58.426 CVE seguite
792 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.426 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2021-21501 | HIGH 7.5 | apache servicecomb Improper configuration will cause ServiceComb ServiceCenter Directory Traversal problem in ServcieCenter 1.x.x versions and fixed in 2.0.0. | 4,4% | — |
| CVE-2021-21341 | HIGH 7.5 | apache activemq XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is vulnerability which may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such | 77,8% | — |
| CVE-2021-20442 | HIGH 7.5 | ibm security_verify_bridge IBM Security Verify Bridge contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 196618. | 1,0% | — |
| CVE-2021-20427 | HIGH 7.5 | ibm security_guardium IBM Security Guardium 11.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 196314. | 1,3% | — |
| CVE-2021-20419 | HIGH 7.5 | ibm security_guardium IBM Security Guardium 11.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 196280. | 0,7% | — |
| CVE-2021-20412 | HIGH 7.5 | ibm security_verify_information_queue IBM Security Verify Information Queue 1.0.6 and 1.0.7 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM | 0,9% | — |
| CVE-2021-20400 | HIGH 7.5 | ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.3 and 7.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 196074. | 0,7% | — |
| CVE-2021-20373 | HIGH 7.5 | ibm db2 IBM Db2 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an Information Disclosure when using the LOAD utility as under certain circumstances the LOAD utility does not enforce directory restrictions. IBM X-Force ID: 199521. | 1,5% | — |
| CVE-2021-20354 | HIGH 7.5 | ibm websphere_application_server IBM WebSphere Application Server 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 194883 | 4,1% | — |
| CVE-2021-20337 | HIGH 7.5 | ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.3.0 to 7.3.3 Patch 8 and 7.4.0 to 7.4.3 GA uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 194448. | 0,7% | — |
| CVE-2021-1734 | HIGH 7.5 | microsoft windows_10 Windows Remote Procedure Call Information Disclosure Vulnerability | 3,8% | — |
| CVE-2021-1723 | HIGH 7.5 | fedoraproject fedora ASP.NET Core and Visual Studio Denial of Service Vulnerability | 4,9% | — |
| CVE-2021-1694 | HIGH 7.5 | microsoft windows_10 Windows Update Stack Elevation of Privilege Vulnerability | 3,2% | — |
| CVE-2021-1594 | HIGH 7.5 | cisco identity_services_engine A vulnerability in the REST API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to perform a command injection attack and elevate privileges to root. This vulnerability is due to insufficient input validation for specifi | 1,4% | — |
| CVE-2021-1585 | HIGH 7.5 | cisco adaptive_security_device_manager A vulnerability in the Cisco Adaptive Security Device Manager (ASDM) Launcher could allow an unauthenticated, remote attacker to execute arbitrary code on a user's operating system. This vulnerability is due to a lack of proper signature verification for speci | 20,0% | — |
| CVE-2021-1513 | HIGH 7.5 | cisco catalyst_sd-wan_manager A vulnerability in the vDaemon process of Cisco SD-WAN Software could allow an unauthenticated, remote attacker to cause a device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient handling of malformed packe | 1,5% | — |
| CVE-2021-1511 | HIGH 7.5 | cisco vedge_1000_firmware Multiple vulnerabilities in Cisco SD-WAN vEdge Software could allow an attacker to execute arbitrary code as the root user or cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the Details sec | 1,0% | — |
| CVE-2021-1510 | HIGH 7.5 | cisco vedge_1000_firmware Multiple vulnerabilities in Cisco SD-WAN vEdge Software could allow an attacker to execute arbitrary code as the root user or cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the Details sec | 1,2% | — |
| CVE-2021-1509 | HIGH 7.5 | cisco vedge_1000_firmware Multiple vulnerabilities in Cisco SD-WAN vEdge Software could allow an attacker to execute arbitrary code as the root user or cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the Details sec | 1,2% | — |
| CVE-2021-1437 | HIGH 7.5 | cisco aironet_access_point_software A vulnerability in the FlexConnect Upgrade feature of Cisco Aironet Series Access Points Software could allow an unauthenticated, remote attacker to obtain confidential information from an affected device. This vulnerability is due to an unrestricted Trivial F | 1,5% | — |
| CVE-2021-1431 | HIGH 7.5 | cisco ios_xe A vulnerability in the vDaemon process of Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to cause a device to reload, resulting a denial of service (DoS) condition. This vulnerability is due to insufficient handling of malformed p | 1,6% | — |
| CVE-2021-1297 | HIGH 7.5 | cisco rv160_vpn_router_firmware Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to conduct directory traversal attacks and overwrite certain files that | 3,7% | — |
| CVE-2021-1296 | HIGH 7.5 | cisco rv160_vpn_router_firmware Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to conduct directory traversal attacks and overwrite certain files that | 3,7% | — |
| CVE-2021-1277 | HIGH 7.5 | cisco data_center_network_manager Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) could allow an attacker to spoof a trusted host or construct a man-in-the-middle attack to extract sensitive information or alter certain API requests. These vulnerabilities are due to insuff | 0,4% | — |
| CVE-2021-1276 | HIGH 7.5 | cisco data_center_network_manager Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) could allow an attacker to spoof a trusted host or construct a man-in-the-middle attack to extract sensitive information or alter certain API requests. These vulnerabilities are due to insuff | 0,4% | — |