EN
58.135 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.135 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più alto In KEV dal, ordina dal più alto
CVE-2024-21755 HIGH 8.8 fortinet fortisandbox A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.3, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0.0 through 4.0.4 allows attacker to execute unauthorized 2,5%
CVE-2021-24070 HIGH 7.8 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 2,5%
CVE-2021-24068 HIGH 7.8 microsoft excel Microsoft Excel Remote Code Execution Vulnerability 2,5%
CVE-2021-24067 HIGH 7.8 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 2,5%
CVE-2020-3586 CRIT 9.4 cisco dna_spaces\ A vulnerability in the web-based management interface of Cisco DNA Spaces Connector could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insufficient validation of user-supplied input 2,5%
CVE-2007-3945 MED 6.4 rsbac rule_set_based_access_control Rule Set Based Access Control (RSBAC) before 1.3.5 does not properly use the Linux Kernel Crypto API for the Linux kernel 2.6.x, which allows context-dependent attackers to bypass authentication controls via unspecified vectors, possibly involving User Managem 2,5%
CVE-2017-3876 HIGH 7.5 cisco ios_xr A vulnerability in the Event Management Service daemon (emsd) of Cisco IOS XR routers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. The vulnerability is due to improper handling of gRPC req 2,5%
CVE-2017-3859 HIGH 7.5 cisco ios_xe A vulnerability in the DHCP code for the Zero Touch Provisioning feature of Cisco ASR 920 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to a format string vul 2,5%
CVE-2017-3856 HIGH 7.5 cisco ios_xe A vulnerability in the web user interface of Cisco IOS XE 3.1 through 3.17 could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to insufficient resource handling by the affected software when the web u 2,5%
CVE-2017-3808 HIGH 7.5 cisco unified_communications_manager A vulnerability in the Session Initiation Protocol (SIP) UDP throttling process of Cisco Unified Communications Manager (Cisco Unified CM) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The v 2,5%
CVE-2000-0487 LOW 3.6 microsoft windows_2000 The Protected Store in Windows 2000 does not properly select the strongest encryption when available, which causes it to use a default of 40-bit encryption instead of 56-bit DES encryption, aka the "Protected Store Key Length" vulnerability. 2,5%
CVE-2022-30209 HIGH 7.4 microsoft windows_10 Windows IIS Server Elevation of Privilege Vulnerability 2,5%
CVE-2017-2315 HIGH 7.5 juniper junos On Juniper Networks EX Series Ethernet Switches running affected Junos OS versions, a vulnerability in IPv6 processing has been discovered that may allow a specially crafted IPv6 Neighbor Discovery (ND) packet destined to an EX Series Ethernet Switch to cause 2,5%
CVE-2022-26910 MED 5.3 microsoft skype_for_business_server Skype for Business and Lync Spoofing Vulnerability 2,5%
CVE-2018-17186 HIGH 7.2 apache syncope An administrator with workflow definition entitlements can use DTD to perform malicious operations, including but not limited to file read, file write, and code execution. 2,5%
CVE-2015-4223 MED 5.0 cisco ios_xr Cisco IOS XR 5.1.3 allows remote attackers to cause a denial of service (process reload) via crafted MPLS Label Distribution Protocol (LDP) packets, aka Bug ID CSCuu77478. 2,5%
CVE-2013-0149 MED 5.8 cisco asa_5500 The OSPF implementation in Cisco IOS 12.0 through 12.4 and 15.0 through 15.3, IOS-XE 2.x through 3.9.xS, ASA and PIX 7.x through 9.1, FWSM, NX-OS, and StarOS before 14.0.50488 does not properly validate Link State Advertisement (LSA) type 1 packets before perf 2,5%
CVE-2022-33638 HIGH 8.3 microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 2,5%
CVE-2020-9696 MED 5.5 adobe acrobat_dc Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have a security bypass vulnerability. Successful exploitation could lead to security feature bypass. 2,5%
CVE-2016-6407 HIGH 7.5 cisco web_security_appliance Cisco AsyncOS through 9.5.0-444 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (link saturation) by making many HTTP requests for overlapping byte ranges simultaneously, aka Bug ID CSCuz27219. 2,5%
CVE-2021-42723 HIGH 7.8 adobe premiere_pro Adobe Bridge version 11.1.1 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted SGI file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute c 2,5%
CVE-2019-0993 MED 4.2 microsoft chakracore A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context 2,5%
CVE-2019-0991 MED 4.2 microsoft chakracore A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context 2,5%
CVE-2017-11876 HIGH 8.8 microsoft project_server Microsoft Project Server and Microsoft SharePoint Enterprise Server 2016 allow an attacker to use cross-site forgery to read content that they are not authorized to read, use the victim's identity to take actions on the web application on behalf of the victim, 2,5%
CVE-2026-20816 HIGH 7.8 microsoft windows_10_1607 Time-of-check time-of-use (toctou) race condition in Windows Installer allows an authorized attacker to elevate privileges locally. 2,5%