58.140 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.140 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2024-38233 | HIGH 7.5 | microsoft windows_10_1607 Windows Networking Denial of Service Vulnerability | 2,4% | — |
| CVE-2022-28256 | MED 5.5 | adobe acrobat Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by a use-after-free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to b | 2,4% | — |
| CVE-2022-26784 | MED 6.5 | microsoft windows_server_2012 Windows Cluster Shared Volume (CSV) Denial of Service Vulnerability | 2,4% | — |
| CVE-2022-24538 | MED 6.5 | microsoft windows_server_2012 Windows Cluster Shared Volume (CSV) Denial of Service Vulnerability | 2,4% | — |
| CVE-2022-22038 | HIGH 8.1 | microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability | 2,4% | — |
| CVE-2021-43899 | CRIT 9.8 | microsoft wireless_display_adapter_firmware Microsoft 4K Wireless Display Adapter Remote Code Execution Vulnerability | 2,4% | — |
| CVE-2017-9790 | HIGH 7.5 | apache mesos When handling a libprocess message wrapped in an HTTP request, libprocess in Apache Mesos before 1.1.3, 1.2.x before 1.2.2, 1.3.x before 1.3.1, and 1.4.0-dev crashes if the request path is empty, because the parser assumes the request path always starts with ' | 2,4% | — |
| CVE-2015-2062 | HIGH 7.2 | huge-it huge-it_slider Multiple SQL injection vulnerabilities in the Huge-IT Slider (slider-image) plugin before 2.7.0 for WordPress allow remote administrators to execute arbitrary SQL commands via the removeslide parameter in a popup_posts or edit_cat action in the sliders_huge_it | 2,4% | — |
| CVE-2014-2106 | HIGH 7.8 | cisco ios Cisco IOS 15.3M before 15.3(3)M2 and IOS XE 3.10.xS before 3.10.2S allow remote attackers to cause a denial of service (device reload) via crafted SIP messages, aka Bug ID CSCug45898. | 2,4% | — |
| CVE-2023-36776 | HIGH 7.0 | microsoft windows_10_1507 Win32k Elevation of Privilege Vulnerability | 2,4% | — |
| CVE-2021-40114 | MED 6.8 | cisco secure_firewall_management_center Multiple Cisco products are affected by a vulnerability in the way the Snort detection engine processes ICMP traffic that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is d | 2,4% | — |
| CVE-2019-17657 | HIGH 7.5 | fortinet fortianalyzer An Uncontrolled Resource Consumption vulnerability in Fortinet FortiSwitch below 3.6.11, 6.0.6 and 6.2.2, FortiAnalyzer below 6.2.3, FortiManager below 6.2.3 and FortiAP-S/W2 below 6.2.2 may allow an attacker to cause admin webUI denial of service (DoS) via ha | 2,4% | — |
| CVE-2014-4064 | MED 4.9 | microsoft windows_7 The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly handle use of the paged kernel pool for allocation o | 2,4% | — |
| CVE-2019-1840 | HIGH 8.6 | cisco prime_network_registrar A vulnerability in the DHCPv6 input packet processor of Cisco Prime Network Registrar could allow an unauthenticated, remote attacker to restart the server and cause a denial of service (DoS) condition on the affected system. The vulnerability is due to incomp | 2,4% | — |
| CVE-2019-1837 | MED 5.3 | cisco unified_communications_manager A vulnerability in the User Data Services (UDS) API of Cisco Unified Communications Manager (Unified CM) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the management GUI. The vulnerability is due to improper va | 2,4% | — |
| CVE-2018-8396 | MED 4.7 | microsoft windows_7 An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2. This CVE | 2,4% | — |
| CVE-2015-3108 | MED 5.0 | adobe air Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and | 2,4% | — |
| CVE-2023-2317 | HIGH 8.6 | typora typora DOM-based XSS in updater/update.html in Typora before 1.6.7 on Windows and Linux allows a crafted markdown file to run arbitrary JavaScript code in the context of Typora main window via loading typora://app/typemark/updater/update.html in <embed> tag. This vul | 2,4% | — |
| CVE-2020-1528 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Radio Manager API improperly handles memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted appl | 2,4% | — |
| CVE-2018-17781 | HIGH 7.5 | foxitsoftware phantompdf Foxit PhantomPDF and Reader before 9.3 allow remote attackers to trigger Uninitialized Object Information Disclosure because creation of ArrayBuffer and DataView objects is mishandled. | 2,4% | — |
| CVE-2007-5337 | MED 4.3 | gnome gnome-vfs Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5, when running on Linux systems with gnome-vfs support, might allow remote attackers to read arbitrary files on SSH/sftp servers that accept key authentication by creating a web page on the target server | 2,4% | — |
| CVE-2021-26987 | CRIT 9.8 | netapp element_plug-in_for_vcenter_server Element Plug-in for vCenter Server incorporates SpringBoot Framework. SpringBoot Framework versions prior to 1.3.2 are susceptible to a vulnerability which when successfully exploited could lead to Remote Code Execution. All versions of Element Plug-in for vCe | 2,4% | — |
| CVE-2022-23280 | MED 5.3 | microsoft outlook_2016 Microsoft Outlook for Mac Security Feature Bypass Vulnerability | 2,4% | — |
| CVE-2021-1722 | HIGH 8.1 | microsoft windows_10 Windows Fax Service Remote Code Execution Vulnerability | 2,4% | — |
| CVE-2015-6428 | MED 5.0 | cisco dpq3925_8x4_docsis_3.0_wireless_residential_gateway_with_embedded_digital_voice_adapter Cisco DPQ3925 devices with EDVA r1 Base allow remote attackers to obtain sensitive information via a crafted HTTP request, aka Bug ID CSCuv03958. | 2,4% | — |