56.855 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.855 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più basso | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2020-3246 | MED 4.3 | cisco umbrella A vulnerability in the web server of Cisco Umbrella could allow an unauthenticated, remote attacker to perform a carriage return line feed (CRLF) injection attack against a user of an affected service. The vulnerability is due to insufficient validation of use | 0,9% | — |
| CVE-2020-3222 | MED 4.3 | cisco ios_xe A vulnerability in the web-based user interface (web UI) of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to bypass access control restrictions on an affected device. The vulnerability is due to the presence of a proxy service at a sp | 0,4% | — |
| CVE-2020-3182 | MED 4.3 | cisco webex_meetings A vulnerability in the multicast DNS (mDNS) protocol configuration of Cisco Webex Meetings Client for MacOS could allow an unauthenticated adjacent attacker to obtain sensitive information about the device on which the Webex client is running. The vulnerabilit | 0,5% | — |
| CVE-2020-29605 | MED 4.3 | mantisbt mantisbt An issue was discovered in MantisBT before 2.24.4. Due to insufficient access-level checks, any logged-in user allowed to perform Group Actions can get access to the Summary fields of private Issues via bug_arr[]= in a crafted bug_actiongroup_page.php URL. (Th | 0,9% | — |
| CVE-2020-29603 | MED 4.3 | mantisbt mantisbt In manage_proj_edit_page.php in MantisBT before 2.24.4, any unprivileged logged-in user can retrieve Private Projects' names via the manage_proj_edit_page.php project_id parameter, without having access to them. | 1,0% | — |
| CVE-2020-27725 | MED 4.3 | f5 big-ip_domain_name_system In version 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2 of BIG-IP DNS, GTM, and Link Controller, zxfrd leaks memory when listing DNS zones. Zones can be listed via TMSH, iControl or SNMP; only users with access to those | 0,8% | — |
| CVE-2020-27121 | MED 4.3 | cisco unified_communications_manager_im_and_presence_service A vulnerability in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) Software could allow an authenticated, remote attacker to cause the Cisco XCP Authentication Service on an affected device to restart, resulting in a denial | 1,2% | — |
| CVE-2020-26086 | MED 4.3 | cisco telepresence_collaboration_endpoint A vulnerability in the video endpoint API (xAPI) of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, remote attacker to gain access to sensitive information on an affected device. The vulnerability is due to improper storag | 0,8% | — |
| CVE-2020-26077 | MED 4.3 | cisco iot_field_network_director A vulnerability in the access control functionality of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to view lists of users from different domains that are configured on an affected system. The vulnerability is due to imp | 0,8% | — |
| CVE-2020-25774 | MED 4.3 | trendmicro apex_one A vulnerability in the Trend Micro Apex One ServerMigrationTool component could allow an attacker to trigger an out-of-bounds red information disclosure which would disclose sensitive information to an unprivileged account. User interaction is required to expl | 2,1% | — |
| CVE-2020-17153 | MED 4.3 | microsoft edge Microsoft Edge for Android Spoofing Vulnerability | 2,1% | — |
| CVE-2020-17015 | MED 4.3 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability | 2,0% | — |
| CVE-2020-15942 | MED 4.3 | fortinet fortiweb An information disclosure vulnerability in Web Vulnerability Scan profile of Fortinet's FortiWeb version 6.2.x below 6.2.4 and version 6.3.x below 6.3.5 may allow a remote authenticated attacker to read the password used by the FortiWeb scanner to access the d | 0,9% | — |
| CVE-2020-15939 | MED 4.3 | fortinet fortisandbox An improper access control vulnerability (CWE-284) in FortiSandbox versions 3.2.1 and below and 3.1.4 and below may allow an authenticated, unprivileged attacker to download the device configuration file via the recovery URL. | 0,6% | — |
| CVE-2020-15935 | MED 4.3 | fortinet fortiadc A cleartext storage of sensitive information in GUI in FortiADC versions 5.4.3 and below, 6.0.0 and below may allow a remote authenticated attacker to retrieve some sensitive information such as users LDAP passwords and RADIUS shared secret by deobfuscating th | 0,5% | — |
| CVE-2020-1462 | MED 4.3 | microsoft edge An information disclosure vulnerability exists when Skype for Business is accessed via Microsoft Edge (EdgeHTML-based), aka 'Skype for Business via Microsoft Edge (EdgeHTML-based) Information Disclosure Vulnerability'. | 4,2% | — |
| CVE-2020-1444 | MED 4.3 | microsoft sharepoint_enterprise_server A remote code execution vulnerability exists in the way Microsoft SharePoint software parses specially crafted email messages, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. | 9,1% | — |
| CVE-2020-1432 | MED 4.3 | microsoft internet_explorer An information disclosure vulnerability exists when Skype for Business is accessed via Internet Explorer, aka 'Skype for Business via Internet Explorer Information Disclosure Vulnerability'. | 4,5% | — |
| CVE-2020-13943 | MED 4.3 | apache tomcat If an HTTP/2 client connecting to Apache Tomcat 10.0.0-M1 to 10.0.0-M7, 9.0.0.M1 to 9.0.37 or 8.5.0 to 8.5.57 exceeded the agreed maximum number of concurrent streams for a connection (in violation of the HTTP/2 protocol), it was possible that a subsequent req | 57,3% | — |
| CVE-2020-1259 | MED 4.3 | microsoft windows_10 A security feature bypass vulnerability exists when Windows Host Guardian Service improperly handles hashes recorded and logged, aka 'Windows Host Guardian Service Security Feature Bypass Vulnerability'. | 3,1% | — |
| CVE-2020-1229 | MED 4.3 | microsoft 365_apps A security feature bypass vulnerability exists in Microsoft Outlook when Office fails to enforce security settings configured on a system, aka 'Microsoft Outlook Security Feature Bypass Vulnerability'. | 3,8% | — |
| CVE-2020-11997 | MED 4.3 | apache guacamole Apache Guacamole 1.2.0 and earlier do not consistently restrict access to connection history based on user visibility. If multiple users share access to the same connection, those users may be able to see which other users have accessed that connection, as wel | 1,2% | — |
| CVE-2020-11609 | MED 4.3 | canonical ubuntu_linux An issue was discovered in the stv06xx subsystem in the Linux kernel before 5.6.1. drivers/media/usb/gspca/stv06xx/stv06xx.c and drivers/media/usb/gspca/stv06xx/stv06xx_pb0100.c mishandle invalid descriptors, as demonstrated by a NULL pointer dereference, aka | 0,6% | — |
| CVE-2020-11608 | MED 4.3 | canonical ubuntu_linux An issue was discovered in the Linux kernel before 5.6.1. drivers/media/usb/gspca/ov519.c allows NULL pointer dereferences in ov511_mode_init_regs and ov518_mode_init_regs when there are zero endpoints, aka CID-998912346c0d. | 0,5% | — |
| CVE-2020-10659 | MED 4.3 | entrustdatacard entelligence_security_provider Entrust Entelligence Security Provider (ESP) before 10.0.60 on Windows mishandles errors during SSL Certificate Validation, leading to situations where (for example) a user continues to interact with a web site that has an invalid certificate chain. | 0,4% | — |