Записи siemens
2 243 опубликованных записей вендора siemens.
Профиль для исследователя
- Попали в KEV
- 29 · 1,3 %
- С эксплойтом
- 38 · 1,7 %
- Pre-auth RCE
- 108
- С записью об исправлении
- 10,1 %
- Медиана: публикация → KEV
- 150 дн.
Повторяющиеся классы
- CWE-787 Out-of-bounds Write189
- CWE-125 Out-of-bounds Read184
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')97
- CWE-20 Improper Input Validation96
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer70
- CWE-122 Heap-based Buffer Overflow70
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
2 243 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
100Срочно | CVE-2021-44228Готовый эксплойт | Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpointsapache · log4j · CWE-20 | Критическая10,0 | KEV | 100,0 % | 10 дек. 2021 г. |
99Срочно | CVE-2019-0708Готовый эксплойт | A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attackermicrosoft · windows 7 · CWE-416 | Критическая9,8 | KEV | 100,0 % | 16 мая 2019 г. |
99Срочно | CVE-2022-22965Готовый эксплойт | A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.vmware · spring framework · CWE-94 | Критическая9,8 | KEV | 99,6 % | 1 апр. 2022 г. |
97Срочно | CVE-2017-5689Готовый эксплойт | An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (Aintel · active management technology firmware · CWE-269 | Критическая9,8 | KEV | 92,2 % | 2 мая 2017 г. |
96Срочно | CVE-2021-40438Готовый эксплойт | A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.resf · rocky linux · CWE-918 | Критическая9,0 | KEV | 100,0 % | 16 сент. 2021 г. |
96Срочно | CVE-2021-45046Готовый эксплойт | Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attackapache · log4j · CWE-917 | Критическая9,0 | KEV | 100,0 % | 14 дек. 2021 г. |
95Срочно | CVE-2017-0144Готовый эксплойт | The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold anmicrosoft · server message block | Высокая8,8 | KEV | 99,2 % | 16 мар. 2017 г. |
95Срочно | CVE-2026-24858Готовый эксплойт | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.fortinet · fortianalyzer · CWE-288 | Критическая9,8 | KEV | 85,8 % | 27 янв. 2026 г. |
93Срочно | CVE-2017-0143Готовый эксплойт | The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold anmicrosoft · server message block | Высокая8,8 | KEV | 93,3 % | 16 мар. 2017 г. |
92Срочно | CVE-2017-0148Готовый эксплойт | The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold anmicrosoft · server message block · CWE-20 | Высокая8,1 | KEV | 99,4 % | 16 мар. 2017 г. |
92Срочно | CVE-2017-0146Готовый эксплойт | The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold anmicrosoft · server message block | Высокая8,8 | KEV | 89,9 % | 16 мар. 2017 г. |
92Срочно | CVE-2017-0145Готовый эксплойт | The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold anmicrosoft · server message block | Высокая8,8 | KEV | 89,9 % | 16 мар. 2017 г. |
90Срочно | CVE-2014-0160Готовый эксплойт | The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remopenssl · openssl · CWE-125 | Высокая7,5 | KEV | 100,0 % | 7 апр. 2014 г. |
90Срочно | CVE-2023-44487Готовый эксплойт | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, assiemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · CWE-400 | Высокая7,5 | KEV | 100,0 % | 10 окт. 2023 г. |
90Срочно | CVE-2017-0147Готовый эксплойт | The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold anmicrosoft · windows 10 1507 | Высокая7,5 | KEV | 99,7 % | 16 мар. 2017 г. |
90Срочно | CVE-2026-0257Готовый эксплойт | PAN-OS: GlobalProtect Authentication Bypass Vulnerabilitiespaloaltonetworks · pan-os · CWE-565 | Высокая7,8 | KEV | 96,4 % | 13 мая 2026 г. |
89Срочно | CVE-2021-4034Готовый эксплойт | A local privilege escalation vulnerability was found on polkit's pkexec utility.polkit project · polkit · CWE-787 | Высокая7,8 | KEV | 94,3 % | 28 янв. 2022 г. |
89Срочно | CVE-2022-0847Готовый эксплойт | A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe linux · linux kernel · CWE-665 | Высокая7,8 | KEV | 92,8 % | 10 мар. 2022 г. |
89Срочно | CVE-2025-59718Готовый эксплойт | A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, Fortifortinet · fortiproxy · CWE-347 | Критическая9,8 | KEV | 68,3 % | 9 дек. 2025 г. |
85Срочно | CVE-2023-4911Готовый эксплойт | Glibc: buffer overflow in ld.so leading to privilege escalationgnu · glibc · CWE-122 | Высокая7,8 | KEV | 81,4 % | 3 окт. 2023 г. |
77На этой неделе | CVE-2026-0300Готовый эксплойт | PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portalpaloaltonetworks · pan-os · CWE-787 | Критическая9,3 | KEV | 31,7 % | 6 мая 2026 г. |
71На этой неделе | CVE-2025-10585Готовый эксплойт | Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a craftedgoogle · chrome · CWE-843 | Критическая9,8 | KEV | 5,4 % | 24 сент. 2025 г. |
70На этой неделе | CVE-2025-25249Готовый эксплойт | A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.1fortinet · fortios · CWE-122 | Критическая9,8 | KEV | 3,9 % | 13 янв. 2026 г. |
70На этой неделе | CVE-2025-39682Готовый эксплойт | tls: fix handling of zero-length records on the rx_listlinux · linux kernel · CWE-754 | Критическая9,8 | KEV | 2,9 % | 5 сент. 2025 г. |
67На этой неделе | CVE-2025-13223Готовый эксплойт | Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a craftedgoogle · chrome · CWE-843 | Высокая8,8 | KEV | 5,0 % | 17 нояб. 2025 г. |
- CVE-2021-44228100Срочно
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %apache · log4j10 дек. 2021 г.
- CVE-2019-070899Срочно
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %microsoft · windows 716 мая 2019 г.
- CVE-2022-2296599Срочно
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %vmware · spring framework1 апр. 2022 г.
- CVE-2017-568997Срочно
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (A
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 92 %intel · active management technology firmware2 мая 2017 г.
- CVE-2021-4043896Срочно
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.
КритическаяCVSS 9,0KEVГотовый эксплойтEPSS 100 %resf · rocky linux16 сент. 2021 г.
- CVE-2021-4504696Срочно
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
КритическаяCVSS 9,0KEVГотовый эксплойтEPSS 100 %apache · log4j14 дек. 2021 г.
- CVE-2017-014495Срочно
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold an
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 99 %microsoft · server message block16 мар. 2017 г.
- CVE-2026-2485895Срочно
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 86 %fortinet · fortianalyzer27 янв. 2026 г.
- CVE-2017-014393Срочно
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold an
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 93 %microsoft · server message block16 мар. 2017 г.
- CVE-2017-014892Срочно
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold an
ВысокаяCVSS 8,1KEVГотовый эксплойтEPSS 99 %microsoft · server message block16 мар. 2017 г.
- CVE-2017-014692Срочно
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold an
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 90 %microsoft · server message block16 мар. 2017 г.
- CVE-2017-014592Срочно
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold an
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 90 %microsoft · server message block16 мар. 2017 г.
- CVE-2014-016090Срочно
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows rem
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %openssl · openssl7 апр. 2014 г.
- CVE-2023-4448790Срочно
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware10 окт. 2023 г.
- CVE-2017-014790Срочно
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold an
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %microsoft · windows 10 150716 мар. 2017 г.
- CVE-2026-025790Срочно
PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 96 %paloaltonetworks · pan-os13 мая 2026 г.
- CVE-2021-403489Срочно
A local privilege escalation vulnerability was found on polkit's pkexec utility.
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 94 %polkit project · polkit28 янв. 2022 г.
- CVE-2022-084789Срочно
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 93 %linux · linux kernel10 мар. 2022 г.
- CVE-2025-5971889Срочно
A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, Forti
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 68 %fortinet · fortiproxy9 дек. 2025 г.
- CVE-2023-491185Срочно
Glibc: buffer overflow in ld.so leading to privilege escalation
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 81 %gnu · glibc3 окт. 2023 г.
- CVE-2026-030077На этой неделе
PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal
КритическаяCVSS 9,3KEVГотовый эксплойтEPSS 32 %paloaltonetworks · pan-os6 мая 2026 г.
- CVE-2025-1058571На этой неделе
Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 5 %google · chrome24 сент. 2025 г.
- CVE-2025-2524970На этой неделе
A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.1
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 4 %fortinet · fortios13 янв. 2026 г.
- CVE-2025-3968270На этой неделе
tls: fix handling of zero-length records on the rx_list
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 3 %linux · linux kernel5 сент. 2025 г.
- CVE-2025-1322367На этой неделе
Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 5 %google · chrome17 нояб. 2025 г.