56.565 CVE seguite
773 Sfruttate ora
181 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.565 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più alto |
|---|---|---|---|---|
| CVE-2024-9465 | CRIT 9.1 | paloaltonetworks expedition An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and | 99,6% | |
| CVE-2024-9463 | HIGH 7.5 | paloaltonetworks expedition An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys | 98,5% | |
| CVE-2024-49039 | HIGH 8.8 | ransomware microsoft windows_10_1507 Windows Task Scheduler Elevation of Privilege Vulnerability | 13,7% | |
| CVE-2024-43451 | MED 6.5 | microsoft windows_10_1507 NTLM Hash Disclosure Spoofing Vulnerability | 81,8% | |
| CVE-2014-2120 | MED 6.1 | cisco adaptive_security_appliance_software Cross-site scripting (XSS) vulnerability in the WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCun19025. | 18,9% | |
| CVE-2024-5910 | CRIT 9.8 | paloaltonetworks expedition Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with network access to Expedition. Note: Expedition is a tool aiding in configuration migration, tuning, and enrichm | 91,8% | |
| CVE-2024-20481 | MED 5.8 | cisco adaptive_security_appliance_software A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of the RAVPN servi | 15,9% | |
| CVE-2024-47575 | CRIT 9.8 | fortinet fortimanager A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiManager 6.4.0 through 6.4.14, FortiManager 6.2.0 through 6.2.12, Fortinet FortiMan | 95,0% | |
| CVE-2024-38094 | HIGH 7.2 | ransomware microsoft sharepoint_server Microsoft SharePoint Remote Code Execution Vulnerability | 50,9% | |
| CVE-2024-30088 | HIGH 7.0 | ransomware microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability | 68,2% | |
| CVE-2024-23113 | CRIT 9.8 | fortinet fortios A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, FortiPAM versions 1.2.0, 1.1.0 through | 61,7% | |
| CVE-2024-43573 | MED 6.5 | microsoft windows_10_1507 Windows MSHTML Platform Spoofing Vulnerability | 43,7% | |
| CVE-2024-43572 | HIGH 7.8 | microsoft windows_10_1507 Microsoft Management Console Remote Code Execution Vulnerability | 66,6% | |
| CVE-2024-27348 | CRIT 9.8 | apache hugegraph RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & Java11 Users are recommended to upgrade to version 1.3.0 with Java11 & enable the Auth system, which fixes the | 99,2% | |
| CVE-2020-0618 | HIGH 8.8 | ransomware microsoft sql_server A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'. | 99,0% | |
| CVE-2014-0502 | HIGH 8.8 | adobe adobe_air Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR SDK before 4.0.0.1628, and Adobe AIR SDK | 24,2% | |
| CVE-2014-0497 | CRIT 9.8 | adobe flash_player Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors. | 99,9% | |
| CVE-2013-0648 | HIGH 8.8 | adobe flash_player Unspecified vulnerability in the ExternalInterface ActionScript functionality in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x before 11.2.202.273 on Linux, allows remote attackers t | 11,1% | |
| CVE-2013-0643 | HIGH 8.8 | adobe flash_player The Firefox sandbox in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x before 11.2.202.273 on Linux, does not properly restrict privileges, which makes it easier for remote attackers t | 10,5% | |
| CVE-2024-43461 | HIGH 8.8 | microsoft windows_10_1507 Windows MSHTML Platform Spoofing Vulnerability | 52,2% | |
| CVE-2024-38226 | HIGH 7.3 | microsoft office_2019 Microsoft Publisher Security Feature Bypass Vulnerability | 2,7% | |
| CVE-2024-38217 | MED 5.4 | microsoft windows_10_1507 Windows Mark of the Web Security Feature Bypass Vulnerability | 9,8% | |
| CVE-2024-38014 | HIGH 7.8 | microsoft windows_10_1507 Windows Installer Elevation of Privilege Vulnerability | 6,3% | |
| CVE-2017-1000253 | HIGH 7.8 | ransomware centos centos Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committed on April 14, 2015). This kernel vulnerability was fixed in April 2015 by commit a87938b2e246b81b4fb713edb371 | 10,7% | |
| CVE-2024-7262 | HIGH 7.8 | kingsoft wps_office Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.16412 (exclusive) on Windows allows an attacker to load an arbitrary Windows library. The vulnerability was found weaponized as a single-click | 1,8% |