57.620 CVE seguite
783 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.620 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2013-1129 | MED 5.0 | cisco unity_connection Memory leak in Cisco Unity Connection 9.x allows remote attackers to cause a denial of service (memory consumption and process crash) by sending many TCP requests, aka Bug ID CSCud59736. | 1,2% | — |
| CVE-2012-3899 | MED 5.0 | cisco intrusion_prevention_system sensorApp on Cisco IPS 4200 series sensors 6.0, 6.2, and 7.0 does not properly allocate memory, which allows remote attackers to cause a denial of service (memory corruption and process crash, and traffic-inspection outage) via network traffic, aka Bug ID CSCt | 1,2% | — |
| CVE-2012-1357 | MED 5.0 | cisco nexus_5000 The igmp_snoop_orib_fill_source_update function in the IGMP process in NX-OS 5.0 and 5.1 on Cisco Nexus 5000 series switches allows remote attackers to cause a denial of service (device reload) via IGMP packets, aka Bug ID CSCts46521. | 1,2% | — |
| CVE-2012-1346 | MED 5.0 | cisco emergency_responder Cisco Emergency Responder 8.6 and 9.2 allows remote attackers to cause a denial of service (CPU consumption) by sending malformed UDP packets to the CERPT port, aka Bug ID CSCtx38369. | 1,2% | — |
| CVE-2002-2316 | MED 5.0 | cisco catos Cisco Catalyst 4000 series switches running CatOS 5.5.5, 6.3.5, and 7.1.2 do not always learn MAC addresses from a single initial packet, which causes unicast traffic to be broadcast across the switch and allows remote attackers to obtain sensitive network inf | 1,2% | — |
| CVE-2024-21399 | HIGH 8.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 1,2% | — |
| CVE-2022-20859 | MED 6.5 | cisco unified_communications_manager A vulnerability in the Disaster Recovery framework of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), and Cisco Unity Connection could allow an authenticated, remote attac | 1,2% | — |
| CVE-2020-9606 | HIGH 7.8 | adobe acrobat_dc Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have an use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution . | 1,2% | — |
| CVE-2018-0439 | HIGH 8.8 | cisco meeting_server A vulnerability in the web-based management interface of Cisco Meeting Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to | 1,2% | — |
| CVE-2018-0413 | HIGH 8.8 | cisco identity_services_engine_software A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnera | 1,2% | — |
| CVE-2023-41752 | HIGH 7.5 | apache traffic_server Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Traffic Server.This issue affects Apache Traffic Server: from 8.0.0 through 8.1.8, from 9.0.0 through 9.2.2. Users are recommended to upgrade to version 8.1.9 or 9.2.3, which f | 1,2% | — |
| CVE-2022-0971 | HIGH 8.8 | google chrome Use after free in Blink Layout in Google Chrome on Android prior to 99.0.4844.74 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. | 1,2% | — |
| CVE-2022-30148 | MED 5.5 | microsoft windows_10 Windows Desired State Configuration (DSC) Information Disclosure Vulnerability | 1,2% | — |
| CVE-2022-29114 | MED 5.5 | microsoft windows_10 Windows Print Spooler Information Disclosure Vulnerability | 1,2% | — |
| CVE-2013-1222 | HIGH 7.8 | cisco unified_customer_voice_portal The Tomcat Web Management feature in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 does not properly configure Tomcat components, which allows remote attackers to launch arbitrary custom web applications via a crafted (1) HTTP or (2) HT | 1,2% | — |
| CVE-2024-43487 | MED 6.5 | microsoft windows_10_1507 Windows Mark of the Web Security Feature Bypass Vulnerability | 1,2% | — |
| CVE-2022-20757 | HIGH 8.6 | cisco secure_firewall_threat_defense A vulnerability in the connection handling function in Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper traff | 1,2% | — |
| CVE-2021-31372 | HIGH 8.8 | juniper junos An Improper Input Validation vulnerability in J-Web of Juniper Networks Junos OS allows a locally authenticated J-Web attacker to escalate their privileges to root over the target device. This issue affects: Juniper Networks Junos OS All versions prior to 18.3 | 1,2% | — |
| CVE-2021-1648 | HIGH 7.8 | microsoft windows_10 Microsoft splwow64 Elevation of Privilege Vulnerability | 1,2% | — |
| CVE-2018-0297 | MED 5.8 | cisco secure_firewall_threat_defense A vulnerability in the detection engine of Cisco Firepower Threat Defense software could allow an unauthenticated, remote attacker to bypass a configured Secure Sockets Layer (SSL) Access Control (AC) policy to block SSL traffic. The vulnerability is due to th | 1,2% | — |
| CVE-2010-4305 | MED 5.0 | cisco unified_videoconferencing_system_3515_multipoint_control_unit Cisco Unified Videoconferencing (UVC) System 3545, 5110, 5115, and 5230; Unified Videoconferencing 3527 Primary Rate Interface (PRI) Gateway; Unified Videoconferencing 3522 Basic Rate Interfaces (BRI) Gateway; and Unified Videoconferencing 3515 Multipoint Cont | 1,2% | — |
| CVE-2023-46801 | HIGH 8.8 | apache linkis In Apache Linkis <= 1.5.0, data source management module, when adding Mysql data source, exists remote code execution vulnerability for java version < 1.8.0_241. The deserialization vulnerability exploited through jrmp can inject malicious files into the serv | 1,2% | — |
| CVE-2023-36766 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Information Disclosure Vulnerability | 1,2% | — |
| CVE-2023-31058 | HIGH 7.5 | apache inlong Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Attackers would bypass the 'autoDeserialize' option filtering by adding blanks. Users are advised to upgrad | 1,2% | — |
| CVE-2017-20006 | HIGH 7.8 | rarlab unrar UnRAR 5.6.1.2 and 5.6.1.3 has a heap-based buffer overflow in Unpack::CopyString (called from Unpack::Unpack5 and CmdExtract::ExtractCurrentFile). | 1,2% | — |