Database CVE
Archivio delle vulnerabilità note (CVE) con punteggio CVSS, gravità, prodotti e vendor coinvolti. Filtra per anno e severità, collegato ai nostri articoli.
- CVE-2022-23131Critica9.1
In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor, because a user login stored in the session was not verified. Malicious unauthenticated actor may exploit this issue to escalate privileges and gain admin access to Zabbix Frontend. To perform the attack, SAML authentication is required to be enabled and the actor has to know the username of Zabbix user (or use the guest account, which is disabled by default).
- CVE-2022-21919Alta7.0
Windows User Profile Service Elevation of Privilege Vulnerability
- CVE-2022-21882Alta7.0
Win32k Elevation of Privilege Vulnerability
- CVE-2022-22265Media5.0
An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary memory write and code execution.
- CVE-2021-35247Media4.3
Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechanism to perform additional validation and sanitization. Please Note: No downstream affect has been detected as the LDAP servers ignored improper characters. To insure proper input validation is completed in all environments. SolarWinds recommends scheduling an update to the latest version of Serv-U.
- CVE-2021-44168Bassa3.3
A download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3 may allow a local authenticated attacker to download arbitrary files on the device via specially crafted update packages.
- CVE-2021-44207Alta8.1
Acclaim USAHERDS through 7.4.0.1 uses hard-coded credentials.
- CVE-2021-22054Alta7.5
VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 contain an SSRF vulnerability. This issue may allow a malicious actor with network access to UEM to send their requests without authentication and to gain access to sensitive information.
- CVE-2021-1048Alta7.8
In ep_loop_check_proc of eventpoll.c, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-204573007References: Upstream kernel
- CVE-2021-0920Media6.4
In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-196926917References: Upstream kernel
- CVE-2021-43891Alta7.8
Vulnerabilità di esecuzione di codice remoto in Visual Studio Code
- CVE-2021-43890Alta7.1
We have investigated reports of a spoofing vulnerability in AppX installer that affects Microsoft Windows. Microsoft is aware of attacks that attempt to exploit this vulnerability by using specially crafted packages that include the malware family known as Emotet/Trickbot/Bazaloader. An attacker could craft a malicious attachment to be used in phishing campaigns. The attacker would then have to convince the user to open the specially crafted attachment. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Please see the Security Updates table for the link to the updated app. Alternatively you can download and install the Installer using the links provided in the FAQ section. Please see the Mitigations and Workaround sections for important information about steps you can take to protect your system from this vulnerability. December 27 2023 Update: In recent months, Microsoft Threat Intelligence has seen an increase in activity from threat actors leveraging social engineering and phishing techniques to target Windows OS users and utilizing the ms-appinstaller URI scheme. To address this increase in activity, we have updated the App Installer to disable the ms-appinstaller protocol by default and recommend other potential mitigations.
- CVE-2021-43226Alta7.8
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- CVE-2021-45046Critica9.0
It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in an information leak and remote code execution in some environments and local code execution in all environments. Log4j 2.16.0 (Java 8) and 2.12.2 (Java 7) fix this issue by removing support for message lookup patterns and disabling JNDI functionality by default.
- CVE-2021-39935Media6.8
È stato scoperto un problema in GitLab CE/EE che interessa tutte le versioni a partire dalla 10.5 prima della 14.3.6, tutte le versioni a partire dalla 14.4 prima della 14.4.4, tutte le versioni a partire dalla 14.5 prima della 14.5.2. Utenti esterni non autorizzati potevano eseguire richieste lato server tramite l'API CI Lint
- CVE-2021-44515Critica9.8
Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in the wild in December 2021. For Enterprise builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For Enterprise builds 10.1.2128.0 through 10.1.2137.2, upgrade to 10.1.2137.3. For MSP builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For MSP builds 10.1.2128.0 through 10.1.2137.2, upgrade to 10.1.2137.3.
- CVE-2021-44228Critica10.0
Le funzionalità JNDI di Apache Log4j2 dalla 2.0-beta9 alla 2.15.0 (escluse le release di sicurezza 2.12.2, 2.12.3 e 2.3.1) utilizzate nella configurazione, nei messaggi di log e nei parametri non proteggono dagli endpoint LDAP controllati dall'attaccante e da altri endpoint correlati a JNDI. Un attaccante in grado di controllare i messaggi di log o i parametri dei messaggi di log può eseguire codice arbitrario caricato da server LDAP quando la sostituzione message lookup è abilitata. A partire da log4j 2.15.0, questo comportamento è stato disabilitato per impostazione predefinita. Dalla versione 2.16.0 (insieme a 2.12.2, 2.12.3 e 2.3.1), questa funzionalità è stata completamente rimossa. Si noti che questa vulnerabilità è specifica di log4j-core e non interessa log4net, log4cxx o altri progetti Apache Logging Services.
- CVE-2021-44529Critica9.8
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).
- CVE-2021-27860Critica9.8
A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p92 and 10.2.2r44p1 allows a remote, unauthenticated attacker to upload a file to any location on the filesystem. The FatPipe advisory identifier for this vulnerability is FPSA006.
- CVE-2021-20038Critica9.8
A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthenticated attacker to potentially execute code as a 'nobody' user in the appliance. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances firmware 10.2.0.8-37sv, 10.2.1.1-19sv, 10.2.1.2-24sv and earlier versions.
This product uses the NVD API but is not endorsed or certified by the NVD.