58.507 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.507 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più basso | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2021-29951 | MED 6.5 | mozilla firefox The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users which, in a domain network, grants normal remote users access to start or stop the service. This could be used to prevent the browser update service from operating (if an attacker sp | 1,9% | — |
| CVE-2021-29913 | MED 6.5 | ibm security_verify_privilege_on-premises IBM Security Verify Privilege On-Premise 11.5 could allow an authenticated user to obtain sensitive information or perform unauthorized actions due to improper input validation. IBM X-Force ID: 207898. | 0,4% | — |
| CVE-2021-29816 | MED 6.5 | ibm jazz_for_service_management IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: | 0,4% | — |
| CVE-2021-29777 | MED 6.5 | ibm db2 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5, under specific circumstance of a table being dropped while being accessed in another session, could allow an authenticated user to cause a denial of srevice IBM | 1,4% | — |
| CVE-2021-29770 | MED 6.5 | ibm i2_analyze IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) could allow an authenticated user to perform unauthorized actions due to hazardous input validation. IBM X-Force ID: 202771. | 0,6% | — |
| CVE-2021-29683 | MED 6.5 | ibm security_identity_manager IBM Security Identity Manager 7.0.2 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 199998. | 0,5% | — |
| CVE-2021-28715 | MED 6.5 | debian debian_linux Guest can force Linux netback driver to hog large amounts of kernel memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Incoming data packets for a guest in the Linux kernel's | 0,3% | — |
| CVE-2021-28714 | MED 6.5 | debian debian_linux Guest can force Linux netback driver to hog large amounts of kernel memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Incoming data packets for a guest in the Linux kernel's | 0,3% | — |
| CVE-2021-28688 | MED 6.5 | debian debian_linux The fix for XSA-365 includes initialization of pointers such that subsequent cleanup code wouldn't use uninitialized or stale values. This initialization went too far and may under certain conditions also overwrite pointers which are in need of cleaning up. Th | 0,3% | — |
| CVE-2021-28655 | MED 6.5 | apache zeppelin The improper Input Validation vulnerability in "”Move folder to Trash” feature of Apache Zeppelin allows an attacker to delete the arbitrary files. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions. | 1,6% | — |
| CVE-2021-28555 | MED 6.5 | adobe acrobat Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by an Out-of-bounds Read vulnerability. An unauthenticated attacker could leverage this vulnerability to get access to | 2,8% | — |
| CVE-2021-28546 | MED 6.5 | adobe acrobat Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are missing support for an integrity check. An unauthenticated attacker could leverage this vulnerability to modify content in a cer | 1,4% | — |
| CVE-2021-28442 | MED 6.5 | microsoft windows_10 Windows TCP/IP Information Disclosure Vulnerability | 6,5% | — |
| CVE-2021-28441 | MED 6.5 | microsoft windows_10 Windows Hyper-V Information Disclosure Vulnerability | 0,8% | — |
| CVE-2021-28328 | MED 6.5 | microsoft windows_10 Windows DNS Information Disclosure Vulnerability | 2,5% | — |
| CVE-2021-28325 | MED 6.5 | microsoft windows_10 Windows SMB Information Disclosure Vulnerability | 62,1% | — |
| CVE-2021-28323 | MED 6.5 | microsoft windows_10 Windows DNS Information Disclosure Vulnerability | 4,3% | — |
| CVE-2021-28311 | MED 6.5 | microsoft windows_10 Windows Application Compatibility Cache Denial of Service Vulnerability | 2,5% | — |
| CVE-2021-28039 | MED 6.5 | linux linux_kernel An issue was discovered in the Linux kernel 5.9.x through 5.11.3, as used with Xen. In some less-common configurations, an x86 PV guest OS user can crash a Dom0 or driver domain via a large amount of I/O activity. The issue relates to misuse of guest physical | 0,4% | — |
| CVE-2021-28038 | MED 6.5 | debian debian_linux An issue was discovered in the Linux kernel through 5.11.3, as used with Xen PV. A certain part of the netback driver lacks necessary treatment of errors such as failed memory allocations (as a result of changes to the handling of grant mapping errors). A host | 0,7% | — |
| CVE-2021-27067 | MED 6.5 | microsoft azure_devops_server Azure DevOps Server and Team Foundation Server Information Disclosure Vulnerability | 2,6% | — |
| CVE-2021-26920 | MED 6.5 | apache druid In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSource allows authenticated users to read data from other sources than intended, such as the local file system, with the privileges of th | 9,5% | — |
| CVE-2021-26559 | MED 6.5 | apache airflow Improper Access Control on Configurations Endpoint for the Stable API of Apache Airflow allows users with Viewer or User role to get Airflow Configurations including sensitive information even when `[webserver] expose_config` is set to `False` in `airflow.cfg` | 2,8% | — |
| CVE-2021-26421 | MED 6.5 | microsoft lync_server Skype for Business and Lync Spoofing Vulnerability | 1,4% | — |
| CVE-2021-26111 | MED 6.5 | fortinet fortiswitch A missing release of memory after effective lifetime vulnerability in FortiSwitch 6.4.0 to 6.4.6, 6.2.0 to 6.2.6, 6.0.0 to 6.0.6, 3.6.11 and below may allow an attacker on an adjacent network to exhaust available memory by sending specifically crafted LLDP/CDP | 0,4% | — |