EN
57.971 CVE seguite
784 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

57.971 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordinato dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2021-31980 HIGH 8.1 microsoft intune_management_extension Microsoft Intune Management Extension Remote Code Execution Vulnerability 2,5%
CVE-2021-3062 HIGH 8.1 paloaltonetworks pan-os An improper access control vulnerability in PAN-OS software enables an attacker with authenticated access to GlobalProtect portals and gateways to connect to the EC2 instance metadata endpoint for VM-Series firewalls hosted on Amazon AWS. Exploitation of this 0,7%
CVE-2021-3060 HIGH 8.1 paloaltonetworks pan-os An OS command injection vulnerability in the Simple Certificate Enrollment Protocol (SCEP) feature of PAN-OS software allows an unauthenticated network-based attacker with specific knowledge of the firewall configuration to execute arbitrary code with root use 33,9%
CVE-2021-3059 HIGH 8.1 paloaltonetworks pan-os An OS command injection vulnerability in the Palo Alto Networks PAN-OS management interface exists when performing dynamic updates. This vulnerability enables a man-in-the-middle attacker to execute arbitrary OS commands to escalate privileges. This issue impa 1,5%
CVE-2021-3057 HIGH 8.1 paloaltonetworks globalprotect A stack-based buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect app that enables a man-in-the-middle attacker to disrupt system processes and potentially execute arbitrary code with SYSTEM privileges. This issue impacts: GlobalProtec 1,4%
CVE-2021-3051 HIGH 8.1 paloaltonetworks cortex_xsoar An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR SAML authentication that enables an unauthenticated network-based attacker with specific knowledge of the Cortex XSOAR instance to access protected resources and perform u 0,6%
CVE-2021-29986 HIGH 8.1 mozilla firefox A suspected race condition when calling getaddrinfo led to memory corruption and a potentially exploitable crash. *Note: This issue only affected Linux operating systems. Other operating systems are unaffected.* This vulnerability affects Thunderbird < 78.13, 1,3%
CVE-2021-29968 HIGH 8.1 mozilla firefox When drawing text onto a canvas with WebRender disabled, an out of bounds read could occur. *This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 89.0.1. 0,8%
CVE-2021-29644 HIGH 8.1 hitachi it_operations_director Hitachi JP1/IT Desktop Management 2 Agent 9 through 12 contains a remote code execution vulnerability because of an Integer Overflow. An attacker with network access to port 31016 may exploit this issue to execute code with unrestricted privileges on the under 2,5%
CVE-2021-28545 HIGH 8.1 adobe acrobat Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are missing support for an integrity check. An unauthenticated attacker would have the ability to completely manipulate data in a ce 2,3%
CVE-2021-28460 HIGH 8.1 microsoft azure_sphere Azure Sphere Unsigned Code Execution Vulnerability 0,5%
CVE-2021-28445 HIGH 8.1 microsoft windows_10 Windows Network File System Remote Code Execution Vulnerability 2,7%
CVE-2021-26701 HIGH 8.1 fedoraproject fedora .NET Core Remote Code Execution Vulnerability 30,1%
CVE-2021-26639 HIGH 8.1 wisa smart_wing_cms This vulnerability is caused by the lack of validation of input values for specific functions if WISA Smart Wing CMS. Remote attackers can use this vulnerability to leak all files in the server without logging in system. 0,5%
CVE-2021-26626 HIGH 8.1 tobesoft xplatform Improper input validation vulnerability in XPLATFORM's execBrowser method can cause execute arbitrary commands. IF the second parameter value of the execBrowser function is ‘default’, the first parameter value could be passed to the ShellExecuteW API. The pass 1,3%
CVE-2021-26617 HIGH 8.1 firstmall firstmall This issues due to insufficient verification of the various input values from user’s input. The vulnerability allows remote attackers to execute malicious code in Firstmall via navercheckout_add function. 1,3%
CVE-2021-26613 HIGH 8.1 tobesoft nexacro improper input validation vulnerability in nexacro permits copying file to the startup folder using rename method. 0,8%
CVE-2021-26612 HIGH 8.1 tobesoft nexacro An improper input validation leading to arbitrary file creation was discovered in copy method of Nexacro platform. Remote attackers use copy method to execute arbitrary command after the file creation included malicious code. 1,2%
CVE-2021-26607 HIGH 8.1 tobesoft nexacro An Improper input validation in execDefaultBrowser method of NEXACRO17 allows a remote attacker to execute arbitrary command on affected systems. 1,9%
CVE-2021-26435 HIGH 8.1 microsoft windows_10 Windows Scripting Engine Memory Corruption Vulnerability 5,3%
CVE-2021-26112 HIGH 8.1 fortinet fortiwan Multiple stack-based buffer overflow vulnerabilities [CWE-121] both in network daemons and in the command line interpreter of FortiWAN before 4.5.9 may allow an unauthenticated attacker to potentially corrupt control data in memory and execute arbitrary code v 1,7%
CVE-2021-26109 HIGH 8.1 fortinet fortios An integer overflow or wraparound vulnerability in the memory allocator of SSLVPN in FortiOS before 7.0.1 may allow an unauthenticated attacker to corrupt control data on the heap via specifically crafted requests to SSLVPN, resulting in potentially arbitrary 1,8%
CVE-2021-24112 HIGH 8.1 microsoft .net .NET Core Remote Code Execution Vulnerability 3,3%
CVE-2021-24019 HIGH 8.1 fortinet forticlient_endpoint_management_server An insufficient session expiration vulnerability [CWE- 613] in FortiClientEMS versions 6.4.2 and below, 6.2.8 and below may allow an attacker to reuse the unexpired admin user session IDs to gain admin privileges, should the attacker be able to obtain that ses 3,9%
CVE-2021-24010 HIGH 8.1 fortinet fortisandbox Improper limitation of a pathname to a restricted directory vulnerabilities in FortiSandbox 3.2.0 through 3.2.2, and 3.1.0 through 3.1.4 may allow an authenticated user to obtain unauthorized access to files and data via specifially crafted web requests. 0,9%