57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.971 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2007-3758 | MED 4.3 | apple safari Safari in Apple iPhone 1.1.1, and Safari 3 before Beta Update 3.0.4 on Windows and in Mac OS X 10.4 through 10.4.10, allows remote attackers to set Javascript window properties for web pages that are in a different domain, which can be leveraged to conduct cro | 3,1% | — |
| CVE-2020-3111 | HIGH 8.8 | cisco ip_conference_phone_7832_firmware A vulnerability in the Cisco Discovery Protocol implementation for the Cisco IP Phone could allow an unauthenticated, adjacent attacker to remotely execute code with root privileges or cause a reload of an affected IP phone. The vulnerability is due to missing | 3,1% | — |
| CVE-2020-17120 | MED 5.3 | microsoft sharepoint_foundation Microsoft SharePoint Information Disclosure Vulnerability | 3,1% | — |
| CVE-2012-5636 | MED 6.1 | apache wicket Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.22, 1.5.x before 1.5.10, and 6.x before 6.4.0 might allow remote attackers to inject arbitrary web script or HTML via vectors related to <script> tags in a rendered response. | 3,1% | — |
| CVE-2019-0207 | HIGH 7.5 | apache tapestry Tapestry processes assets `/assets/ctx` using classes chain `StaticFilesFilter -> AssetDispatcher -> ContextResource`, which doesn't filter the character `\`, so attacker can perform a path traversal attack to read any files on Windows platform. | 3,1% | — |
| CVE-2013-1105 | HIGH 9.0 | cisco 2000_wireless_lan_controller Cisco Wireless LAN Controller (WLC) devices with software 7.0 before 7.0.235.3, 7.1 and 7.2 before 7.2.111.3, and 7.3 before 7.3.101.0 allow remote authenticated users to bypass wireless-management settings and read or modify the device configuration via an SN | 3,1% | — |
| CVE-2005-3058 | HIGH 7.5 | fortinet fortigate Interpretation conflict in Fortinet FortiGate 2.8, running FortiOS 2.8MR10 and v3beta, allows remote attackers to bypass the URL blocker via an (1) HTTP request terminated with a line feed (LF) and not carriage return line feed (CRLF) or (2) HTTP request with | 3,1% | — |
| CVE-2018-0264 | CRIT 9.6 | cisco webex_business_suite_31 A vulnerability in the Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) files could allow an unauthenticated, remote attacker to execute arbitrary code on the system of a targeted user. An attacker could exploit this vulnerability by se | 3,1% | — |
| CVE-2013-3657 | HIGH 7.5 | vmware esx Buffer overflow in VMware ESXi 4.0 through 5.0, and ESX 4.0 and 4.1, allows remote attackers to execute arbitrary code or cause a denial of service via unspecified vectors. | 3,1% | — |
| CVE-2021-45884 | HIGH 7.5 | brave brave In Brave Desktop 1.17 through 1.33 before 1.33.106, when CNAME-based adblocking and a proxying extension with a SOCKS fallback are enabled, additional DNS requests are issued outside of the proxying extension using the system's DNS settings, resulting in infor | 3,1% | — |
| CVE-2021-42306 | HIGH 8.1 | microsoft azure_active_directory An information disclosure vulnerability manifests when a user or an application uploads unprotected private key data as part of an authentication certificate keyCredential on an Azure AD Application or Service Principal (which is not recommended). This vulner | 3,1% | — |
| CVE-2010-4390 | HIGH 9.3 | realnetworks realplayer Multiple heap-based buffer overflows in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.5, and Linux RealPlayer 11.0.2.1744 allow remote attackers to have an unspecified impact via a crafted header in an IVR file. | 3,1% | — |
| CVE-2010-4379 | HIGH 9.3 | realnetworks realplayer Heap-based buffer overflow in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.4, RealPlayer Enterprise 2.1.2, Mac RealPlayer 11.0 through 11.1, Linux RealPlayer 11.0.2.1744, and possibly HelixPlayer 1.0.6 and other versions, allows rem | 3,1% | — |
| CVE-2024-21392 | HIGH 7.5 | microsoft .net .NET and Visual Studio Denial of Service Vulnerability | 3,1% | — |
| CVE-2020-9658 | HIGH 7.8 | adobe audition Adobe Audition versions 13.0.6 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution . | 3,1% | — |
| CVE-2021-1714 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 3,1% | — |
| CVE-2021-1713 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 3,1% | — |
| CVE-2018-6947 | HIGH 7.8 | microsoft windows_10 An uninitialised stack variable in the nxfuse component that is part of the Open Source DokanFS library shipped with NoMachine 6.0.66_2 and earlier allows a local low privileged user to gain elevation of privileges on Windows 7 (32 and 64bit), and denial of se | 3,1% | — |
| CVE-2012-6600 | HIGH 9.0 | paloaltonetworks pan-os The device-management command-line interface in Palo Alto Networks PAN-OS 4.0.x before 4.0.9 and 4.1.x before 4.1.2 allows remote authenticated users to execute arbitrary commands via unspecified vectors, aka Ref ID 34502. | 3,1% | — |
| CVE-2022-24492 | HIGH 8.8 | microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability | 3,1% | — |
| CVE-2006-5553 | HIGH 7.8 | cisco security_agent Cisco Security Agent (CSA) for Linux 4.5 before 4.5.1.657 and 5.0 before 5.0.0.193, as used by Unified CallManager (CUCM) and Unified Presence Server (CUPS), allows remote attackers to cause a denial of service (resource consumption) via a port scan with certa | 3,1% | — |
| CVE-2001-0851 | MED 5.0 | caldera openlinux Linux kernel 2.0, 2.2 and 2.4 with syncookies enabled allows remote attackers to bypass firewall rules by brute force guessing the cookie. | 3,1% | — |
| CVE-2021-39844 | LOW 3.3 | adobe acrobat Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of arbitrary memory information in the context of the curre | 3,1% | — |
| CVE-2020-17058 | HIGH 7.5 | microsoft edge Microsoft Browser Memory Corruption Vulnerability | 3,1% | — |
| CVE-2018-1272 | HIGH 7.5 | oracle application_testing_suite Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, provide client-side support for multipart requests. When Spring MVC or Spring WebFlux server application (server A) receives input from a remote clie | 3,1% | — |