57.056 CVE seguite
777 Sfruttate ora
184 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.056 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2021-21008 | HIGH 7.0 | adobe animate Adobe Animate version 21.0 (and earlier) is affected by an uncontrolled search path element that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a mali | 2,4% | — |
| CVE-2019-12648 | HIGH 8.8 | cisco ios A vulnerability in the IOx application environment for Cisco IOS Software could allow an authenticated, remote attacker to gain unauthorized access to the Guest Operating System (Guest OS) running on an affected device. The vulnerability is due to incorrect ro | 2,4% | — |
| CVE-2001-0895 | MED 5.0 | cisco catalyst_2900xl Multiple Cisco networking products allow remote attackers to cause a denial of service on the local network via a series of ARP packets sent to the router's interface that contains a different MAC address for the router, which eventually causes the router to o | 2,4% | — |
| CVE-2021-24081 | HIGH 7.8 | microsoft windows_10 Microsoft Windows Codecs Library Remote Code Execution Vulnerability | 2,3% | — |
| CVE-2018-0386 | MED 6.1 | cisco hosted_collaboration_solution A vulnerability in Cisco Unified Communications Domain Manager Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on an affected system. The vulnerability is due to improper validation of input that is passe | 2,3% | — |
| CVE-2022-26816 | MED 6.5 | microsoft windows_server_2016 Windows DNS Server Information Disclosure Vulnerability | 2,3% | — |
| CVE-2017-12362 | MED 6.5 | cisco meeting_server A vulnerability in Cisco Meeting Server versions prior to 2.2.2 could allow an authenticated, remote attacker to cause the system to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to video calls being made on systems with a | 2,3% | — |
| CVE-2014-1663 | MED 5.0 | citrix xenmobile_device_manager Unspecified vulnerability in Citrix XenMobile Device Manager server (formerly Zenprise Device Manager server) 8.5, 8.6, and MDM 8.0.1 allows remote attackers to obtain sensitive information via unknown vectors. | 2,3% | — |
| CVE-2011-2583 | MED 5.0 | cisco unified_contact_center_express Cisco Unified Contact Center Express (aka CCX) 8.0 and 8.5 allows remote attackers to cause a denial of service via network traffic, as demonstrated by an SEC-BE-STABLE test case, aka Bug ID CSCth33834. | 2,3% | — |
| CVE-2025-21176 | HIGH 8.8 | microsoft .net .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability | 2,3% | — |
| CVE-2021-38542 | MED 5.9 | apache james Apache James prior to release 3.6.1 is vulnerable to a buffering attack relying on the use of the STARTTLS command. This can result in Man-in -the-middle command injection attacks, leading potentially to leakage of sensible information. | 2,3% | — |
| CVE-2018-3939 | HIGH 8.8 | foxitsoftware foxit_reader An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 9.1.0.5096. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution | 2,3% | — |
| CVE-2018-0371 | MED 6.5 | cisco meeting_server A vulnerability in the Web Admin Interface of Cisco Meeting Server could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient validation of incoming HTTP requests. An attacker could expl | 2,3% | — |
| CVE-2011-0788 | HIGH 7.6 | sun jdk Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, when running on Windows, allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, a | 2,3% | — |
| CVE-2018-0330 | HIGH 8.8 | cisco nx-os A vulnerability in the NX-API management application programming interface (API) in devices running, or based on, Cisco NX-OS Software could allow an authenticated, remote attacker to execute commands with elevated privileges. The vulnerability is due to a fai | 2,3% | — |
| CVE-2017-7664 | CRIT 10.0 | apache openmeetings Uploaded XML documents were not correctly validated in Apache OpenMeetings 3.1.0. | 2,3% | — |
| CVE-2015-6260 | HIGH 7.5 | zyxel gs1900-10hp_firmware Cisco NX-OS 7.1(1)N1(1) on Nexus 5500, 5600, and 6000 devices does not properly validate PDUs in SNMP packets, which allows remote attackers to cause a denial of service (SNMP application restart) via a crafted packet, aka Bug ID CSCut84645. | 2,3% | — |
| CVE-2015-3099 | MED 5.0 | adobe air Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and | 2,3% | — |
| CVE-2015-3098 | MED 5.0 | adobe air Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and | 2,3% | — |
| CVE-2022-3724 | MED 6.3 | wireshark wireshark Crash in the USB HID protocol dissector in Wireshark 3.6.0 to 3.6.8 allows denial of service via packet injection or crafted capture file on Windows | 2,3% | — |
| CVE-2026-21531 | CRIT 9.8 | microsoft azure_conversation_authoring_client_library Deserialization of untrusted data in Azure SDK allows an unauthorized attacker to execute code over a network. | 2,3% | — |
| CVE-2024-41869 | HIGH 7.8 | adobe acrobat Acrobat Reader versions 24.002.21005, 24.001.30159, 20.005.30655, 24.003.20054 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user | 2,3% | — |
| CVE-2022-22976 | MED 5.3 | netapp active_iq_unified_manager Spring Security versions 5.5.x prior to 5.5.7, 5.6.x prior to 5.6.4, and earlier unsupported versions contain an integer overflow vulnerability. When using the BCrypt class with the maximum work factor (31), the encoder does not perform any salt rounds, due to | 2,3% | — |
| CVE-2022-21874 | HIGH 7.8 | microsoft windows_10 Windows Security Center API Remote Code Execution Vulnerability | 2,3% | — |
| CVE-2021-31180 | HIGH 7.8 | microsoft 365_apps Microsoft Office Graphics Remote Code Execution Vulnerability | 2,3% | — |