57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.971 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2017-12216 | HIGH 8.8 | cisco socialminer A vulnerability in the web-based user interface of Cisco SocialMiner could allow an unauthenticated, remote attacker to have read and write access to information stored in the affected system. The vulnerability is due to improper handling of XML External Entit | 2,9% | — |
| CVE-2012-4086 | MED 5.1 | cisco unified_computing_system A setup script for fabric interconnect devices in Cisco Unified Computing System (UCS) allows remote attackers to execute arbitrary commands via invalid parameters, aka Bug ID CSCtg20790. | 2,9% | — |
| CVE-2007-1281 | HIGH 7.8 | kaspersky_lab kaspersky_antivirus_engine Kaspersky AntiVirus Engine 6.0.1.411 for Windows and 5.5-10 for Linux allows remote attackers to cause a denial of service (CPU consumption) via a crafted UPX compressed file with a negative offset, which triggers an infinite loop during decompression. | 2,9% | — |
| CVE-2006-3945 | MED 5.0 | opera opera_browser The CSS functionality in Opera 9 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by setting the background property of a DHTML element to a long http or https URL, which triggers memory corruption. | 2,9% | — |
| CVE-2026-20929 | HIGH 7.5 | microsoft windows_10_1607 Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network. | 2,9% | — |
| CVE-2022-32250 | HIGH 7.8 | debian debian_linux net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces) to escalate privileges to root because an incorrect NFT_STATEFUL_EXPR check leads to a use-after-free. | 2,9% | — |
| CVE-2021-31214 | HIGH 7.8 | microsoft visual_studio_code Visual Studio Code Remote Code Execution Vulnerability | 2,9% | — |
| CVE-2018-10880 | MED 5.5 | canonical ubuntu_linux Linux kernel is vulnerable to a stack-out-of-bounds write in the ext4 filesystem code when mounting and writing to a crafted ext4 image in ext4_update_inline_data(). An attacker could use this to cause a system crash and a denial of service. | 2,9% | — |
| CVE-2016-4921 | HIGH 7.5 | juniper junos By flooding a Juniper Networks router running Junos OS with specially crafted IPv6 traffic, all available resources can be consumed, leading to the inability to store next hop information for legitimate traffic. In extreme cases, the crafted IPv6 traffic may r | 2,9% | — |
| CVE-2023-36560 | HIGH 8.8 | microsoft .net_framework ASP.NET Security Feature Bypass Vulnerability | 2,9% | — |
| CVE-2019-12407 | MED 6.1 | apache jspwiki On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the remember parameter on some of the JSPs, which could allow the attacker to execute javascript in the vict | 2,9% | — |
| CVE-2019-12404 | MED 6.1 | apache jspwiki On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to InfoContent.jsp, which could allow the attacker to execute javascript in the victim's browser and get some s | 2,9% | — |
| CVE-2019-10087 | MED 6.1 | apache jspwiki On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the Page Revision History, which could allow the attacker to execute javascript in the victim's browser and | 2,9% | — |
| CVE-2018-8156 | MED 5.4 | microsoft project_server An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft | 2,9% | — |
| CVE-2018-8155 | MED 5.4 | microsoft sharepoint_foundation An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft | 2,9% | — |
| CVE-2018-8149 | MED 5.4 | microsoft sharepoint_server An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft | 2,9% | — |
| CVE-2014-0721 | HIGH 10.0 | cisco unified_sip_phone_3905 The Cisco Unified SIP Phone 3905 with firmware before 9.4(1) allows remote attackers to obtain root access via a session on the test interface on TCP port 7870, aka Bug ID CSCuh75574. | 2,9% | — |
| CVE-2021-31205 | MED 6.5 | microsoft windows_10 Windows SMB Client Security Feature Bypass Vulnerability | 2,9% | — |
| CVE-2017-15717 | MED 6.1 | apache sling_xss_protection_api A flaw in the way URLs are escaped and encoded in the org.apache.sling.xss.impl.XSSAPIImpl#getValidHref and org.apache.sling.xss.impl.XSSFilterImpl#isValidHref allows special crafted URLs to pass as valid, although they carry XSS payloads. The affected version | 2,9% | — |
| CVE-2010-4682 | HIGH 7.8 | cisco 5500_series_adaptive_security_appliance Memory leak on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2(3) allows remote attackers to cause a denial of service (memory consumption) by making multiple incorrect LDAP authentication attempts, aka Bug ID CSCtf29867. | 2,9% | — |
| CVE-2022-30130 | LOW 3.3 | microsoft .net_framework .NET Framework Denial of Service Vulnerability | 2,9% | — |
| CVE-2019-14897 | CRIT 9.8 | canonical ubuntu_linux A stack-based buffer overflow was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip driver. An attacker is able to cause a denial of service (system crash) or, possibly execute arbitrary code, when a STA works in IBSS mode (allows connecti | 2,9% | — |
| CVE-2020-17082 | HIGH 7.8 | microsoft raw_image_extension Raw Image Extension Remote Code Execution Vulnerability | 2,9% | — |
| CVE-2023-38222 | HIGH 7.8 | adobe acrobat Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user in | 2,9% | — |
| CVE-2006-6589 | MED 6.8 | apache ofbiz Cross-site scripting (XSS) vulnerability in ecommerce/control/keywordsearch in the Apache Open For Business Project (OFBiz) and Opentaps 0.9.3 allows remote attackers to inject arbitrary web script or HTML via the SEARCH_STRING parameter, a different issue tha | 2,9% | — |