EN
57.479 CVE seguite
782 Sfruttate ora
187 Usate dai ransomware
Ultima sincronia

CVE Tracker

57.479 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordinato dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2021-39534 HIGH 8.8 juniper libslax An issue was discovered in libslax through v0.22.1. slaxIsCommentStart() in slaxlexer.c has a heap-based buffer overflow. 1,3%
CVE-2021-39533 HIGH 8.8 juniper libslax An issue was discovered in libslax through v0.22.1. slaxLexer() in slaxlexer.c has a heap-based buffer overflow. 1,3%
CVE-2021-39531 HIGH 8.8 juniper libslax An issue was discovered in libslax through v0.22.1. slaxLexer() in slaxlexer.c has a stack-based buffer overflow. 1,3%
CVE-2021-39236 HIGH 8.8 apache ozone In Apache Ozone before 1.2.0, Authenticated users with valid Ozone S3 credentials can create specific OM requests, impersonating any other user. 2,5%
CVE-2021-39232 HIGH 8.8 apache ozone In Apache Ozone versions prior to 1.2.0, certain admin related SCM commands can be executed by any authenticated users, not just by admins. 1,6%
CVE-2021-38666 HIGH 8.8 microsoft windows_10 Remote Desktop Client Remote Code Execution Vulnerability 15,1%
CVE-2021-36970 HIGH 8.8 microsoft windows_10 Windows Print Spooler Spoofing Vulnerability 3,1%
CVE-2021-36965 HIGH 8.8 microsoft windows_10 Windows WLAN AutoConfig Service Remote Code Execution Vulnerability 4,6%
CVE-2021-36954 HIGH 8.8 microsoft windows_10 Windows Bind Filter Driver Elevation of Privilege Vulnerability 0,5%
CVE-2021-36947 HIGH 8.8 microsoft windows_10 Windows Print Spooler Remote Code Execution Vulnerability 7,5%
CVE-2021-36936 HIGH 8.8 microsoft windows_10 Windows Print Spooler Remote Code Execution Vulnerability 7,4%
CVE-2021-36741 HIGH 8.8 trendmicro apex_one An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 allows a remote attached to upload arbitrary files on affected installations. Please note: an attacker must firs 5,0%
CVE-2021-3656 HIGH 8.8 fedoraproject fedora A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due to improper validation of the "virt_ext" 0,7%
CVE-2021-3653 HIGH 8.8 debian debian_linux A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due to improper validation of the "int_ctl" 0,4%
CVE-2021-3626 HIGH 8.8 canonical multipass The Windows version of Multipass before 1.7.0 allowed any local process to connect to the localhost TCP control socket to perform mounts from the operating system to a guest, allowing for privilege escalation. 0,2%
CVE-2021-36194 HIGH 8.8 fortinet fortiweb Multiple stack-based buffer overflows in the API controllers of FortiWeb 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allow an authenticated attacker to achieve arbitrary code execution via specially crafted requests. 1,4%
CVE-2021-36186 HIGH 8.8 fortinet fortiweb A stack-based buffer overflow in Fortinet FortiWeb version 6.4.0, version 6.3.15 and below, 6.2.5 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests 1,6%
CVE-2021-36185 HIGH 8.8 fortinet fortiwlm A improper neutralization of special elements used in an OS command ('OS Command Injection') in Fortinet FortiWLM version 8.6.1 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests. 1,9%
CVE-2021-36184 HIGH 8.8 fortinet fortiwlm A improper neutralization of Special Elements used in an SQL Command ('SQL Injection') in Fortinet FortiWLM version 8.6.1 and below allows attacker to disclosure device, users and database information via crafted HTTP requests. 1,0%
CVE-2021-36182 HIGH 8.8 fortinet fortiweb A Improper neutralization of special elements used in a command ('Command Injection') in Fortinet FortiWeb version 6.3.13 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests 1,9%
CVE-2021-36162 HIGH 8.8 apache dubbo Apache Dubbo supports various rules to support configuration override or traffic routing (called routing in Dubbo). These rules are loaded into the configuration center (eg: Zookeeper, Nacos, ...) and retrieved by the customers when making a request in order t 2,3%
CVE-2021-36004 HIGH 8.8 adobe indesign Adobe InDesign version 16.0 (and earlier) is affected by an Out-of-bounds Write vulnerability in the CoolType library. An unauthenticated attacker could leverage this vulnerability to achieve remote code execution in the context of the current user. Exploitati 2,2%
CVE-2021-34748 HIGH 8.8 cisco intersight_virtual_appliance A vulnerability in the web-based management interface of Cisco Intersight Virtual Appliance could allow an authenticated, remote attacker to perform a command injection attack on an affected device. This vulnerability is due to insufficient input validation. A 2,7%
CVE-2021-34735 HIGH 8.8 cisco ata_190_firmware Multiple vulnerabilities in the Cisco ATA 190 Series Analog Telephone Adapter Software could allow an attacker to perform a command injection attack resulting in remote code execution or cause a denial of service (DoS) condition on an affected device. For more 1,9%
CVE-2021-34710 HIGH 8.8 cisco ata_190_firmware Multiple vulnerabilities in the Cisco ATA 190 Series Analog Telephone Adapter Software could allow an attacker to perform a command injection attack resulting in remote code execution or cause a denial of service (DoS) condition on an affected device. For more 2,6%