57.924 CVE seguite
784 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.924 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2022-31705 | HIGH 8.2 | vmware esxi VMware ESXi, Workstation, and Fusion contain a heap out-of-bounds write vulnerability in the USB 2.0 controller (EHCI). A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's | 1,6% | — |
| CVE-2022-30196 | HIGH 8.2 | microsoft windows_10 Windows Secure Channel Denial of Service Vulnerability | 2,1% | — |
| CVE-2022-26932 | HIGH 8.2 | microsoft windows_server Storage Spaces Direct Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2022-22239 | HIGH 8.2 | juniper junos_os_evolved An Execution with Unnecessary Privileges vulnerability in Management Daemon (mgd) of Juniper Networks Junos OS Evolved allows a locally authenticated attacker with low privileges to escalate their privileges on the device and potentially remote systems. This v | 0,2% | — |
| CVE-2022-21978 | HIGH 8.2 | microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability | 0,8% | — |
| CVE-2022-1012 | HIGH 8.2 | linux linux_kernel A memory leak problem was found in the TCP source port generation algorithm in net/ipv4/tcp.c due to the small table perturb size. This flaw may allow an attacker to information leak and may cause a denial of service problem. | 3,9% | — |
| CVE-2021-47245 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: synproxy: Fix out of bounds when parsing TCP options The TCP option parser in synproxy (synproxy_parse_options) could read one byte out of bounds. When the length is 1, the execut | 0,8% | — |
| CVE-2021-47244 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mptcp: Fix out of bounds when parsing TCP options The TCP option parser in mptcp (mptcp_get_options) could read one byte out of bounds. When the length is 1, the execution flow gets into the | 0,7% | — |
| CVE-2021-47023 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: marvell: prestera: fix port event handling on init For some reason there might be a crash during ports creation if port events are handling at the same time because fw may send initial | 0,8% | — |
| CVE-2021-46955 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: openvswitch: fix stack OOB read while fragmenting IPv4 packets running openvswitch on kernels built with KASAN, it's possible to see the following splat while testing fragmentation of IPv4 p | 0,7% | — |
| CVE-2021-44224 | HIGH 8.2 | apache http_server A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy declarations, can allow for requests to be directed to a declared Unix Domain Sock | 82,3% | — |
| CVE-2021-44169 | HIGH 8.2 | fortinet forticlient A improper initialization in Fortinet FortiClient (Windows) version 6.0.10 and below, version 6.2.9 and below, version 6.4.7 and below, version 7.0.3 and below allows attacker to gain administrative privileges via placing a malicious executable inside the Fort | 0,4% | — |
| CVE-2021-41028 | HIGH 8.2 | fortinet forticlient A combination of a use of hard-coded cryptographic key vulnerability [CWE-321] in FortiClientEMS 7.0.1 and below, 6.4.6 and below and an improper certificate validation vulnerability [CWE-297] in FortiClientWindows, FortiClientLinux and FortiClientMac 7.0.1 an | 0,2% | — |
| CVE-2021-37713 | HIGH 8.2 | npmjs tar The npm package "tar" (aka node-tar) before versions 4.4.18, 5.0.10, and 6.1.9 has an arbitrary file creation/overwrite and arbitrary code execution vulnerability. node-tar aims to guarantee that any file whose location would be outside of the extraction targe | 1,3% | — |
| CVE-2021-37712 | HIGH 8.2 | debian debian_linux The npm package "tar" (aka node-tar) before versions 4.4.18, 5.0.10, and 6.1.9 has an arbitrary file creation/overwrite and arbitrary code execution vulnerability. node-tar aims to guarantee that any file whose location would be modified by a symbolic link is | 1,8% | — |
| CVE-2021-34469 | HIGH 8.2 | microsoft 365_apps Microsoft Office Security Feature Bypass Vulnerability | 3,7% | — |
| CVE-2021-33767 | HIGH 8.2 | microsoft open_enclave_software_development_kit Open Enclave SDK Elevation of Privilege Vulnerability | 0,9% | — |
| CVE-2021-33741 | HIGH 8.2 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 2,7% | — |
| CVE-2021-31937 | HIGH 8.2 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 0,9% | — |
| CVE-2021-31844 | HIGH 8.2 | mcafee data_loss_prevention_endpoint A buffer overflow vulnerability in McAfee Data Loss Prevention (DLP) Endpoint for Windows prior to 11.6.200 allows a local attacker to execute arbitrary code with elevated privileges through placing carefully constructed Ami Pro (.sam) files onto the local sys | 0,4% | — |
| CVE-2021-23175 | HIGH 8.2 | nvidia geforce_experience NVIDIA GeForce Experience contains a vulnerability in user authorization, where GameStream does not correctly apply individual user access controls for users on the same device, which, with user intervention, may lead to escalation of privileges, information d | 0,4% | — |
| CVE-2021-23012 | HIGH 8.2 | f5 big-ip_access_policy_manager On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, 14.1.x before 14.1.4, and 13.1.x before 13.1.4, lack of input validation for items used in the system support functionality may allow users granted either "Resource Administrator" or "Administrat | 0,3% | — |
| CVE-2021-21045 | HIGH 8.2 | adobe acrobat Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by an improper access control vulnerability. An unauthenticated attacker could leverage this vulnerability to elevate p | 1,8% | — |
| CVE-2021-1602 | HIGH 8.2 | cisco small_business_rv_series_router_firmware A vulnerability in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected d | 2,0% | — |
| CVE-2020-4949 | HIGH 8.2 | ibm websphere_application_server IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM | 4,8% | — |