EN
57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

57.971 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più alto In KEV dal, ordina dal più alto
CVE-2007-3758 MED 4.3 apple safari Safari in Apple iPhone 1.1.1, and Safari 3 before Beta Update 3.0.4 on Windows and in Mac OS X 10.4 through 10.4.10, allows remote attackers to set Javascript window properties for web pages that are in a different domain, which can be leveraged to conduct cro 3,1%
CVE-2020-3111 HIGH 8.8 cisco ip_conference_phone_7832_firmware A vulnerability in the Cisco Discovery Protocol implementation for the Cisco IP Phone could allow an unauthenticated, adjacent attacker to remotely execute code with root privileges or cause a reload of an affected IP phone. The vulnerability is due to missing 3,1%
CVE-2020-17120 MED 5.3 microsoft sharepoint_foundation Microsoft SharePoint Information Disclosure Vulnerability 3,1%
CVE-2012-5636 MED 6.1 apache wicket Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.22, 1.5.x before 1.5.10, and 6.x before 6.4.0 might allow remote attackers to inject arbitrary web script or HTML via vectors related to <script> tags in a rendered response. 3,1%
CVE-2019-0207 HIGH 7.5 apache tapestry Tapestry processes assets `/assets/ctx` using classes chain `StaticFilesFilter -> AssetDispatcher -> ContextResource`, which doesn't filter the character `\`, so attacker can perform a path traversal attack to read any files on Windows platform. 3,1%
CVE-2013-1105 HIGH 9.0 cisco 2000_wireless_lan_controller Cisco Wireless LAN Controller (WLC) devices with software 7.0 before 7.0.235.3, 7.1 and 7.2 before 7.2.111.3, and 7.3 before 7.3.101.0 allow remote authenticated users to bypass wireless-management settings and read or modify the device configuration via an SN 3,1%
CVE-2005-3058 HIGH 7.5 fortinet fortigate Interpretation conflict in Fortinet FortiGate 2.8, running FortiOS 2.8MR10 and v3beta, allows remote attackers to bypass the URL blocker via an (1) HTTP request terminated with a line feed (LF) and not carriage return line feed (CRLF) or (2) HTTP request with 3,1%
CVE-2018-0264 CRIT 9.6 cisco webex_business_suite_31 A vulnerability in the Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) files could allow an unauthenticated, remote attacker to execute arbitrary code on the system of a targeted user. An attacker could exploit this vulnerability by se 3,1%
CVE-2013-3657 HIGH 7.5 vmware esx Buffer overflow in VMware ESXi 4.0 through 5.0, and ESX 4.0 and 4.1, allows remote attackers to execute arbitrary code or cause a denial of service via unspecified vectors. 3,1%
CVE-2021-45884 HIGH 7.5 brave brave In Brave Desktop 1.17 through 1.33 before 1.33.106, when CNAME-based adblocking and a proxying extension with a SOCKS fallback are enabled, additional DNS requests are issued outside of the proxying extension using the system's DNS settings, resulting in infor 3,1%
CVE-2021-42306 HIGH 8.1 microsoft azure_active_directory An information disclosure vulnerability manifests when a user or an application uploads unprotected private key data as part of an authentication certificate keyCredential  on an Azure AD Application or Service Principal (which is not recommended). This vulner 3,1%
CVE-2010-4390 HIGH 9.3 realnetworks realplayer Multiple heap-based buffer overflows in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.5, and Linux RealPlayer 11.0.2.1744 allow remote attackers to have an unspecified impact via a crafted header in an IVR file. 3,1%
CVE-2010-4379 HIGH 9.3 realnetworks realplayer Heap-based buffer overflow in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.4, RealPlayer Enterprise 2.1.2, Mac RealPlayer 11.0 through 11.1, Linux RealPlayer 11.0.2.1744, and possibly HelixPlayer 1.0.6 and other versions, allows rem 3,1%
CVE-2024-21392 HIGH 7.5 microsoft .net .NET and Visual Studio Denial of Service Vulnerability 3,1%
CVE-2020-9658 HIGH 7.8 adobe audition Adobe Audition versions 13.0.6 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution . 3,1%
CVE-2021-1714 HIGH 7.8 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 3,1%
CVE-2021-1713 HIGH 7.8 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 3,1%
CVE-2018-6947 HIGH 7.8 microsoft windows_10 An uninitialised stack variable in the nxfuse component that is part of the Open Source DokanFS library shipped with NoMachine 6.0.66_2 and earlier allows a local low privileged user to gain elevation of privileges on Windows 7 (32 and 64bit), and denial of se 3,1%
CVE-2012-6600 HIGH 9.0 paloaltonetworks pan-os The device-management command-line interface in Palo Alto Networks PAN-OS 4.0.x before 4.0.9 and 4.1.x before 4.1.2 allows remote authenticated users to execute arbitrary commands via unspecified vectors, aka Ref ID 34502. 3,1%
CVE-2022-24492 HIGH 8.8 microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability 3,1%
CVE-2006-5553 HIGH 7.8 cisco security_agent Cisco Security Agent (CSA) for Linux 4.5 before 4.5.1.657 and 5.0 before 5.0.0.193, as used by Unified CallManager (CUCM) and Unified Presence Server (CUPS), allows remote attackers to cause a denial of service (resource consumption) via a port scan with certa 3,1%
CVE-2001-0851 MED 5.0 caldera openlinux Linux kernel 2.0, 2.2 and 2.4 with syncookies enabled allows remote attackers to bypass firewall rules by brute force guessing the cookie. 3,1%
CVE-2021-39844 LOW 3.3 adobe acrobat Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of arbitrary memory information in the context of the curre 3,1%
CVE-2020-17058 HIGH 7.5 microsoft edge Microsoft Browser Memory Corruption Vulnerability 3,1%
CVE-2018-1272 HIGH 7.5 oracle application_testing_suite Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, provide client-side support for multipart requests. When Spring MVC or Spring WebFlux server application (server A) receives input from a remote clie 3,1%