57.075 CVE seguite
777 Sfruttate ora
184 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.075 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2021-27644 | HIGH 8.8 | apache dolphinscheduler In Apache DolphinScheduler before 1.3.6 versions, authorized users can use SQL injection in the data source center. (Only applicable to MySQL data source with internal login account password) | 1,9% | — |
| CVE-2019-0040 | CRIT 9.1 | juniper junos On Junos OS, rpcbind should only be listening to port 111 on the internal routing instance (IRI). External packets destined to port 111 should be dropped. Due to an information leak vulnerability, responses were being generated from the source address of the m | 1,9% | — |
| CVE-2017-0096 | LOW 2.6 | microsoft windows_10 Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1, Windows Server 2012 Gold and R2; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows guest OS users to obtain sensitive information from host OS mem | 1,9% | — |
| CVE-2014-2128 | MED 5.0 | cisco adaptive_security_appliance_software The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 8.2 before 8.2(5.47, 8.3 before 8.3(2.40), 8.4 before 8.4(7.3), 8.6 before 8.6(1.13), 9.0 before 9.0(3.8), and 9.1 before 9.1(3.2) allows remote attackers to bypass authentication v | 1,9% | — |
| CVE-2003-0187 | MED 5.0 | linux linux_kernel The connection tracking core of Netfilter for Linux 2.4.20, with CONFIG_IP_NF_CONNTRACK enabled or the ip_conntrack module loaded, allows remote attackers to cause a denial of service (resource consumption) due to an inconsistency with Linux 2.4.20's support o | 1,9% | — |
| CVE-2024-20662 | MED 4.9 | microsoft windows_server_2008 Windows Online Certificate Status Protocol (OCSP) Information Disclosure Vulnerability | 1,9% | — |
| CVE-2021-43083 | HIGH 8.8 | apache plc4x Apache PLC4X - PLC4C (Only the C language implementation was effected) was vulnerable to an unsigned integer underflow flaw inside the tcp transport. Users should update to 0.9.1, which addresses this issue. However, in order to exploit this vulnerability, a u | 1,9% | — |
| CVE-2019-0003 | MED 5.9 | juniper junos When a specific BGP flowspec configuration is enabled and upon receipt of a specific matching BGP packet meeting a specific term in the flowspec configuration, a reachable assertion failure occurs, causing the routing protocol daemon (rpd) process to crash wit | 1,9% | — |
| CVE-2017-6792 | MED 6.5 | cisco prime_collaboration_provisioning A vulnerability in the batch provisioning feature in Cisco Prime Collaboration Provisioning Tool could allow an authenticated, remote attacker to overwrite system files as root. The vulnerability is due to lack of input validation of the parameters in BatchFil | 1,9% | — |
| CVE-2022-30149 | HIGH 7.5 | microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 1,9% | — |
| CVE-2022-30146 | HIGH 7.5 | microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 1,9% | — |
| CVE-2022-30143 | HIGH 7.5 | microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 1,9% | — |
| CVE-2022-30140 | HIGH 7.5 | microsoft windows_10 Windows iSCSI Discovery Service Remote Code Execution Vulnerability | 1,9% | — |
| CVE-2010-2554 | HIGH 7.8 | microsoft windows_7 The Tracing Feature for Services in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 has incorrect ACLs on its registry keys, which allows local users to gain privileges via vectors involving a named pipe and impersonat | 1,9% | — |
| CVE-2021-36182 | HIGH 8.8 | fortinet fortiweb A Improper neutralization of special elements used in a command ('Command Injection') in Fortinet FortiWeb version 6.3.13 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests | 1,9% | — |
| CVE-2021-43876 | HIGH 8.8 | microsoft sharepoint_enterprise_server Microsoft SharePoint Elevation of Privilege Vulnerability | 1,9% | — |
| CVE-2021-29747 | HIGH 7.5 | ibm infosphere_information_server IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain highly sensitive information due to a vulnerability in the authentication mechanism. IBM X-Force ID: 201775. | 1,9% | — |
| CVE-2020-3436 | HIGH 8.6 | cisco adaptive_security_appliance A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to upload arbitrary-sized files to specific folders on an affected device | 1,9% | — |
| CVE-2020-3414 | HIGH 8.6 | cisco ios_xe A vulnerability in the packet processing of Cisco IOS XE Software for Cisco 4461 Integrated Services Routers could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerabil | 1,9% | — |
| CVE-2019-1947 | HIGH 8.6 | cisco asyncos A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause the CPU utilization to increase to 100 percent, causing a denial of service (DoS) | 1,9% | — |
| CVE-2020-3298 | HIGH 7.5 | cisco adaptive_security_appliance_software A vulnerability in the Open Shortest Path First (OSPF) implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the reload of an affected devic | 1,9% | — |
| CVE-2020-3254 | HIGH 7.5 | cisco adaptive_security_appliance_software Multiple vulnerabilities in the Media Gateway Control Protocol (MGCP) inspection feature of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of servic | 1,9% | — |
| CVE-2022-20871 | MED 6.3 | cisco asyncos A vulnerability in the web management interface of Cisco AsyncOS for Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow an authenticated, remote attacker to perform a command injection and elevate privilege | 1,9% | — |
| CVE-2023-46226 | CRIT 9.8 | apache iotdb Remote Code Execution vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 1.0.0 through 1.2.2. Users are recommended to upgrade to version 1.3.0, which fixes the issue. | 1,9% | — |
| CVE-2022-31781 | HIGH 7.5 | apache tapestry Apache Tapestry up to version 5.8.1 is vulnerable to Regular Expression Denial of Service (ReDoS) in the way it handles Content Types. Specially crafted Content Types may cause catastrophic backtracking, taking exponential time to complete. Specifically, this | 1,9% | — |