58.070 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.070 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2024-26215 | HIGH 7.5 | microsoft windows_server_2008 DHCP Server Service Denial of Service Vulnerability | 2,7% | — |
| CVE-2022-30133 | CRIT 9.8 | microsoft windows_10 Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability | 2,7% | — |
| CVE-2021-1385 | MED 6.5 | cisco ios A vulnerability in the Cisco IOx application hosting environment of multiple Cisco platforms could allow an authenticated, remote attacker to conduct directory traversal attacks and read and write files on the underlying operating system or host system. This v | 2,7% | — |
| CVE-2012-2945 | HIGH 7.5 | apache hadoop Hadoop 1.0.3 contains a symlink vulnerability. | 2,7% | — |
| CVE-2022-24532 | HIGH 7.8 | microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability | 2,7% | — |
| CVE-2018-5224 | HIGH 8.8 | atlassian bamboo Bamboo did not correctly check if a configured Mercurial repository URI contained values that the Windows operating system may consider argument parameters. An attacker who has permission to create a repository in Bamboo, edit an existing plan in Bamboo that h | 2,7% | — |
| CVE-2018-0170 | HIGH 7.5 | cisco ios_xe A vulnerability in the Cisco Umbrella Integration feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition, related to the OpenDNS software. The vulnerability is due to a logic error that exi | 2,7% | — |
| CVE-2018-0157 | HIGH 8.6 | cisco ios_xe A vulnerability in the Zone-Based Firewall code of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a device to reload. The vulnerability is due to the way fragmented packets are handled in the firewall code. An attacker could exp | 2,7% | — |
| CVE-2018-0136 | HIGH 8.6 | cisco ios_xr A vulnerability in the IPv6 subsystem of Cisco IOS XR Software Release 5.3.4 for the Cisco Aggregation Services Router (ASR) 9000 Series could allow an unauthenticated, remote attacker to trigger a reload of one or more Trident-based line cards, resulting in a | 2,7% | — |
| CVE-2017-3864 | HIGH 8.6 | cisco ios A vulnerability in the DHCP client implementation of Cisco IOS (12.2, 12.4, and 15.0 through 15.6) and Cisco IOS XE (3.3 through 3.7) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability occurs during | 2,7% | — |
| CVE-2013-2757 | HIGH 7.5 | citrix cloudplatform Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C does not properly restrict access to VNC ports on the management network, which allows remote attackers to have unspecified impact via unknown vectors. | 2,7% | — |
| CVE-2022-30192 | HIGH 8.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 2,7% | — |
| CVE-2022-28274 | HIGH 7.8 | adobe photoshop Adobe Photoshop versions 22.5.6 (and earlier) and 23.2.2 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this | 2,7% | — |
| CVE-2011-4087 | HIGH 7.5 | linux linux_kernel The br_parse_ip_options function in net/bridge/br_netfilter.c in the Linux kernel before 2.6.39 does not properly initialize a certain data structure, which allows remote attackers to cause a denial of service by leveraging connectivity to a network interface | 2,7% | — |
| CVE-2008-3792 | HIGH 7.1 | linux linux_kernel net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.26.4 does not verify that the SCTP-AUTH extension is enabled before proceeding with SCTP-AUTH API functions, which allows attackers to cause a de | 2,7% | — |
| CVE-2024-38226 | HIGH 7.3 | microsoft office_2019 Microsoft Publisher Security Feature Bypass Vulnerability | 2,7% | |
| CVE-2020-1937 | HIGH 8.8 | apache kylin Kylin has some restful apis which will concatenate SQLs with the user input string, a user is likely to be able to run malicious database queries. | 2,7% | — |
| CVE-2010-1763 | HIGH 10.0 | apple itunes Unspecified vulnerability in WebKit in Apple iTunes before 9.2 on Windows has unknown impact and attack vectors, a different vulnerability than CVE-2010-1387 and CVE-2010-1769. | 2,7% | — |
| CVE-2021-38629 | MED 6.5 | microsoft windows_10 Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability | 2,7% | — |
| CVE-2020-24557 | HIGH 7.8 | trendmicro apex_one A vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 on Microsoft Windows may allow an attacker to manipulate a particular product folder to disable the security temporarily, abuse a specific Windows function and attain privilege e | 2,7% | |
| CVE-2017-7663 | MED 6.1 | apache openmeetings Both global and Room chat are vulnerable to XSS attack in Apache OpenMeetings 3.2.0. | 2,7% | — |
| CVE-2021-42524 | HIGH 7.8 | adobe animate Adobe Animate version 21.0.9 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a | 2,7% | — |
| CVE-2021-42272 | HIGH 7.8 | adobe animate Adobe Animate version 21.0.9 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a | 2,7% | — |
| CVE-2020-3554 | HIGH 7.5 | cisco adaptive_security_appliance A vulnerability in the TCP packet processing of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected devic | 2,7% | — |
| CVE-2020-1198 | HIGH 7.4 | microsoft sharepoint_enterprise_server <p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially | 2,7% | — |