57.479 CVE seguite
782 Sfruttate ora
187 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.479 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2021-43075 | HIGH 8.8 | fortinet fortiwlm A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.2 and below, version 8.5.2 and below, version 8.4.2 and below, version 8.3.2 and below allows attacker to execute unauthorized code or | 1,6% | — |
| CVE-2021-43073 | HIGH 8.8 | fortinet fortiweb A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below allows attacker to execute unauthorized code or commands via crafted HT | 1,4% | — |
| CVE-2021-43071 | HIGH 8.8 | fortinet fortiweb A heap-based buffer overflow in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests to the LogReport API controller. | 1,2% | — |
| CVE-2021-42993 | HIGH 8.8 | flexihub flexihub FlexiHub For Windows is affected by Integer Overflow. IOCTL Handler 0x22001B in the FlexiHub For Windows above 2.0.4340 below 5.3.14268 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) | 0,5% | — |
| CVE-2021-42990 | HIGH 8.8 | flexihub flexihub FlexiHub For Windows is affected by Buffer Overflow. IOCTL Handler 0x22001B in the FlexiHub For Windows above 2.0.4340 below 5.3.14268 allows local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) | 0,5% | — |
| CVE-2021-42760 | HIGH 8.8 | fortinet fortiwlm A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.1 and below allows attacker to disclose sensitive information from DB tables via crafted requests. | 0,9% | — |
| CVE-2021-42758 | HIGH 8.8 | fortinet fortiwlc An improper access control vulnerability [CWE-284] in FortiWLC 8.6.1 and below may allow an authenticated and remote attacker with low privileges to execute any command as an admin user with full access rights via bypassing the GUI restrictions. | 2,0% | — |
| CVE-2021-42743 | HIGH 8.8 | splunk splunk A misconfiguration in the node default path allows for local privilege escalation from a lower privileged user to the Splunk user in Splunk Enterprise versions before 8.1.1 on Windows. | 0,2% | — |
| CVE-2021-42321 | HIGH 8.8 | ransomware microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 91,7% | |
| CVE-2021-42316 | HIGH 8.8 | microsoft dynamics_365 Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability | 2,3% | — |
| CVE-2021-42315 | HIGH 8.8 | microsoft defender_for_iot Microsoft Defender for IoT Remote Code Execution Vulnerability | 2,2% | — |
| CVE-2021-42314 | HIGH 8.8 | microsoft defender_for_iot Microsoft Defender for IoT Remote Code Execution Vulnerability | 2,2% | — |
| CVE-2021-42309 | HIGH 8.8 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 2,7% | — |
| CVE-2021-42283 | HIGH 8.8 | microsoft windows_10 NTFS Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2021-42275 | HIGH 8.8 | microsoft windows_10 Microsoft COM for Windows Remote Code Execution Vulnerability | 2,1% | — |
| CVE-2021-4225 | HIGH 8.8 | smartypantsplugins sp_project_\&_document_manager The SP Project & Document Manager WordPress plugin before 4.24 allows any authenticated users, such as subscribers, to upload files. The plugin attempts to prevent PHP and other similar files that could be executed on the server from being uploaded by checking | 1,7% | — |
| CVE-2021-41971 | HIGH 8.8 | apache superset Apache Superset up to and including 1.3.0 when configured with ENABLE_TEMPLATE_PROCESSING on (disabled by default) allowed SQL injection when a malicious authenticated user sends an http request with a custom URL. | 1,8% | — |
| CVE-2021-41635 | HIGH 8.8 | melag ftp_server When installed as Windows service MELAG FTP Server 2.2.0.4 is run as SYSTEM user, which grants remote attackers to abuse misconfigurations or vulnerabilities with administrative access over the entire host system. | 2,1% | — |
| CVE-2021-4154 | HIGH 8.8 | linux linux_kernel A use-after-free flaw was found in cgroup1_parse_param in kernel/cgroup/cgroup-v1.c in the Linux kernel's cgroup v1 parser. A local attacker with a user privilege could cause a privilege escalation by exploiting the fsconfig syscall parameter leading to a cont | 1,2% | — |
| CVE-2021-41365 | HIGH 8.8 | microsoft defender_for_iot Microsoft Defender for IoT Remote Code Execution Vulnerability | 2,7% | — |
| CVE-2021-41020 | HIGH 8.8 | fortinet fortiisolator An improper access control vulnerability [CWE-284] in FortiIsolator versions 2.3.2 and below may allow an authenticated, non privileged attacker to regenerate the CA certificate via the regeneration URL. | 0,6% | — |
| CVE-2021-41018 | HIGH 8.8 | fortinet fortiweb A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests. | 3,3% | — |
| CVE-2021-41017 | HIGH 8.8 | fortinet fortiweb Multiple heap-based buffer overflow vulnerabilities in some web API controllers of FortiWeb 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allow a remote authenticated attacker to execute arbitrary code or commands via specifically crafted HTTP requests. | 1,9% | — |
| CVE-2021-4093 | HIGH 8.8 | canonical ubuntu_linux A flaw was found in the KVM's AMD code for supporting the Secure Encrypted Virtualization-Encrypted State (SEV-ES). A KVM guest using SEV-ES can trigger out-of-bounds reads and writes in the host kernel via a malicious VMGEXIT for a string I/O instruction (for | 0,4% | — |
| CVE-2021-40444 | HIGH 8.8 | ransomware microsoft windows_10_1507 Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to exploit this vulnerability by using specially-crafted Microsoft Office documents. An at | 97,5% |