58.046 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.046 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2018-0376 | CRIT 9.8 | cisco mobility_services_engine A vulnerability in the Policy Builder interface of Cisco Policy Suite before 18.2.0 could allow an unauthenticated, remote attacker to access the Policy Builder interface. The vulnerability is due to a lack of authentication. An attacker could exploit this vul | 2,7% | — |
| CVE-2018-0374 | CRIT 9.8 | cisco mobility_services_engine A vulnerability in the Policy Builder database of Cisco Policy Suite before 18.2.0 could allow an unauthenticated, remote attacker to connect directly to the Policy Builder database. The vulnerability is due to a lack of authentication. An attacker could explo | 2,7% | — |
| CVE-2022-29109 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 2,7% | — |
| CVE-2015-1643 | HIGH 7.2 | microsoft windows_7 Microsoft Windows Server 2003 R2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly constrain impersonation levels, which allows local user | 2,7% | — |
| CVE-2018-8564 | MED 4.3 | microsoft edge A spoofing vulnerability exists when Microsoft Edge improperly handles specific HTML content, aka "Microsoft Edge Spoofing Vulnerability." This affects Microsoft Edge. | 2,7% | — |
| CVE-2014-6386 | HIGH 7.8 | juniper junos Juniper Junos 11.4 before 11.4R8, 12.1X44 before 12.1X44-D35, 12.1X45 before 12.1X45-D25, 12.1X46 before 12.1X46-D20, 12.1X47 before 12.1X47-D10, 12.2 before 12.2R9, 12.3R2 before 12.3R2-S3, 12.3 before 12.3R3, 13.1 before 13.1R4, and 13.2 before 13.2R1 allows | 2,7% | — |
| CVE-2014-3819 | HIGH 7.8 | juniper junos Juniper Junos 11.4 before 11.4R12, 12.1 before 12.1R10, 12.1X44 before 12.1X44-D35, 12.1X45 before 12.1X45-D25, 12.1X46 before 12.1X46-D20, 12.1X47 before 12.1X47-D10, 12.2 before 12.2R8, 12.3 before 12.3R7, 13.1 before 13.1R4, 13.2 before 13.2R4, 13.3 before | 2,7% | — |
| CVE-2012-4618 | HIGH 7.8 | cisco ios The SIP ALG feature in the NAT implementation in Cisco IOS 12.2, 12.4, and 15.0 through 15.2 allows remote attackers to cause a denial of service (device reload) via transit IP packets, aka Bug ID CSCtn76183. | 2,7% | — |
| CVE-2011-1176 | MED 4.3 | debian debian_linux The configuration merger in itk.c in the Steinar H. Gunderson mpm-itk Multi-Processing Module 2.2.11-01 and 2.2.11-02 for the Apache HTTP Server does not properly handle certain configuration sections that specify NiceValue but not AssignUserID, which might al | 2,7% | — |
| CVE-2007-1215 | HIGH 7.2 | microsoft windows_2000 Buffer overflow in the Graphics Device Interface (GDI) in Microsoft Windows 2000 SP4; XP SP2; Server 2003 Gold, SP1, and SP2; and Vista allows local users to gain privileges via certain "color-related parameters" in crafted images. | 2,7% | — |
| CVE-2015-3270 | MED 6.5 | apache ambari Apache Ambari before 2.0.2 or 2.1.x before 2.1.1 allows remote authenticated users to gain administrative privileges via unspecified vectors, possibly related to changing passwords. | 2,7% | — |
| CVE-2014-9635 | MED 5.3 | jenkins jenkins Jenkins before 1.586 does not set the HttpOnly flag in a Set-Cookie header for session cookies when run on Tomcat 7.0.41 or later, which makes it easier for remote attackers to obtain potentially sensitive information via script access to cookies. | 2,7% | — |
| CVE-2014-9634 | MED 5.3 | jenkins jenkins Jenkins before 1.586 does not set the secure flag on session cookies when run on Tomcat 7.0.41 or later, which makes it easier for remote attackers to capture cookies by intercepting their transmission within an HTTP session. | 2,7% | — |
| CVE-2013-3887 | MED 4.9 | microsoft windows_7 The Ancillary Function Driver (AFD) in afd.sys in the kernel-mode drivers in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server 2012 allows local users to obtai | 2,7% | — |
| CVE-2012-1310 | HIGH 7.8 | cisco ios Memory leak in the Zone-Based Firewall in Cisco IOS 12.4, 15.0, 15.1, and 15.2 allows remote attackers to cause a denial of service (memory consumption or device reload) via crafted IP packets, aka Bug ID CSCto89536. | 2,7% | — |
| CVE-2023-28311 | HIGH 7.8 | microsoft 365_apps Microsoft Word Remote Code Execution Vulnerability | 2,7% | — |
| CVE-2024-21438 | HIGH 7.5 | microsoft windows_10_1507 Microsoft AllJoyn API Denial of Service Vulnerability | 2,7% | — |
| CVE-2022-21957 | HIGH 7.2 | microsoft dynamics_365 Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability | 2,7% | — |
| CVE-2016-3230 | MED 5.0 | microsoft windows_10 The Search component in Microsoft Windows 7, Windows Server 2008 R2 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to cause a denial of service (performance degradation) via a crafted applicat | 2,7% | — |
| CVE-2005-4886 | HIGH 7.8 | linux linux_kernel The selinux_parse_skb_ipv6 function in security/selinux/hooks.c in the Linux kernel before 2.6.12-rc4 allows remote attackers to cause a denial of service (OOPS) via vectors associated with an incorrect call to the ipv6_skip_exthdr function. | 2,7% | — |
| CVE-2020-9609 | MED 5.5 | adobe acrobat_dc Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | 2,7% | — |
| CVE-2021-1560 | MED 6.5 | cisco dna_spaces\ Multiple vulnerabilities in Cisco DNA Spaces Connector could allow an authenticated, remote attacker to perform a command injection attack on an affected device. These vulnerabilities are due to insufficient input sanitization when executing affected commands. | 2,7% | — |
| CVE-2021-1559 | MED 6.5 | cisco dna_spaces\ Multiple vulnerabilities in Cisco DNA Spaces Connector could allow an authenticated, remote attacker to perform a command injection attack on an affected device. These vulnerabilities are due to insufficient input sanitization when executing affected commands. | 2,7% | — |
| CVE-2021-41332 | MED 6.5 | microsoft windows_10 Windows Print Spooler Information Disclosure Vulnerability | 2,7% | — |
| CVE-2006-0457 | HIGH 7.1 | linux linux_kernel Race condition in the (1) add_key, (2) request_key, and (3) keyctl functions in Linux kernel 2.6.x allows local users to cause a denial of service (crash) or read sensitive kernel memory by modifying the length of a string argument between the time that the ke | 2,7% | — |