EN
56.706 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia

CVE Tracker

56.706 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più alto In KEV dal, ordina dal più alto
CVE-2021-38294 CRIT 9.8 apache storm A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x prior to 2.2.1 and Apache Storm 1.x prior to 1.2.4. A specially crafted thrift request to the Nimbus server allows Remote Code Execution (RCE) prior to authentic 84,5%
CVE-2015-1830 MED 5.0 apache activemq Directory traversal vulnerability in the fileserver upload/download functionality for blob messages in Apache ActiveMQ 5.x before 5.11.2 for Windows allows remote attackers to create JSP files in arbitrary directories via unspecified vectors. 84,4%
CVE-2023-29325 HIGH 8.1 microsoft windows_10_1507 Windows OLE Remote Code Execution Vulnerability 84,4%
CVE-2013-7285 CRIT 9.8 apache activemq Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarshaling XML or any supported format. e.g. 84,4%
CVE-2014-0556 HIGH 10.0 adobe adobe_air Heap-based buffer overflow in Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 84,3%
CVE-2024-21762 CRIT 9.8 ransomware fortinet fortios A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0 84,3%
CVE-2024-38077 CRIT 9.8 microsoft windows_server_2008 Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability 84,2%
CVE-2024-38112 HIGH 7.5 microsoft windows_10_1507 Windows MSHTML Platform Spoofing Vulnerability 84,2%
CVE-2017-0213 HIGH 7.3 ransomware microsoft windows_10_1507 Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation privilege vulnerabi 84,1%
CVE-2012-0779 HIGH 9.3 adobe flash_player Adobe Flash Player before 10.3.183.19 and 11.x before 11.2.202.235 on Windows, Mac OS X, and Linux; before 11.1.111.9 on Android 2.x and 3.x; and before 11.1.115.8 on Android 4.x allows remote attackers to execute arbitrary code via a crafted file, related to 84,1%
CVE-2024-43451 MED 6.5 microsoft windows_10_1507 NTLM Hash Disclosure Spoofing Vulnerability 84,1%
CVE-2024-30044 HIGH 7.2 microsoft sharepoint_server Microsoft SharePoint Server Remote Code Execution Vulnerability 84,0%
CVE-2020-3161 CRIT 9.8 cisco 8831_firmware A vulnerability in the web server for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition. The vulnerability is due to 83,9%
CVE-2009-3953 HIGH 8.8 adobe acrobat The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remote attackers to execute arbitrary code via malformed U3D data in a PDF document, related to a CLODProgressiveMeshDeclarat 83,9%
CVE-2018-11759 HIGH 7.5 apache tomcat_jk_connector The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK (mod_jk) Connector 1.2.0 to 1.2.44 did not handle some edge cases correctly. If only a sub-set of the URLs supported by 83,8%
CVE-2019-1620 CRIT 9.8 cisco data_center_network_manager A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to upload arbitrary files on an affected device. The vulnerability is due to incorrect permission settings in affe 83,8%
CVE-2023-50386 HIGH 8.8 apache solr Improper Control of Dynamically-Managed Code Resources, Unrestricted Upload of File with Dangerous Type, Inclusion of Functionality from Untrusted Control Sphere vulnerability in Apache Solr.This issue affects Apache Solr: from 6.0.0 through 8.11.2, from 9.0.0 83,7%
CVE-2023-39265 LOW 3.8 apache superset Apache Superset would allow for SQLite database connections to be incorrectly registered when an attacker uses alternative driver names like sqlite+pysqlite or by using database imports. This could allow for unexpected file creation on Superset webservers. Add 83,7%
CVE-2012-1889 HIGH 8.8 microsoft xml_core_services Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site. 83,6%
CVE-2019-0193 HIGH 7.2 apache solr In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the whole DIH configuration can come from a request's "dataConfig" parameter. The debug mode of the DIH admin screen 83,5%
CVE-2016-5195 HIGH 7.0 canonical ubuntu_linux Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in October 2016 83,5%
CVE-2022-26923 HIGH 8.8 microsoft windows_10_1507 Active Directory Domain Services Elevation of Privilege Vulnerability 83,5%
CVE-2005-1790 LOW 2.6 microsoft internet_explorer Microsoft Internet Explorer 6 SP2 6.0.2900.2180 and 6.0.2800.1106, and earlier versions, allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a Javascript BODY onload event that calls the window function, aka "Mismatched 83,5%
CVE-2019-9512 HIGH 7.5 apache traffic_server Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. The attacker sends continual pings to an HTTP/2 peer, causing the peer to build an internal queue of responses. Depending on how efficiently this data is que 83,4%
CVE-2021-20021 CRIT 9.8 ransomware sonicwall email_security A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. 83,4%