57.479 CVE seguite
782 Sfruttate ora
187 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.479 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più basso | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2020-17513 | MED 5.3 | apache airflow In Apache Airflow versions prior to 1.10.13, the Charts and Query View of the old (Flask-admin based) UI were vulnerable for SSRF attack. | 4,3% | — |
| CVE-2020-17120 | MED 5.3 | microsoft sharepoint_foundation Microsoft SharePoint Information Disclosure Vulnerability | 3,1% | — |
| CVE-2020-17090 | MED 5.3 | microsoft windows_10 Microsoft Defender for Endpoint Security Feature Bypass Vulnerability | 3,3% | — |
| CVE-2020-17017 | MED 5.3 | microsoft sharepoint_enterprise_server Microsoft SharePoint Information Disclosure Vulnerability | 3,8% | — |
| CVE-2020-16979 | MED 5.3 | microsoft sharepoint_enterprise_server Microsoft SharePoint Information Disclosure Vulnerability | 3,1% | — |
| CVE-2020-16922 | MED 5.3 | microsoft windows_10 <p>A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could bypass security features and load improperly signed files.</p> <p>In an attack scenario, an attacker could by | 0,8% | — |
| CVE-2020-16904 | MED 5.3 | microsoft azure_functions <p>An elevation of privilege vulnerability exists in the way Azure Functions validate access keys.</p> <p>An unauthenticated attacker who successfully exploited this vulnerability could invoke an HTTP Function without proper authorization.</p> <p>This security | 3,4% | — |
| CVE-2020-16886 | MED 5.3 | microsoft powershellget <p>A security feature bypass vulnerability exists in the PowerShellGet V2 module. An attacker who successfully exploited this vulnerability could bypass WDAC (Windows Defender Application Control) policy and execute arbitrary code on a policy locked-down machi | 0,8% | — |
| CVE-2020-1680 | MED 5.3 | juniper junos On Juniper Networks MX Series with MS-MIC or MS-MPC card configured with NAT64 configuration, receipt of a malformed IPv6 packet may crash the MS-PIC component on MS-MIC or MS-MPC. This issue occurs when a multiservice card is translating the malformed IPv6 pa | 1,3% | — |
| CVE-2020-1665 | MED 5.3 | juniper junos On Juniper Networks MX Series and EX9200 Series, in a certain condition the IPv6 Distributed Denial of Service (DDoS) protection might not take affect when it reaches the threshold condition. The DDoS protection allows the device to continue to function while | 1,3% | — |
| CVE-2020-1661 | MED 5.3 | juniper junos On Juniper Networks Junos OS devices configured as a DHCP forwarder, the Juniper Networks Dynamic Host Configuration Protocol Daemon (jdhcp) process might crash when receiving a malformed DHCP packet. This issue only affects devices configured as DHCP forwarde | 1,0% | — |
| CVE-2020-1655 | MED 5.3 | juniper junos When a device running Juniper Networks Junos OS with MPC7, MPC8, or MPC9 line cards installed and the system is configured for inline IP reassembly, used by L2TP, MAP-E, GRE, and IPIP, the packet forwarding engine (PFE) will become disabled upon receipt of lar | 1,0% | — |
| CVE-2020-1628 | MED 5.3 | juniper junos Juniper Networks Junos OS uses the 128.0.0.0/2 subnet for internal communications between the RE and PFEs. It was discovered that packets utilizing these IP addresses may egress an EX4300 switch, leaking configuration information such as heartbeats, kernel ver | 1,3% | — |
| CVE-2020-1616 | MED 5.3 | juniper advanced_threat_protection Due to insufficient server-side login attempt limit enforcement, a vulnerability in the SSH login service of Juniper Networks Juniper Advanced Threat Prevention (JATP) Series and Virtual JATP (vJATP) devices allows an unauthenticated, remote attacker to perfor | 1,4% | — |
| CVE-2020-1601 | MED 5.3 | juniper junos Certain types of malformed Path Computation Element Protocol (PCEP) packets when received and processed by a Juniper Networks Junos OS device serving as a Path Computation Client (PCC) in a PCEP environment using Juniper's path computational element protocol d | 1,1% | — |
| CVE-2020-15933 | MED 5.3 | fortinet fortimail A exposure of sensitive information to an unauthorized actor in Fortinet FortiMail versions 6.0.9 and below, FortiMail versions 6.2.4 and below FortiMail versions 6.4.1 and 6.4.0 allows attacker to obtain potentially sensitive software-version information via | 0,8% | — |
| CVE-2020-1455 | MED 5.3 | microsoft sql_server_management_studio A denial of service vulnerability exists when Microsoft SQL Server Management Studio (SSMS) improperly handles files. An attacker could exploit the vulnerability to trigger a denial of service. To exploit the vulnerability, an attacker would first require exec | 1,2% | — |
| CVE-2020-1434 | MED 5.3 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Sync Host Service handles objects in memory, aka 'Windows Sync Host Service Elevation of Privilege Vulnerability'. | 0,8% | — |
| CVE-2020-13998 | MED 5.3 | citrix xenapp Citrix XenApp 6.5, when 2FA is enabled, allows a remote unauthenticated attacker to ascertain whether a user exists on the server, because the 2FA error page only occurs after a valid username is entered. NOTE: This vulnerability only affects products that are | 1,4% | — |
| CVE-2020-13956 | MED 5.3 | apache httpclient Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution. | 9,0% | — |
| CVE-2020-13953 | MED 5.3 | apache tapestry In Apache Tapestry from 5.4.0 to 5.5.0, crafting specific URLs, an attacker can download files inside the WEB-INF folder of the WAR being run. | 2,7% | — |
| CVE-2020-13937 | MED 5.3 | apache kylin Apache Kylin 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 3.0.0-alpha, 3.0.0-alpha2, 3.0.0-beta, 3.0.0, 3.0.1, 3.0.2, 3.1.0, 4.0.0-alpha has one restful api which exposed Kylin's | 78,3% | — |
| CVE-2020-13923 | MED 5.3 | apache ofbiz IDOR vulnerability in the order processing feature from ecommerce component of Apache OFBiz before 17.12.04 | 5,0% | — |
| CVE-2020-1315 | MED 5.3 | microsoft internet_explorer An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory, aka 'Internet Explorer Information Disclosure Vulnerability'. | 3,8% | — |
| CVE-2020-12888 | MED 5.3 | canonical ubuntu_linux The VFIO PCI driver in the Linux kernel through 5.6.13 mishandles attempts to access disabled memory space. | 0,4% | — |