İçeriğe atla
Noroxi

siemens kayıtları

siemens üreticisine ait 2.243 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
29 · %1,3
Silahlaştırılmış
38 · %1,7
Pre-auth RCE
108
Düzeltme kaydı olan
%10,1
Yayından KEV’e ortanca
150 gün

Tüm kayıtlar

2.243 kayıt
  • Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %100

    apache · log4j10 Ara 2021

  • A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    microsoft · windows 716 May 2019

  • A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    vmware · spring framework1 Nis 2022

  • An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (A

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %92

    intel · active management technology firmware2 May 2017

  • A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.

    KritikCVSS 9,0KEVSilahlaştırılmışEPSS %100

    resf · rocky linux16 Eyl 2021

  • Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack

    KritikCVSS 9,0KEVSilahlaştırılmışEPSS %100

    apache · log4j14 Ara 2021

  • The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold an

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %99

    microsoft · server message block16 Mar 2017

  • An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %86

    fortinet · fortianalyzer27 Oca 2026

  • The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold an

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %93

    microsoft · server message block16 Mar 2017

  • The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold an

    YüksekCVSS 8,1KEVSilahlaştırılmışEPSS %99

    microsoft · server message block16 Mar 2017

  • The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold an

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %90

    microsoft · server message block16 Mar 2017

  • The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold an

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %90

    microsoft · server message block16 Mar 2017

  • The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows rem

    YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %100

    openssl · openssl7 Nis 2014

  • The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as

    YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %100

    siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware10 Eki 2023

  • The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold an

    YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %100

    microsoft · windows 10 150716 Mar 2017

  • PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %96

    paloaltonetworks · pan-os13 May 2026

  • A local privilege escalation vulnerability was found on polkit's pkexec utility.

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %94

    polkit project · polkit28 Oca 2022

  • A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %93

    linux · linux kernel10 Mar 2022

  • A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, Forti

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %68

    fortinet · fortiproxy9 Ara 2025

  • Glibc: buffer overflow in ld.so leading to privilege escalation

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %81

    gnu · glibc3 Eki 2023

  • CVE-2026-0300
    77Bu hafta

    PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal

    KritikCVSS 9,3KEVSilahlaştırılmışEPSS %32

    paloaltonetworks · pan-os6 May 2026

  • CVE-2025-10585
    71Bu hafta

    Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %5

    google · chrome24 Eyl 2025

  • CVE-2025-25249
    70Bu hafta

    A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.1

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %4

    fortinet · fortios13 Oca 2026

  • CVE-2025-39682
    70Bu hafta

    tls: fix handling of zero-length records on the rx_list

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %3

    linux · linux kernel5 Eyl 2025

  • CVE-2025-13223
    67Bu hafta

    Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %5

    google · chrome17 Kas 2025