56.721 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.721 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2021-31196 | HIGH 7.2 | microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 54,1% | |
| CVE-2015-6172 | HIGH 9.3 | microsoft office Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2016, Word 2013 RT SP1, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code via a crafted email message processed by Outlook, aka "Microsoft Office RCE | 53,9% | — |
| CVE-2017-7659 | HIGH 7.5 | apache http_server A maliciously constructed HTTP/2 request could cause mod_http2 in Apache HTTP Server 2.4.24, 2.4.25 to dereference a NULL pointer and crash the server process. | 53,9% | — |
| CVE-2022-21971 | HIGH 7.8 | microsoft windows_10_1809 Windows Runtime Remote Code Execution Vulnerability | 53,9% | |
| CVE-2016-3325 | LOW 3.1 | microsoft edge Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability." | 53,9% | — |
| CVE-2007-3896 | HIGH 9.3 | microsoft internet_explorer The URL handling in Shell32.dll in the Windows shell in Microsoft Windows XP and Server 2003, with Internet Explorer 7 installed, allows remote attackers to execute arbitrary programs via invalid "%" sequences in a mailto: or other URI handler, as demonstrated | 53,8% | — |
| CVE-2026-49160 | HIGH 7.5 | microsoft windows_10_1607 Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network. | 53,8% | — |
| CVE-2008-4255 | HIGH 9.3 | microsoft office_frontpage Heap-based buffer overflow in mscomct2.ocx (aka Windows Common ActiveX control or Microsoft Animation ActiveX control) in Microsoft Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2, and Office Project 2003 S | 53,7% | — |
| CVE-2016-3209 | MED 5.5 | microsoft .net_framework Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word | 53,7% | — |
| CVE-2021-22941 | CRIT 9.8 | ransomware citrix sharefile_storagezones_controller Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compromise the storage zones controller. | 53,6% | |
| CVE-2021-27068 | HIGH 8.8 | microsoft visual_studio_2019 Visual Studio Remote Code Execution Vulnerability | 53,6% | — |
| CVE-2002-1143 | MED 5.0 | microsoft excel Microsoft Word and Excel allow remote attackers to steal sensitive information via certain field codes that insert the information when the document is returned to the attacker, as demonstrated in Word using (1) INCLUDETEXT or (2) INCLUDEPICTURE, aka "Flaw in | 53,6% | — |
| CVE-2023-32029 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 53,5% | — |
| CVE-2002-1254 | HIGH 7.5 | microsoft ie Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model and access information on the local system or in other domains, and possibly execute code, via cached methods and objects, aka "Cross Domain Verification via Cached | 53,5% | — |
| CVE-2023-39456 | HIGH 7.5 | apache traffic_server Improper Input Validation vulnerability in Apache Traffic Server with malformed HTTP/2 frames.This issue affects Apache Traffic Server: from 9.0.0 through 9.2.2. Users are recommended to upgrade to version 9.2.3, which fixes the issue. | 53,5% | — |
| CVE-2006-5583 | HIGH 10.0 | microsoft windows_2003_server Buffer overflow in the SNMP Service in Microsoft Windows 2000 SP4, XP SP2, Server 2003, Server 2003 SP1, and possibly other versions allows remote attackers to execute arbitrary code via a crafted SNMP packet, aka "SNMP Memory Corruption Vulnerability." | 53,5% | — |
| CVE-2020-35452 | HIGH 7.3 | apache http_server Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack overflow in mod_auth_digest. There is no report of this overflow being exploitable, nor the Apache HTTP Server team could create one, though some particular compiler | 53,5% | — |
| CVE-2021-23017 | HIGH 7.7 | f5 nginx A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact. | 53,5% | — |
| CVE-2011-0104 | HIGH 9.3 | microsoft excel Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted HLink record in an Excel file, aka " | 53,4% | — |
| CVE-2015-2419 | HIGH 8.8 | microsoft internet_explorer JScript 9 in Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "JScript9 Memory Corruption Vulnerability." | 53,4% | |
| CVE-2016-2211 | HIGH 7.8 | symantec advanced_threat_protection The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) fo | 53,4% | — |
| CVE-2020-1074 | HIGH 7.8 | microsoft windows_10 <p>A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system.</p> <p>An attacker could explo | 53,4% | — |
| CVE-2005-1978 | HIGH 7.5 | microsoft windows_2000 COM+ in Microsoft Windows does not properly "create and use memory structures," which allows local users or remote attackers to execute arbitrary code. | 53,4% | — |
| CVE-1999-0191 | MED 6.4 | microsoft internet_information_server IIS newdsn.exe CGI script allows remote users to overwrite files. | 53,3% | — |
| CVE-2015-1642 | HIGH 7.8 | microsoft office Microsoft Office 2007 SP3, 2010 SP2, and 2013 SP1 allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability." | 53,2% |