57.065 CVE seguite
777 Sfruttate ora
184 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.065 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2021-40758 | HIGH 7.8 | adobe after_effects Adobe After Effects version 18.4.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious WAV file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is requir | 2,0% | — |
| CVE-2020-3194 | HIGH 7.8 | cisco webex_meetings A vulnerability in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exists due to insufficient validation of certa | 2,0% | — |
| CVE-2019-0869 | MED 6.1 | microsoft azure_devops_server A spoofing vulnerability exists in Microsoft Azure DevOps Server when it fails to properly handle web requests, aka 'Azure DevOps Server HTML Injection Vulnerability'. | 2,0% | — |
| CVE-2013-3173 | HIGH 7.2 | microsoft windows_7 Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to ga | 2,0% | — |
| CVE-2009-1195 | MED 4.9 | apache http_server The Apache HTTP Server 2.2.11 and earlier 2.2 versions does not properly handle Options=IncludesNOEXEC in the AllowOverride directive, which allows local users to gain privileges by configuring (1) Options Includes, (2) Options +Includes, or (3) Options +Inclu | 2,0% | — |
| CVE-2021-42758 | HIGH 8.8 | fortinet fortiwlc An improper access control vulnerability [CWE-284] in FortiWLC 8.6.1 and below may allow an authenticated and remote attacker with low privileges to execute any command as an admin user with full access rights via bypassing the GUI restrictions. | 2,0% | — |
| CVE-2018-15428 | MED 6.8 | cisco ios_xr A vulnerability in the implementation of Border Gateway Protocol (BGP) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to incorrect processing of cert | 2,0% | — |
| CVE-2014-3261 | HIGH 7.6 | cisco cg-os Buffer overflow in the Smart Call Home implementation in Cisco NX-OS on Fabric Interconnects in Cisco Unified Computing System 1.4 before 1.4(1i), NX-OS 5.0 before 5.0(3)U2(2) on Nexus 3000 devices, NX-OS 4.1 before 4.1(2)E1(1l) on Nexus 4000 devices, NX-OS 5. | 2,0% | — |
| CVE-2007-0186 | MED 6.8 | f5 firepass_4100 Multiple cross-site scripting (XSS) vulnerabilities in F5 FirePass SSL VPN allow remote attackers to inject arbitrary web script or HTML via (1) the xcho parameter to my.logon.php3; the (2) topblue, (3) midblue, (4) wtopblue, and certain other Custom color par | 2,0% | — |
| CVE-1999-0165 | HIGH 10.0 | bsdi bsd_os NFS cache poisoning. | 2,0% | — |
| CVE-2023-38647 | CRIT 9.8 | apache helix An attacker can use SnakeYAML to deserialize java.net.URLClassLoader and make it load a JAR from a specified URL, and then deserialize javax.script.ScriptEngineManager to load code using that ClassLoader. This unbounded deserialization can likely lead to remot | 2,0% | — |
| CVE-2022-38006 | MED 6.5 | microsoft windows_10 Windows Graphics Component Information Disclosure Vulnerability | 2,0% | — |
| CVE-2018-1338 | MED 5.5 | apache tika A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's BPGParser in versions of Apache Tika before 1.18. | 2,0% | — |
| CVE-2013-5481 | HIGH 7.1 | cisco ios The PPTP implementation in Cisco IOS 12.2 and 15.0 through 15.3, when NAT is used, allows remote attackers to cause a denial of service (device reload) via crafted TCP port-1723 packets, aka Bug ID CSCtq14817. | 2,0% | — |
| CVE-2008-3818 | HIGH 7.8 | cisco ons Cisco ONS 15310-CL, 15310-MA, 15327, 15454, 15454 SDH, and 15600 with software 7.0.2 through 7.0.6, 7.2.2, 8.0.x, 8.5.1, and 8.5.2 allows remote attackers to cause a denial of service (control-card reset) via a crafted TCP session. | 2,0% | — |
| CVE-2006-7217 | MED 4.0 | apache derby Apache Derby before 10.2.1.6 does not determine schema privilege requirements during the DropSchemaNode bind phase, which allows remote authenticated users to execute arbitrary drop schema statements in SQL authorization mode. | 2,0% | — |
| CVE-2024-54677 | MED 5.3 | apache tomcat Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of service. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.9. | 2,0% | — |
| CVE-2021-43013 | HIGH 7.8 | adobe media_encoder Adobe Media Encoder version 15.4.1 (and earlier) are affected by a memory corruption vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue | 2,0% | — |
| CVE-2021-1313 | HIGH 8.6 | cisco ios_xr Multiple vulnerabilities in the ingress packet processing function of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, se | 2,0% | — |
| CVE-2021-1288 | HIGH 8.6 | cisco ios_xr Multiple vulnerabilities in the ingress packet processing function of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, se | 2,0% | — |
| CVE-2015-0751 | HIGH 7.8 | cisco unified_communications_manager Cisco IP Phone 7861, when firmware from Cisco Unified Communications Manager 10.3(1) is used, allows remote attackers to cause a denial of service via crafted packets, aka Bug ID CSCus81800. | 2,0% | — |
| CVE-2012-5055 | MED 5.0 | vmware springsource_spring_security DaoAuthenticationProvider in VMware SpringSource Spring Security before 2.0.8, 3.0.x before 3.0.8, and 3.1.x before 3.1.3 does not check the password if the user is not found, which makes the response delay shorter and might allow remote attackers to enumerate | 2,0% | — |
| CVE-2026-62888 | HIGH 7.8 | microsoft windows_10_21h2 Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | 2,0% | — |
| CVE-2026-62783 | HIGH 7.8 | microsoft windows_10_1809 Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. | 2,0% | — |
| CVE-2023-36437 | HIGH 8.8 | microsoft azure_pipelines_agent Azure DevOps Server Remote Code Execution Vulnerability | 2,0% | — |