58.127 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.127 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2016-6445 | CRIT 9.1 | cisco meeting_server A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) service of the Cisco Meeting Server (CMS) before 2.0.6 and Acano Server before 1.8.18 and 1.9.x before 1.9.6 could allow an unauthenticated, remote attacker to masquerade as a legitimate | 2,5% | — |
| CVE-2010-0590 | HIGH 7.8 | cisco unified_communications_manager The CMSIPUtility component in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 7.x before 7.1(3a)su1 and 8.x before 8.0(1) allows remote attackers to cause a denial of service (process failure) via a malformed SIP Register message, aka Bug | 2,5% | — |
| CVE-2010-0587 | HIGH 7.8 | cisco unified_communications_manager Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x before 4.3(2)SR2, 6.x before 6.1(5), 7.x before 7.1(3a)su1, and 8.x before 8.0(1) allows remote attackers to cause a denial of service (process failure) via a malformed SCCP StationCapab | 2,5% | — |
| CVE-2001-0757 | HIGH 7.5 | cisco 6400_nrp_2 Cisco 6400 Access Concentrator Node Route Processor 2 (NRP2) 12.1DC card does not properly disable access when a password has not been set for vtys, which allows remote attackers to obtain access via telnet. | 2,5% | — |
| CVE-2026-55009 | HIGH 7.8 | microsoft exchange_server Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally. | 2,5% | — |
| CVE-2024-21409 | HIGH 7.3 | microsoft .net .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability | 2,5% | — |
| CVE-2023-36585 | HIGH 7.5 | microsoft windows_10_1507 Windows upnphost.dll Denial of Service Vulnerability | 2,5% | — |
| CVE-2021-40452 | HIGH 7.8 | microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability | 2,5% | — |
| CVE-2021-36008 | LOW 3.3 | adobe illustrator Adobe Illustrator version 25.2.3 (and earlier) is affected by an Use-after-free vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to read arbitrary file system information in the context of the c | 2,5% | — |
| CVE-2019-6982 | MED 5.5 | foxitsoftware 3d An issue was discovered in Foxit 3D Plugin Beta before 9.4.0.16807 for Foxit Reader and PhantomPDF. The application could encounter an Out-of-Bounds Write and crash during the handling of certain PDF files that embed specifically crafted 3D content, because of | 2,5% | — |
| CVE-2018-14613 | MED 5.5 | linux linux_kernel An issue was discovered in the Linux kernel through 4.17.10. There is an invalid pointer dereference in io_ctl_map_page() when mounting and operating a crafted btrfs image, because of a lack of block group item validation in check_leaf_item in fs/btrfs/tree-ch | 2,5% | — |
| CVE-2014-6379 | HIGH 7.5 | juniper junos Juniper Junos 11.4 before R12, 12.1 before R10, 12.1X44 before D35, 12.1X45 before D25, 12.1X46 before D20, 12.1X47 before D10, 12.2 before R8, 12.2X50 before D70, 12.3 before R6, 13.1 before R4-S3, 13.1X49 before D55, 13.1X50 before D30, 13.2 before R4, 13.2X | 2,5% | — |
| CVE-2002-0792 | MED 5.0 | cisco content_services_switch_11000 The web management interface for Cisco Content Service Switch (CSS) 11000 switches allows remote attackers to cause a denial of service (soft reset) via (1) an HTTPS POST request, or (2) malformed XML data. | 2,5% | — |
| CVE-2021-31454 | HIGH 7.8 | foxitsoftware foxit_reader This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.1.37576. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The | 2,5% | — |
| CVE-2023-36910 | CRIT 9.8 | microsoft windows_10 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 2,5% | — |
| CVE-2021-24081 | HIGH 7.8 | microsoft windows_10 Microsoft Windows Codecs Library Remote Code Execution Vulnerability | 2,5% | — |
| CVE-2019-8240 | HIGH 7.5 | adobe bridge_cc Adobe Bridge CC versions 9.1 and earlier have a memory corruption vulnerability. Successful exploitation could lead to information disclosure. | 2,5% | — |
| CVE-2019-8239 | HIGH 7.5 | adobe bridge_cc Adobe Bridge CC versions 9.1 and earlier have a memory corruption vulnerability. Successful exploitation could lead to information disclosure. | 2,5% | — |
| CVE-2012-1746 | MED 5.0 | oracle database_server Unspecified vulnerability in the Network Layer component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3, when running on Windows, allows remote attackers to affect availability via unknown vectors, a different vulnerab | 2,5% | — |
| CVE-2024-22274 | HIGH 7.2 | vmware cloud_foundation The vCenter Server contains an authenticated remote code execution vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to run arbitrary commands on the underlying operating system. | 2,5% | — |
| CVE-2016-5333 | CRIT 9.8 | vmware photon_os VMware Photos OS OVA 1.0 before 2016-08-14 has a default SSH public key in an authorized_keys file, which allows remote attackers to obtain SSH access by leveraging knowledge of the private key. | 2,5% | — |
| CVE-2020-1565 | HIGH 7.5 | microsoft windows_10 An elevation of privilege vulnerability exists when the "Public Account Pictures" folder improperly handles junctions. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a sp | 2,5% | — |
| CVE-2020-1477 | HIGH 7.0 | microsoft windows_10 A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user ri | 2,5% | — |
| CVE-2018-0372 | HIGH 7.5 | cisco nx-os A vulnerability in the DHCPv6 feature of the Cisco Nexus 9000 Series Fabric Switches in Application-Centric Infrastructure (ACI) Mode could allow an unauthenticated, remote attacker to cause the device to run low on system memory, which could result in a Denia | 2,5% | — |
| CVE-2018-0316 | HIGH 7.5 | cisco ip_phone_firmware A vulnerability in the Session Initiation Protocol (SIP) call-handling functionality of Cisco IP Phone 6800, 7800, and 8800 Series Phones with Multiplatform Firmware could allow an unauthenticated, remote attacker to cause an affected phone to reload unexpecte | 2,5% | — |