56.706 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.706 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2022-21972 | HIGH 8.1 | microsoft windows_10 Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | 79,8% | — |
| CVE-2004-1080 | HIGH 10.0 | microsoft windows_2000 The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attackers to write to arbitrary memory locations and possibly execute arbitrary code via a modified memory pointer in a WINS replication | 79,8% | — |
| CVE-2006-4777 | HIGH 7.6 | microsoft ie Heap-based buffer overflow in the DirectAnimation Path Control (DirectAnimation.PathControl) COM object (daxctle.ocx) for Internet Explorer 6.0 SP1, on Chinese and possibly other Windows distributions, allows remote attackers to execute arbitrary code via unkn | 79,8% | — |
| CVE-2020-16139 | HIGH 7.5 | cisco unified_ip_conference_station_7937g_firmware A denial-of-service in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers restart the device remotely through sending specially crafted packets. Note: We cannot prove this vulnerability exists. Out of an abundance of caution, th | 79,8% | — |
| CVE-2011-4858 | MED 5.0 | apache tomcat Apache Tomcat before 5.5.35, 6.x before 6.0.35, and 7.x before 7.0.23 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) | 79,7% | — |
| CVE-2016-7201 | HIGH 8.8 | microsoft edge The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerabilit | 79,7% | |
| CVE-2026-41089 | CRIT 9.8 | microsoft windows_server_2012 Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network. | 79,6% | — |
| CVE-2018-4993 | HIGH 7.5 | adobe acrobat_dc Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an NTLM SSO hash theft vulnerability. Successful exploitation could lead to information disclosure. | 79,5% | — |
| CVE-2008-5499 | HIGH 9.3 | adobe flash_player_for_linux Unspecified vulnerability in Adobe Flash Player for Linux 10.0.12.36, and 9.0.151.0 and earlier, allows remote attackers to execute arbitrary code via a crafted SWF file. | 79,4% | — |
| CVE-2024-56325 | CRIT 9.8 | apache pinot Authentication Bypass Issue If the path does not contain / and contain., authentication is not required. Expected Normal Request and Response Example curl -X POST -H "Content-Type: application/json" -d {\"username\":\"hack2\",\"password\":\"hack\",\"compone | 79,4% | — |
| CVE-2020-13957 | CRIT 9.8 | apache solr Apache Solr versions 6.6.0 to 6.6.6, 7.0.0 to 7.7.3 and 8.0.0 to 8.6.2 prevents some features considered dangerous (which could be used for remote code execution) to be configured in a ConfigSet that's uploaded via API without authentication/authorization. The | 79,3% | — |
| CVE-2023-20889 | HIGH 7.5 | vmware vrealize_network_insight Aria Operations for Networks contains an information disclosure vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in information disclosure. | 79,3% | — |
| CVE-2006-5614 | LOW 2.6 | microsoft windows_nt_helper_components Microsoft Windows NAT Helper Components (ipnathlp.dll) on Windows XP SP2, when Internet Connection Sharing is enabled, allows remote attackers to cause a denial of service (svchost.exe crash) via a malformed DNS query, which results in a null pointer dereferen | 79,2% | — |
| CVE-2016-8740 | HIGH 7.5 | apache http_server The mod_http2 module in the Apache HTTP Server 2.4.17 through 2.4.23, when the Protocols configuration includes h2 or h2c, does not restrict request-header length, which allows remote attackers to cause a denial of service (memory consumption) via crafted CONT | 79,1% | — |
| CVE-2022-23944 | CRIT 9.1 | apache shenyu User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1. | 79,0% | — |
| CVE-2009-3548 | HIGH 7.5 | apache tomcat The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a blank default password for the administrative user, which allows remote attackers to gain privileges. | 79,0% | — |
| CVE-2020-13947 | MED 6.1 | apache activemq An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the message.jsp page of Apache ActiveMQ versions 5.15.12 through 5.16.0. | 79,0% | — |
| CVE-2018-0769 | HIGH 7.5 | microsoft chakracore Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corrupti | 79,0% | — |
| CVE-2006-4691 | HIGH 10.0 | microsoft windows_2000 Stack-based buffer overflow in the NetpManageIPCConnect function in the Workstation service (wkssvc.dll) in Microsoft Windows 2000 SP4 and XP SP2 allows remote attackers to execute arbitrary code via NetrJoinDomain2 RPC messages with a long hostname. | 78,9% | — |
| CVE-2019-1622 | MED 5.3 | cisco data_center_network_manager A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to retrieve sensitive information from an affected device. The vulnerability is due to improper access controls fo | 78,9% | — |
| CVE-2012-4792 | HIGH 8.8 | microsoft internet_explorer Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly allocated or (2) is deleted, as demonstrated by a CDwnB | 78,8% | |
| CVE-2015-0015 | HIGH 7.8 | microsoft windows_server_2003 Microsoft Windows Server 2003 SP2, Server 2008 SP2 and R2 SP1, and Server 2012 Gold and R2 allow remote attackers to cause a denial of service (system hang and RADIUS outage) via crafted username strings to (1) Internet Authentication Service (IAS) or (2) Netw | 78,7% | — |
| CVE-2021-22555 | HIGH 8.3 | brocade fabric_operating_system A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space | 78,7% | |
| CVE-2006-0027 | HIGH 7.5 | microsoft exchange_server Unspecified vulnerability in Microsoft Exchange allows remote attackers to execute arbitrary code via e-mail messages with crafted (1) vCal or (2) iCal Calendar properties. | 78,7% | — |
| CVE-2018-0886 | HIGH 7.0 | microsoft windows_10 The Credential Security Support Provider protocol (CredSSP) in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709 Windows Server 2016 and Windows Server, | 78,6% | — |