58.135 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.135 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2024-21755 | HIGH 8.8 | fortinet fortisandbox A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.3, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0.0 through 4.0.4 allows attacker to execute unauthorized | 2,5% | — |
| CVE-2021-24070 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 2,5% | — |
| CVE-2021-24068 | HIGH 7.8 | microsoft excel Microsoft Excel Remote Code Execution Vulnerability | 2,5% | — |
| CVE-2021-24067 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 2,5% | — |
| CVE-2020-3586 | CRIT 9.4 | cisco dna_spaces\ A vulnerability in the web-based management interface of Cisco DNA Spaces Connector could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insufficient validation of user-supplied input | 2,5% | — |
| CVE-2007-3945 | MED 6.4 | rsbac rule_set_based_access_control Rule Set Based Access Control (RSBAC) before 1.3.5 does not properly use the Linux Kernel Crypto API for the Linux kernel 2.6.x, which allows context-dependent attackers to bypass authentication controls via unspecified vectors, possibly involving User Managem | 2,5% | — |
| CVE-2017-3876 | HIGH 7.5 | cisco ios_xr A vulnerability in the Event Management Service daemon (emsd) of Cisco IOS XR routers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. The vulnerability is due to improper handling of gRPC req | 2,5% | — |
| CVE-2017-3859 | HIGH 7.5 | cisco ios_xe A vulnerability in the DHCP code for the Zero Touch Provisioning feature of Cisco ASR 920 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to a format string vul | 2,5% | — |
| CVE-2017-3856 | HIGH 7.5 | cisco ios_xe A vulnerability in the web user interface of Cisco IOS XE 3.1 through 3.17 could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to insufficient resource handling by the affected software when the web u | 2,5% | — |
| CVE-2017-3808 | HIGH 7.5 | cisco unified_communications_manager A vulnerability in the Session Initiation Protocol (SIP) UDP throttling process of Cisco Unified Communications Manager (Cisco Unified CM) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The v | 2,5% | — |
| CVE-2000-0487 | LOW 3.6 | microsoft windows_2000 The Protected Store in Windows 2000 does not properly select the strongest encryption when available, which causes it to use a default of 40-bit encryption instead of 56-bit DES encryption, aka the "Protected Store Key Length" vulnerability. | 2,5% | — |
| CVE-2022-30209 | HIGH 7.4 | microsoft windows_10 Windows IIS Server Elevation of Privilege Vulnerability | 2,5% | — |
| CVE-2017-2315 | HIGH 7.5 | juniper junos On Juniper Networks EX Series Ethernet Switches running affected Junos OS versions, a vulnerability in IPv6 processing has been discovered that may allow a specially crafted IPv6 Neighbor Discovery (ND) packet destined to an EX Series Ethernet Switch to cause | 2,5% | — |
| CVE-2022-26910 | MED 5.3 | microsoft skype_for_business_server Skype for Business and Lync Spoofing Vulnerability | 2,5% | — |
| CVE-2018-17186 | HIGH 7.2 | apache syncope An administrator with workflow definition entitlements can use DTD to perform malicious operations, including but not limited to file read, file write, and code execution. | 2,5% | — |
| CVE-2015-4223 | MED 5.0 | cisco ios_xr Cisco IOS XR 5.1.3 allows remote attackers to cause a denial of service (process reload) via crafted MPLS Label Distribution Protocol (LDP) packets, aka Bug ID CSCuu77478. | 2,5% | — |
| CVE-2013-0149 | MED 5.8 | cisco asa_5500 The OSPF implementation in Cisco IOS 12.0 through 12.4 and 15.0 through 15.3, IOS-XE 2.x through 3.9.xS, ASA and PIX 7.x through 9.1, FWSM, NX-OS, and StarOS before 14.0.50488 does not properly validate Link State Advertisement (LSA) type 1 packets before perf | 2,5% | — |
| CVE-2022-33638 | HIGH 8.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 2,5% | — |
| CVE-2020-9696 | MED 5.5 | adobe acrobat_dc Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have a security bypass vulnerability. Successful exploitation could lead to security feature bypass. | 2,5% | — |
| CVE-2016-6407 | HIGH 7.5 | cisco web_security_appliance Cisco AsyncOS through 9.5.0-444 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (link saturation) by making many HTTP requests for overlapping byte ranges simultaneously, aka Bug ID CSCuz27219. | 2,5% | — |
| CVE-2021-42723 | HIGH 7.8 | adobe premiere_pro Adobe Bridge version 11.1.1 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted SGI file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute c | 2,5% | — |
| CVE-2019-0993 | MED 4.2 | microsoft chakracore A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context | 2,5% | — |
| CVE-2019-0991 | MED 4.2 | microsoft chakracore A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context | 2,5% | — |
| CVE-2017-11876 | HIGH 8.8 | microsoft project_server Microsoft Project Server and Microsoft SharePoint Enterprise Server 2016 allow an attacker to use cross-site forgery to read content that they are not authorized to read, use the victim's identity to take actions on the web application on behalf of the victim, | 2,5% | — |
| CVE-2026-20816 | HIGH 7.8 | microsoft windows_10_1607 Time-of-check time-of-use (toctou) race condition in Windows Installer allows an authorized attacker to elevate privileges locally. | 2,5% | — |