microsoft Exchange, has several hard coded usernames and passwords, which allows remote attackers to gain unauthorized access and change configuration settings or read outgoing or incoming e-mail messages. | 2,5% | — |
| CVE-2021-27055 | HIGH 7.0 | microsoft 365_apps Microsoft Visio Security Feature Bypass Vulnerability | 2,5% | — |
| CVE-2012-5424 | MED 5.0 | cisco secure_access_control_server Cisco Secure Access Control System (ACS) 5.x before 5.2 Patch 11 and 5.3 before 5.3 Patch 7, when a certain configuration involving TACACS+ and LDAP is used, does not properly validate passwords, which allows remote attackers to bypass authentication by sendin | 2,5% | — |
| CVE-2008-1181 | MED 5.0 | juniper secure_access_2000 Juniper Networks Secure Access 2000 5.5 R1 (build 11711) allows remote attackers to obtain sensitive information via a direct request for remediate.cgi without certain parameters, which reveals the path in an "Execute failed" error message. | 2,5% | — |
| CVE-2005-4849 | MED 5.0 | apache derby Apache Derby before 10.1.2.1 exposes the (1) user and (2) password attributes in cleartext via (a) the RDBNAM parameter of the ACCSEC command and (b) the output of the DatabaseMetaData.getURL function, which allows context-dependent attackers to obtain sensiti | 2,5% | — |
| CVE-2021-36016 | LOW 3.3 | adobe media_encoder Adobe Media Encoder version 15.2 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to read arbitrary file system information in the context of t | 2,5% | — |
| CVE-2021-34489 | HIGH 7.8 | microsoft windows_10 DirectWrite Remote Code Execution Vulnerability | 2,5% | — |
| CVE-2009-1168 | HIGH 7.1 | cisco ios Cisco IOS 12.0(32)S12 through 12.0(32)S13 and 12.0(33)S3 through 12.0(33)S4, 12.0(32)SY8 through 12.0(32)SY9, 12.2(33)SXI1, 12.2XNC before 12.2(33)XNC2, 12.2XND before 12.2(33)XND1, and 12.4(24)T1; and IOS XE 2.3 through 2.3.1t and 2.4 through 2.4.0; when RFC4 | 2,5% | — |
| CVE-2022-26901 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 2,4% | — |
| CVE-2021-26900 | HIGH 7.8 | microsoft windows_10 Windows Win32k Elevation of Privilege Vulnerability | 2,4% | — |
| CVE-2024-43521 | HIGH 7.5 | microsoft windows_server_2012 Windows Hyper-V Denial of Service Vulnerability | 2,4% | — |
| CVE-2021-34492 | HIGH 8.1 | microsoft windows_10 Windows Certificate Spoofing Vulnerability | 2,4% | — |
| CVE-2017-7687 | HIGH 7.5 | apache mesos When handling a decoding failure for a malformed URL path of an HTTP request, libprocess in Apache Mesos before 1.1.3, 1.2.x before 1.2.2, 1.3.x before 1.3.1, and 1.4.0-dev might crash because the code accidentally calls inappropriate function. A malicious act | 2,4% | — |
| CVE-2007-3756 | MED 4.3 | apple safari Safari in Apple iPhone 1.1.1, and Safari 3 before Beta Update 3.0.4 on Windows and Mac OS X 10.4 through 10.4.10, allows remote attackers to obtain sensitive information via a crafted web page that identifies the URL of the parent window, even when the parent | 2,4% | — |
| CVE-2021-32567 | HIGH 7.5 | apache traffic_server Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1. | 2,4% | — |
| CVE-2020-24427 | LOW 3.3 | adobe acrobat Acrobat Reader versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) are affected by an input validation vulnerability when decoding a crafted codec that could result in the disclosure of sensitive memory. An atta | 2,4% | — |
| CVE-2019-19770 | HIGH 8.2 | linux linux_kernel In the Linux kernel 4.19.83, there is a use-after-free (read) in the debugfs_remove function in fs/debugfs/inode.c (which is used to remove a file or directory in debugfs that was previously created with a call to another debugfs function such as debugfs_creat | 2,4% | — |
| CVE-2018-19450 | HIGH 7.8 | foxitsoftware foxit_pdf_sdk_activex A command injection can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) 5.4.0.1031 when parsing a launch action. An attacker can leverage this to gain remote code execution. | 2,4% | — |
| CVE-2018-19445 | HIGH 7.8 | foxitsoftware foxit_pdf_sdk_activex A command injection can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031 when the JavaScript API app.launchURL is used. An attacker can leverage this to gain remote code execution. | 2,4% | — |
| CVE-2025-21351 | HIGH 7.5 | microsoft windows_10_1607 Windows Active Directory Domain Services API Denial of Service Vulnerability | 2,4% | — |
| CVE-2024-38233 | HIGH 7.5 | microsoft windows_10_1607 Windows Networking Denial of Service Vulnerability | 2,4% | — |
| CVE-2022-28256 | MED 5.5 | adobe acrobat Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by a use-after-free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to b | 2,4% | — |
| CVE-2021-43899 | CRIT 9.8 | microsoft wireless_display_adapter_firmware Microsoft 4K Wireless Display Adapter Remote Code Execution Vulnerability | 2,4% | — |