EN
57.056 CVE seguite
777 Sfruttate ora
184 Usate dai ransomware
Ultima sincronia

CVE Tracker

57.056 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2015-4291 HIGH 7.8 cisco ios_xe Cisco IOS XE 2.x before 2.4.3 and 2.5.x before 2.5.1 on ASR 1000 devices allows remote attackers to cause a denial of service (Embedded Services Processor crash) via a crafted series of fragmented (1) IPv4 or (2) IPv6 packets, aka Bug ID CSCtd72617. 2,0%
CVE-2024-49019 HIGH 7.8 microsoft windows_server_2008 Active Directory Certificate Services Elevation of Privilege Vulnerability 2,0%
CVE-2023-29330 HIGH 8.8 microsoft teams Microsoft Teams Remote Code Execution Vulnerability 2,0%
CVE-2022-25598 HIGH 7.5 apache dolphinscheduler Apache DolphinScheduler user registration is vulnerable to Regular express Denial of Service (ReDoS) attacks, Apache DolphinScheduler users should upgrade to version 2.0.5 or higher. 2,0%
CVE-2021-21984 CRIT 9.8 vmware vrealize_business_for_cloud VMware vRealize Business for Cloud 7.x prior to 7.6.0 contains a remote code execution vulnerability due to an unauthorised end point. A malicious actor with network access may exploit this issue causing unauthorised remote code execution on vRealize Business 2,0%
CVE-2020-5903 MED 6.1 f5 big-ip_access_policy_manager In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, a Cross-Site Scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility. 2,0%
CVE-2022-35774 MED 4.9 microsoft azure_site_recovery_vmware_to_azure Azure Site Recovery Elevation of Privilege Vulnerability 2,0%
CVE-2021-42732 HIGH 7.8 adobe indesign Access of Memory Location After End of Buffer (CWE-788) 2,0%
CVE-2021-43255 MED 5.5 microsoft 365_apps Microsoft Office Trust Center Spoofing Vulnerability 2,0%
CVE-2024-21307 HIGH 7.5 microsoft windows_10_1507 Remote Desktop Client Remote Code Execution Vulnerability 2,0%
CVE-2022-35744 CRIT 9.8 microsoft windows_10_1507 Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability 2,0%
CVE-2022-20801 MED 4.7 cisco rv340_firmware Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV340 and RV345 Routers could allow an authenticated, remote attacker to inject and execute arbitrary commands on the underlying operating system of an affected device. Thes 2,0%
CVE-2020-1595 CRIT 9.9 microsoft sharepoint_enterprise_server <p>A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe data input. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoint application 2,0%
CVE-2019-9969 HIGH 7.8 xnview xnview_classic XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to xnview+0x385399. 2,0%
CVE-2023-33170 HIGH 8.1 fedoraproject fedora ASP.NET and Visual Studio Security Feature Bypass Vulnerability 2,0%
CVE-2023-21728 HIGH 7.5 microsoft windows_10_1607 Windows Netlogon Denial of Service Vulnerability 2,0%
CVE-2023-21683 HIGH 7.5 microsoft windows_10_1607 Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability 2,0%
CVE-2023-21677 HIGH 7.5 microsoft windows_10_1607 Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability 2,0%
CVE-2023-21527 HIGH 7.5 microsoft windows_10_1607 Windows iSCSI Service Denial of Service Vulnerability 2,0%
CVE-2022-23206 HIGH 7.5 apache traffic_control In Apache Traffic Control Traffic Ops prior to 6.1.0 or 5.1.6, an unprivileged user who can reach Traffic Ops over HTTPS can send a specially-crafted POST request to /user/login/oauth to scan a port of a server that Traffic Ops can reach. 2,0%
CVE-2021-33746 HIGH 8.0 microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability 2,0%
CVE-2021-1639 HIGH 7.0 microsoft visual_studio_2017 Visual Studio Code Remote Code Execution Vulnerability 2,0%
CVE-2016-1295 MED 5.3 cisco adaptive_security_appliance_software Cisco Adaptive Security Appliance (ASA) Software 8.4 allows remote attackers to obtain sensitive information via an AnyConnect authentication attempt, aka Bug ID CSCuo65775. 2,0%
CVE-2010-1729 MED 4.3 apple safari WebKit.dll in WebKit, as used in Safari.exe 4.531.9.1 in Apple Safari, allows remote attackers to cause a denial of service (application crash) via JavaScript that writes <marquee> sequences in an infinite loop. 2,0%
CVE-2008-3817 HIGH 7.8 cisco adaptive_security_appliance_5500_series Memory leak in Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 8.0 before 8.0(4) and 8.1 before 8.1(2) allows remote attackers to cause a denial of service (memory consumption) via an unspecified sequence of packets, related to 2,0%