57.479 CVE seguite
782 Sfruttate ora
187 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.479 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più basso | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2021-34517 | MED 5.3 | microsoft sharepoint_foundation Microsoft SharePoint Server Spoofing Vulnerability | 1,9% | — |
| CVE-2021-34451 | MED 5.3 | microsoft office_online_server Microsoft Office Online Server Spoofing Vulnerability | 1,8% | — |
| CVE-2021-34426 | MED 5.3 | keybase keybase A vulnerability was discovered in the Keybase Client for Windows before version 5.6.0 when a user executed the "keybase git lfs-config" command on the command-line. In versions prior to 5.6.0, a malicious actor with write access to a user\'s Git repository cou | 0,2% | — |
| CVE-2021-33757 | MED 5.3 | microsoft windows_10 Windows Security Account Manager Remote Protocol Security Feature Bypass Vulnerability | 3,4% | — |
| CVE-2021-33744 | MED 5.3 | microsoft windows_10 Windows Secure Kernel Mode Security Feature Bypass Vulnerability | 0,8% | — |
| CVE-2021-33190 | MED 5.3 | apache apisix_dashboard In Apache APISIX Dashboard version 2.6, we changed the default value of listen host to 0.0.0.0 in order to facilitate users to configure external network access. In the IP allowed list restriction, a risky function was used for the IP acquisition, which made i | 2,7% | — |
| CVE-2021-33037 | MED 5.3 | apache tomcat Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specifically: - To | 75,4% | — |
| CVE-2021-32785 | MED 5.3 | debian debian_linux mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. When mod_auth_openidc versions prior to 2.4.9 are configured t | 2,7% | — |
| CVE-2021-32591 | MED 5.3 | fortinet fortiadc A missing cryptographic steps vulnerability in the function that encrypts users' LDAP and RADIUS credentials in FortiSandbox before 4.0.1, FortiWeb before 6.3.12, FortiADC before 6.2.1, FortiMail 7.0.1 and earlier may allow an attacker in possession of the pas | 0,9% | — |
| CVE-2021-32584 | MED 5.3 | fortinet fortiwlc An improper access control (CWE-284) vulnerability in FortiWLC version 8.6.0, version 8.5.3 and below, version 8.4.8 and below, version 8.3.3 and below, version 8.2.7 to 8.2.4, version 8.1.3 may allow an unauthenticated and remote attacker to access certain ar | 0,6% | — |
| CVE-2021-31386 | MED 5.3 | juniper junos A Protection Mechanism Failure vulnerability in the J-Web HTTP service of Juniper Networks Junos OS allows a remote unauthenticated attacker to perform Person-in-the-Middle (PitM) attacks against the device. This issue affects: Juniper Networks Junos OS 12.3 v | 0,7% | — |
| CVE-2021-31380 | MED 5.3 | juniper session_and_resource_control A configuration weakness in the JBoss Application Server (AppSvr) component of Juniper Networks SRC Series allows a remote attacker to send a specially crafted query to cause the web server to disclose sensitive information in the HTTP response which allows th | 1,1% | — |
| CVE-2021-31371 | MED 5.3 | juniper junos Juniper Networks Junos OS uses the 128.0.0.0/2 subnet for internal communications between the RE and PFEs. It was discovered that packets utilizing these IP addresses may egress an QFX5000 Series switch, leaking configuration information such as heartbeats, ke | 0,8% | — |
| CVE-2021-31369 | MED 5.3 | juniper junos On MX Series platforms with MS-MPC/MS-MIC, an Allocation of Resources Without Limits or Throttling vulnerability in Juniper Networks Junos OS allows an unauthenticated network attacker to cause a partial Denial of Service (DoS) with a high rate of specific tra | 1,0% | — |
| CVE-2021-31361 | MED 5.3 | juniper junos An Improper Check for Unusual or Exceptional Conditions vulnerability combined with Improper Handling of Exceptional Conditions in Juniper Networks Junos OS on QFX Series and PTX Series allows an unauthenticated network based attacker to cause increased FPC CP | 1,0% | — |
| CVE-2021-31352 | MED 5.3 | juniper session_and_resource_control An Information Exposure vulnerability in Juniper Networks SRC Series devices configured for NETCONF over SSH permits the negotiation of weak ciphers, which could allow a remote attacker to obtain sensitive information. A remote attacker with read and write acc | 0,8% | — |
| CVE-2021-31173 | MED 5.3 | microsoft sharepoint_foundation Microsoft SharePoint Server Information Disclosure Vulnerability | 2,1% | — |
| CVE-2021-30641 | MED 5.3 | apache http_server Apache HTTP Server versions 2.4.39 to 2.4.46 Unexpected matching behavior with 'MergeSlashes OFF' | 52,6% | — |
| CVE-2021-29767 | MED 5.3 | ibm i2_analysts_notebook IBM i2 Analyst's Notebook Premium 9.2.0, 9.2.1, and 9.2.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IB | 1,3% | — |
| CVE-2021-29766 | MED 5.3 | ibm i2_analyze IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks again | 1,3% | — |
| CVE-2021-29687 | MED 5.3 | ibm security_identity_manager IBM Security Identity Manager 7.0.2 could allow a remote user to enumerate usernames due to a difference of responses from valid and invalid login attempts. IBM X-Force ID: 200018 | 1,3% | — |
| CVE-2021-29682 | MED 5.3 | ibm security_identity_manager IBM Security Identity Manager 7.0.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 199997 | 1,3% | — |
| CVE-2021-29681 | MED 5.3 | ibm infosphere_information_server IBM InfoSphere Information Server 11.7 could allow an attacker to obtain sensitive information by injecting parameters into an HTML query. This information could be used in further attacks against the system. IBM X-Force ID: 199918. | 0,9% | — |
| CVE-2021-29621 | MED 5.3 | apache airflow Flask-AppBuilder is a development framework, built on top of Flask. User enumeration in database authentication in Flask-AppBuilder <= 3.2.3. Allows for a non authenticated user to enumerate existing accounts by timing the response time from the server when yo | 3,4% | — |
| CVE-2021-28559 | MED 5.3 | adobe acrobat Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by an Information Exposure vulnerability. An unauthenticated attacker could leverage this vulnerability to get access t | 1,6% | — |