58.507 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.507 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più basso | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2021-44050 | MED 6.5 | broadcom ca_network_flow_analysis CA Network Flow Analysis (NFA) 21.2.1 and earlier contain a SQL injection vulnerability in the NFA web application, due to insufficient input validation, that could potentially allow an authenticated user to access sensitive data. | 0,9% | — |
| CVE-2021-43244 | MED 6.5 | microsoft windows_10 Windows Kernel Information Disclosure Vulnerability | 0,8% | — |
| CVE-2021-43216 | MED 6.5 | microsoft windows_10 Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability | 3,2% | — |
| CVE-2021-42809 | MED 6.5 | thalesgroup sentinel_protection_installer Improper Access Control of Dynamically-Managed Code Resources (DLL) in Thales Sentinel Protection Installer could allow the execution of arbitrary code. | 0,3% | — |
| CVE-2021-42808 | MED 6.5 | thalesgroup sentinel_protection_installer Improper Access Control in Thales Sentinel Protection Installer could allow a local user to escalate privileges. | 0,2% | — |
| CVE-2021-42305 | MED 6.5 | microsoft exchange_server Microsoft Exchange Server Spoofing Vulnerability | 7,9% | — |
| CVE-2021-42293 | MED 6.5 | microsoft 365_apps Microsoft Jet Red Database Engine and Access Connectivity Engine Elevation of Privilege Vulnerability | 2,8% | — |
| CVE-2021-42250 | MED 6.5 | apache superset Improper output neutralization for Logs. A specific Apache Superset HTTP endpoint allowed for an authenticated user to forge log entries or inject malicious content into logs. | 1,8% | — |
| CVE-2021-41973 | MED 6.5 | apache mina In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. The decoder assumed that the HTTP Header begins at the beginning of the buffer and loops if there is more data than expected. Please update M | 4,6% | — |
| CVE-2021-41972 | MED 6.5 | apache superset Apache Superset up to and including 1.3.1 allowed for database connections password leak for authenticated users. This information could be accessed in a non-trivial way. | 1,5% | — |
| CVE-2021-41767 | MED 6.5 | apache guacamole Apache Guacamole 1.3.0 and older may incorrectly include a private tunnel identifier in the non-private details of some REST responses. This may allow an authenticated user who already has permission to access a particular connection to read from or interact w | 1,9% | — |
| CVE-2021-41571 | MED 6.5 | apache pulsar In Apache Pulsar it is possible to access data from BookKeeper that does not belong to the topics accessible by the authenticated user. The Admin API get-message-by-id requires the user to input a topic and a ledger id. The ledger id is a pointer to the data, | 1,7% | — |
| CVE-2021-41350 | MED 6.5 | microsoft exchange_server Microsoft Exchange Server Spoofing Vulnerability | 1,9% | — |
| CVE-2021-41349 | MED 6.5 | microsoft exchange_server Microsoft Exchange Server Spoofing Vulnerability | 93,5% | — |
| CVE-2021-41332 | MED 6.5 | microsoft windows_10 Windows Print Spooler Information Disclosure Vulnerability | 2,7% | — |
| CVE-2021-41026 | MED 6.5 | fortinet fortiweb A relative path traversal in FortiWeb versions 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allow an authenticated attacker to retrieve arbitrary files from the underlying filesystem via specially crafted web requests. | 0,9% | — |
| CVE-2021-40460 | MED 6.5 | microsoft windows_10 Windows Remote Procedure Call Runtime Security Feature Bypass Vulnerability | 1,6% | — |
| CVE-2021-40439 | MED 6.5 | apache openoffice Apache OpenOffice has a dependency on expat software. Versions prior to 2.1.0 were subject to CVE-2013-0340 a "Billion Laughs" entity expansion denial of service attack and exploit via crafted XML files. ODF files consist of a set of XML files. All versions of | 3,9% | — |
| CVE-2021-40120 | MED 6.5 | cisco application_extension_platform A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote attacker with administrative privileges to inject arbitrary commands into the underlying operating system and execute t | 2,0% | — |
| CVE-2021-40111 | MED 6.5 | apache james In Apache James, while fuzzing with Jazzer the IMAP parsing stack, we discover that crafted APPEND and STATUS IMAP command could be used to trigger infinite loops resulting in expensive CPU computations and OutOfMemory exceptions. This can be used for a Denial | 2,1% | — |
| CVE-2021-39856 | MED 6.5 | adobe acrobat Acrobat Reader DC ActiveX Control versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an Information Disclosure vulnerability. An unauthenticated attacker could leverage this vulnerability to obt | 2,4% | — |
| CVE-2021-39855 | MED 6.5 | adobe acrobat Acrobat Reader DC ActiveX Control versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an Information Disclosure vulnerability. An unauthenticated attacker could leverage this vulnerability to obt | 2,4% | — |
| CVE-2021-39532 | MED 6.5 | juniper libslax An issue was discovered in libslax through v0.22.1. A NULL pointer dereference exists in the function slaxLexer() located in slaxlexer.c. It allows an attacker to cause Denial of Service. | 0,9% | — |
| CVE-2021-39235 | MED 6.5 | apache ozone In Apache Ozone before 1.2.0, Ozone Datanode doesn't check the access mode parameter of the block token. Authenticated users with valid READ block token can do any write operation on the same block. | 1,6% | — |
| CVE-2021-39087 | MED 6.5 | ibm sterling_b2b_integrator IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 could allow an authenticated user to obtain sensitive information due to improper permission controls. IBM X-Force ID: 216109. | 0,6% | — |