EN
58.140 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.140 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più alto In KEV dal, ordina dal più alto
CVE-2022-3724 MED 6.3 wireshark wireshark Crash in the USB HID protocol dissector in Wireshark 3.6.0 to 3.6.8 allows denial of service via packet injection or crafted capture file on Windows 2,5%
CVE-2022-35671 MED 5.5 adobe acrobat Adobe Acrobat Reader versions 22.001.20169 (and earlier), 20.005.30362 (and earlier) and 17.012.30249 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerabi 2,5%
CVE-2021-1586 HIGH 8.6 cisco nx-os A vulnerability in the Multi-Pod or Multi-Site network configurations for Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, remote attacker to unexpectedly restart the device, resulting in 2,5%
CVE-2019-12629 HIGH 7.2 cisco sd-wan_firmware A vulnerability in the WebUI of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject and execute arbitrary commands with vmanage user privileges on an affected system. The vulnerability is due to insufficient input validation of da 2,5%
CVE-2018-3283 MED 4.4 canonical ubuntu_linux Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Logging). Supported versions that are affected are 5.7.23 and prior and 8.0.12 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access 2,5%
CVE-2004-1322 HIGH 7.5 cisco unity_server Cisco Unity 2.x, 3.x, and 4.x, when integrated with Microsoft Exchange, has several hard coded usernames and passwords, which allows remote attackers to gain unauthorized access and change configuration settings or read outgoing or incoming e-mail messages. 2,5%
CVE-2025-59517 HIGH 7.8 microsoft windows_10_1607 Improper access control in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally. 2,5%
CVE-2021-35992 LOW 3.3 adobe bridge Adobe Bridge version 11.0.2 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose sensitive memory information in the context of the cur 2,5%
CVE-2021-35991 LOW 3.3 adobe bridge Adobe Bridge version 11.0.2 (and earlier) is affected by an Access of Uninitialized Pointer vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose arbitrary memory information in the cont 2,5%
CVE-2021-27055 HIGH 7.0 microsoft 365_apps Microsoft Visio Security Feature Bypass Vulnerability 2,5%
CVE-2012-5424 MED 5.0 cisco secure_access_control_server Cisco Secure Access Control System (ACS) 5.x before 5.2 Patch 11 and 5.3 before 5.3 Patch 7, when a certain configuration involving TACACS+ and LDAP is used, does not properly validate passwords, which allows remote attackers to bypass authentication by sendin 2,5%
CVE-2008-1181 MED 5.0 juniper secure_access_2000 Juniper Networks Secure Access 2000 5.5 R1 (build 11711) allows remote attackers to obtain sensitive information via a direct request for remediate.cgi without certain parameters, which reveals the path in an "Execute failed" error message. 2,5%
CVE-2005-4849 MED 5.0 apache derby Apache Derby before 10.1.2.1 exposes the (1) user and (2) password attributes in cleartext via (a) the RDBNAM parameter of the ACCSEC command and (b) the output of the DatabaseMetaData.getURL function, which allows context-dependent attackers to obtain sensiti 2,5%
CVE-2021-34489 HIGH 7.8 microsoft windows_10 DirectWrite Remote Code Execution Vulnerability 2,5%
CVE-2015-0757 MED 5.0 cisco identity_services_engine_software The web framework in Cisco Identity Services Engine (ISE) 1.2(1.901) and 1.3(0.722) does not properly implement session handlers, which allows remote attackers to obtain sensitive information by reading web pages, as demonstrated by MnT reports, aka Bug ID CSC 2,5%
CVE-2009-1168 HIGH 7.1 cisco ios Cisco IOS 12.0(32)S12 through 12.0(32)S13 and 12.0(33)S3 through 12.0(33)S4, 12.0(32)SY8 through 12.0(32)SY9, 12.2(33)SXI1, 12.2XNC before 12.2(33)XNC2, 12.2XND before 12.2(33)XND1, and 12.4(24)T1; and IOS XE 2.3 through 2.3.1t and 2.4 through 2.4.0; when RFC4 2,5%
CVE-2021-26900 HIGH 7.8 microsoft windows_10 Windows Win32k Elevation of Privilege Vulnerability 2,4%
CVE-2024-43521 HIGH 7.5 microsoft windows_server_2012 Windows Hyper-V Denial of Service Vulnerability 2,4%
CVE-2021-34492 HIGH 8.1 microsoft windows_10 Windows Certificate Spoofing Vulnerability 2,4%
CVE-2018-19444 HIGH 7.8 foxitsoftware foxit_pdf_sdk_activex A use after free in the TextBox field Validate action in IReader_ContentProvider can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031. An attacker can leverage this to gain remote code execution. Relative to CVE-2018- 2,4%
CVE-2017-7687 HIGH 7.5 apache mesos When handling a decoding failure for a malformed URL path of an HTTP request, libprocess in Apache Mesos before 1.1.3, 1.2.x before 1.2.2, 1.3.x before 1.3.1, and 1.4.0-dev might crash because the code accidentally calls inappropriate function. A malicious act 2,4%
CVE-2007-3756 MED 4.3 apple safari Safari in Apple iPhone 1.1.1, and Safari 3 before Beta Update 3.0.4 on Windows and Mac OS X 10.4 through 10.4.10, allows remote attackers to obtain sensitive information via a crafted web page that identifies the URL of the parent window, even when the parent 2,4%
CVE-2021-32567 HIGH 7.5 apache traffic_server Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1. 2,4%
CVE-2020-24427 LOW 3.3 adobe acrobat Acrobat Reader versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) are affected by an input validation vulnerability when decoding a crafted codec that could result in the disclosure of sensitive memory. An atta 2,4%
CVE-2019-19770 HIGH 8.2 linux linux_kernel In the Linux kernel 4.19.83, there is a use-after-free (read) in the debugfs_remove function in fs/debugfs/inode.c (which is used to remove a file or directory in debugfs that was previously created with a call to another debugfs function such as debugfs_creat 2,4%