EN
57.921 CVE seguite
783 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

57.921 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più alto In KEV dal, ordina dal più alto
CVE-2016-7216 MED 5.5 microsoft windows_7 The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 mishandles permissions, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Elevation of Privilege Vulnerability." 4,1%
CVE-2008-1451 HIGH 7.2 microsoft windows_2000 The WINS service on Microsoft Windows 2000 SP4, and Server 2003 SP1 and SP2, does not properly validate data structures in WINS network packets, which allows local users to gain privileges via a crafted packet, aka "Memory Overwrite Vulnerability." 4,1%
CVE-2018-6809 CRIT 9.8 citrix netscaler_application_delivery_controller_firmware NetScaler ADC 10.5, 11.0, 11.1, and 12.0, and NetScaler Gateway 10.5, 11.0, 11.1, and 12.0 allow remote attackers to gain privilege on a target system. 4,1%
CVE-2022-37967 HIGH 7.2 fedoraproject fedora Windows Kerberos Elevation of Privilege Vulnerability 4,1%
CVE-2021-30610 HIGH 8.8 fedoraproject fedora Chromium: CVE-2021-30610 Use after free in Extensions API 4,1%
CVE-2003-0664 HIGH 7.5 microsoft word Microsoft Word 2002, 2000, 97, and 98(J) does not properly check certain properties of a document, which allows attackers to bypass the macro security model and automatically execute arbitrary macros via a malicious document. 4,1%
CVE-2017-8474 MED 5.0 microsoft windows_10 The kernel in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a specially c 4,1%
CVE-2019-8013 HIGH 8.8 adobe acrobat_dc Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an use after free vulnerability. Successful exploi 4,1%
CVE-2020-17066 HIGH 7.8 microsoft excel Microsoft Excel Remote Code Execution Vulnerability 4,1%
CVE-2020-17065 HIGH 7.8 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 4,1%
CVE-2020-17062 HIGH 7.8 microsoft 365_apps Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability 4,1%
CVE-2019-12806 HIGH 8.8 crosscert unisign UniSign 2.0.4.0 and earlier version contains a stack-based buffer overflow vulnerability which can overwrite the stack with arbitrary data, due to a buffer overflow in a library. That leads remote attacker to execute arbitrary code via crafted https packets. 4,1%
CVE-2018-8490 HIGH 8.4 microsoft windows_10 A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka "Windows Hyper-V Remote Code Execution Vulnerability." This affects Windows Server 2 4,1%
CVE-2003-0232 HIGH 7.2 microsoft data_engine Microsoft SQL Server 7, 2000, and MSDE allows local users to execute arbitrary code via a certain request to the Local Procedure Calls (LPC) port that leads to a buffer overflow. 4,1%
CVE-2021-30624 HIGH 8.8 fedoraproject fedora Chromium: CVE-2021-30624 Use after free in Autofill 4,1%
CVE-2021-30620 HIGH 8.8 fedoraproject fedora Chromium: CVE-2021-30620 Insufficient policy enforcement in Blink 4,1%
CVE-2021-30618 HIGH 8.8 fedoraproject fedora Chromium: CVE-2021-30618 Inappropriate implementation in DevTools 4,1%
CVE-2021-30613 HIGH 8.8 fedoraproject fedora Chromium: CVE-2021-30613 Use after free in Base internals 4,1%
CVE-2021-30607 HIGH 8.8 fedoraproject fedora Chromium: CVE-2021-30607 Use after free in Permissions 4,1%
CVE-2021-30606 HIGH 8.8 fedoraproject fedora Chromium: CVE-2021-30606 Use after free in Blink 4,1%
CVE-2020-16924 HIGH 7.8 microsoft windows_10 <p>A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system.</p> <p>An attacker could explo 4,1%
CVE-2019-1051 MED 4.2 microsoft chakracore A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context 4,1%
CVE-2018-17198 CRIT 9.8 apache roller Server-side Request Forgery (SSRF) and File Enumeration vulnerability in Apache Roller 5.2.1, 5.2.0 and earlier unsupported versions relies on Java SAX Parser to implement its XML-RPC interface and by default that parser supports external entities in XML DOCTY 4,1%
CVE-2017-7064 MED 5.5 apple icloud An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. The issue involves the "WebKit" component. It allows at 4,1%
CVE-2019-15992 HIGH 7.2 cisco adaptive_security_appliance A vulnerability in the implementation of the Lua interpreter integrated in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to execute arbitrary code with root priv 4,1%