57.255 CVE seguite
779 Sfruttate ora
184 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.255 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2021-26920 | MED 6.5 | apache druid In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSource allows authenticated users to read data from other sources than intended, such as the local file system, with the privileges of th | 9,9% | — |
| CVE-2015-4047 | HIGH 7.8 | canonical ubuntu_linux racoon/gssapi.c in IPsec-Tools 0.8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a series of crafted UDP requests. | 9,9% | — |
| CVE-2016-0779 | CRIT 9.8 | apache tomee The EjbObjectInputStream class in Apache TomEE before 1.7.4 and 7.x before 7.0.0-M3 allows remote attackers to execute arbitrary code via a crafted serialized object. | 9,9% | — |
| CVE-2016-4092 | CRIT 9.8 | adobe acrobat Heap-based buffer overflow in Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allows attackers to execute arbitrary code vi | 9,9% | — |
| CVE-2016-4091 | CRIT 9.8 | adobe acrobat Heap-based buffer overflow in Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allows attackers to execute arbitrary code vi | 9,9% | — |
| CVE-2017-2962 | HIGH 7.8 | adobe acrobat Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable type confusion vulnerability in the XSLT engine related to localization functionality. Successful exploitation could lead to arbitrary cod | 9,9% | — |
| CVE-2020-0673 | HIGH 7.5 | microsoft internet_explorer A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0674, CVE-2020-0710, CVE-2020-0711, CV | 9,9% | — |
| CVE-2007-3164 | MED 5.8 | microsoft internet_explorer Microsoft Internet Explorer 7, when prompting for HTTP Basic Authentication for an IDN web site, uses ACE labels for the domain name in the status bar, but uses internationalized labels for this name in the authentication dialog, which might allow remote attac | 9,9% | — |
| CVE-2018-8041 | MED 5.3 | apache camel Apache Camel's Mail 2.20.0 through 2.20.3, 2.21.0 through 2.21.1 and 2.22.0 is vulnerable to path traversal. | 9,8% | — |
| CVE-2019-0609 | HIGH 7.5 | microsoft chakracore A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0639, CVE-2019-0680, CVE-2019-0769, CVE-20 | 9,8% | — |
| CVE-2000-0672 | MED 5.0 | apache tomcat The default configuration of Jakarta Tomcat does not restrict access to the /admin context, which allows remote attackers to read arbitrary files by directly calling the administrative servlets to add a context for the root directory. | 9,8% | — |
| CVE-2020-11581 | HIGH 8.1 | pulsesecure pulse_connect_secure An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris clients when a Host Checker policy is enforced, allows a man-in-the-middle attacker to perform OS command injec | 9,8% | — |
| CVE-2011-0598 | HIGH 9.3 | adobe acrobat Integer overflow in ACE.dll in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allows remote attackers to execute arbitrary code via crafted ICC data, a different vulnerability than CVE-2011-0596, CVE | 9,8% | — |
| CVE-2023-46260 | CRIT 9.8 | ivanti avalanche An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | 9,8% | — |
| CVE-2020-16915 | HIGH 7.8 | microsoft windows_10 <p>A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user | 9,8% | — |
| CVE-2017-7672 | MED 5.9 | apache struts If an application allows enter an URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL. Solution is to upgrade to Apache Struts versio | 9,8% | — |
| CVE-2018-8171 | HIGH 7.5 | microsoft asp.net_core A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature Bypass Vulnerability." This affects ASP.NET, ASP.NET Core 1.1, ASP.NET Core 1.0, ASP.NET Core 2.0, ASP.NET MVC | 9,8% | — |
| CVE-2000-0115 | MED 5.0 | microsoft internet_information_server IIS allows local users to cause a denial of service via invalid regular expressions in a Visual Basic script in an ASP page. | 9,8% | — |
| CVE-2018-8039 | HIGH 8.1 | apache cxf It is possible to configure Apache CXF to use the com.sun.net.ssl implementation via 'System.setProperty("java.protocol.handler.pkgs", "com.sun.net.ssl.internal.www.protocol");'. When this system property is set, CXF uses some reflection to try to make the Hos | 9,8% | — |
| CVE-2015-1421 | HIGH 10.0 | canonical ubuntu_linux Use-after-free vulnerability in the sctp_assoc_update function in net/sctp/associola.c in the Linux kernel before 3.18.8 allows remote attackers to cause a denial of service (slab corruption and panic) or possibly have unspecified other impact by triggering an | 9,8% | — |
| CVE-2025-52970 | HIGH 8.1 | fortinet fortiweb A improper handling of parameters in Fortinet FortiWeb versions 7.6.3 and below, versions 7.4.7 and below, versions 7.2.10 and below, and 7.0.10 and below may allow an unauthenticated remote attacker with non-public information pertaining to the device and tar | 9,8% | — |
| CVE-2017-11869 | HIGH 7.5 | microsoft internet_explorer Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain t | 9,8% | — |
| CVE-2006-1301 | HIGH 9.3 | microsoft excel Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted SELECTION record that triggers memory corruption, a different vulnerability than CVE-2006-1302. | 9,8% | — |
| CVE-2014-8985 | HIGH 7.5 | microsoft internet_explorer Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2810, CVE | 9,8% | — |
| CVE-1999-1110 | MED 5.0 | microsoft internet_explorer Windows Media Player ActiveX object as used in Internet Explorer 5.0 returns a specific error code when a file does not exist, which allows remote malicious web sites to determine the existence of files on the client. | 9,8% | — |