58.450 CVE seguite
792 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.450 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più basso | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2022-21820 | MED 6.3 | nvidia data_center_gpu_manager NVIDIA DCGM contains a vulnerability in nvhostengine, where a network user can cause detection of error conditions without action, which may lead to limited code execution, some denial of service, escalation of privileges, and limited impacts to both data conf | 16,5% | — |
| CVE-2022-20964 | MED 6.3 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to inject arbitrary commands on the underlying operating system. This vulnerability is due to improper validation of user i | 30,6% | — |
| CVE-2022-20926 | MED 6.3 | cisco secure_firewall_management_center A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. The vulnerability is due to insufficient | 0,9% | — |
| CVE-2022-20925 | MED 6.3 | cisco secure_firewall_management_center A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. The vulnerability is due to insufficient | 0,9% | — |
| CVE-2022-20871 | MED 6.3 | cisco asyncos A vulnerability in the web management interface of Cisco AsyncOS for Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow an authenticated, remote attacker to perform a command injection and elevate privilege | 1,9% | — |
| CVE-2022-1280 | MED 6.3 | linux linux_kernel A use-after-free vulnerability was found in drm_lease_held in drivers/gpu/drm/drm_lease.c in the Linux kernel due to a race problem. This flaw allows a local user privilege attacker to cause a denial of service (DoS) or a kernel information leak. | 0,3% | — |
| CVE-2021-47267 | MED 6.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: usb: fix various gadget panics on 10gbps cabling usb_assign_descriptors() is called with 5 parameters, the last 4 of which are the usb_descriptor_header for: full-speed (USB1.1 - 12Mbps [i | 0,7% | — |
| CVE-2021-43076 | MED 6.3 | fortinet fortiadc An improper privilege management vulnerability [CWE-269] in FortiADC versions 6.2.1 and below, 6.1.5 and below, 6.0.4 and below, 5.4.5 and below and 5.3.7 and below may allow a remote authenticated attacker with restricted user profile to modify the system fil | 0,5% | — |
| CVE-2021-41032 | MED 6.3 | fortinet fortios An improper access control vulnerability [CWE-284] in FortiOS versions 6.4.8 and prior and 7.0.3 and prior may allow an authenticated attacker with a restricted user profile to gather sensitive information and modify the SSL-VPN tunnel status of other VDOMs us | 0,6% | — |
| CVE-2021-40830 | MED 6.3 | amazon amazon_web_services_aws-c-io The AWS IoT Device SDK v2 for Java, Python, C++ and Node.js appends a user supplied Certificate Authority (CA) to the root CAs instead of overriding it on Unix systems. TLS handshakes will thus succeed if the peer can be verified either from the user-supplied | 0,4% | — |
| CVE-2021-40828 | MED 6.3 | amazon amazon_web_services_aws-c-io Connections initialized by the AWS IoT Device SDK v2 for Java (versions prior to 1.3.3), Python (versions prior to 1.5.18), C++ (versions prior to 1.12.7) and Node.js (versions prior to 1.5.1) did not verify server certificate hostname during TLS handshake whe | 0,4% | — |
| CVE-2021-40448 | MED 6.3 | microsoft accessibility_insights_for_android Microsoft Accessibility Insights for Android Information Disclosure Vulnerability | 3,2% | — |
| CVE-2021-36929 | MED 6.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | 3,2% | — |
| CVE-2021-35221 | MED 6.3 | solarwinds orion_platform Improper Access Control Tampering Vulnerability using ImportAlert function which can lead to a Remote Code Execution (RCE) from the Alerts Settings page. | 2,0% | — |
| CVE-2021-34500 | MED 6.3 | microsoft windows_10 Windows Kernel Memory Information Disclosure Vulnerability | 2,6% | — |
| CVE-2021-33755 | MED 6.3 | microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability | 3,1% | — |
| CVE-2021-26107 | MED 6.3 | fortinet fortimanager An improper access control vulnerability [CWE-284] in FortiManager versions 6.4.4 and 6.4.5 may allow an authenticated attacker with a restricted user profile to modify the VPN tunnel status of other VDOMs using VPN Manager. | 0,5% | — |
| CVE-2021-26103 | MED 6.3 | fortinet fortios An insufficient verification of data authenticity vulnerability (CWE-345) in the user interface of FortiProxy verison 2.0.3 and below, 1.2.11 and below and FortiGate verison 7.0.0, 6.4.6 and below, 6.2.9 and below of SSL VPN portal may allow a remote, unauthen | 0,4% | — |
| CVE-2021-24011 | MED 6.3 | fortinet fortinac A privilege escalation vulnerability in FortiNAC version below 8.8.2 may allow an admin user to escalate the privileges to root by abusing the sudo privileges. | 0,8% | — |
| CVE-2021-24006 | MED 6.3 | fortinet fortimanager An improper access control vulnerability in FortiManager versions 6.4.0 to 6.4.3 may allow an authenticated attacker with a restricted user profile to access the SD-WAN Orchestrator panel via directly visiting its URL. | 1,0% | — |
| CVE-2021-22125 | MED 6.3 | fortinet fortisandbox An instance of improper neutralization of special elements in the sniffer module of FortiSandbox before 3.2.2 may allow an authenticated administrator to execute commands on the underlying system's shell via altering the content of its configuration file. | 1,4% | — |
| CVE-2021-21384 | MED 6.3 | shescape_project shescape shescape is a simple shell escape package for JavaScript. In shescape before version 1.1.3, anyone using _Shescape_ to defend against shell injection may still be vulnerable against shell injection if the attacker manages to insert a into the payload. For an e | 0,6% | — |
| CVE-2021-1518 | MED 6.3 | cisco firepower_device_manager_on-box A vulnerability in the REST API of Cisco Firepower Device Manager (FDM) On-Box Software could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system of an affected device. This vulnerability is due to insufficient | 1,9% | — |
| CVE-2021-1415 | MED 6.3 | cisco rv340_firmware Multiple vulnerabilities in the web-based management interface of Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an authenticated, remote attacker to execute arbitrary code with elevated privileges equivalent to the web service | 1,6% | — |
| CVE-2021-1414 | MED 6.3 | cisco rv340_firmware Multiple vulnerabilities in the web-based management interface of Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an authenticated, remote attacker to execute arbitrary code with elevated privileges equivalent to the web service | 1,9% | — |