57.921 CVE seguite
783 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.921 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2022-41057 | HIGH 7.8 | microsoft windows_10 Windows HTTP.sys Elevation of Privilege Vulnerability | 1,1% | — |
| CVE-2012-0903 | MED 4.3 | vmware zimbra_desktop Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Desktop 7.1.2 b10978 allow remote attackers to inject arbitrary web script or HTML via the (1) Username or (2) MailBox Name. | 1,1% | — |
| CVE-2024-43467 | HIGH 7.5 | microsoft windows_server_2008 Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability | 1,1% | — |
| CVE-2023-20873 | CRIT 9.8 | vmware spring_boot In Spring Boot versions 3.0.0 - 3.0.5, 2.7.0 - 2.7.10, and older unsupported versions, an application that is deployed to Cloud Foundry could be susceptible to a security bypass. Users of affected versions should apply the following mitigation: 3.0.x users sho | 1,1% | — |
| CVE-2023-20863 | MED 6.5 | vmware spring_framework In spring framework versions prior to 5.2.24 release+ ,5.3.27+ and 6.0.8+ , it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition. | 1,1% | — |
| CVE-2022-35283 | MED 6.5 | ibm security_verify_information_queue IBM Security Verify Information Queue 10.0.2 could allow an authenticated user to cause a denial of service with a specially crafted HTTP request. | 1,1% | — |
| CVE-2019-1413 | MED 4.3 | microsoft edge A security feature bypass vulnerability exists when Microsoft Edge improperly handles extension requests and fails to request host permission for all_urls, aka 'Microsoft Edge Security Feature Bypass Vulnerability'. | 1,1% | — |
| CVE-2017-5083 | MED 4.3 | google chrome Inappropriate implementation in Blink in Google Chrome prior to 59.0.3071.86 for Mac, Windows, and Linux, and 59.0.3071.92 for Android, allowed a remote attacker to display UI on a non attacker controlled tab via a crafted HTML page. | 1,1% | — |
| CVE-2017-16878 | MED 6.1 | paloaltonetworks pan-os Cross-site scripting (XSS) vulnerability in the Captive Portal function in Palo Alto Networks PAN-OS before 8.0.7 allows remote attackers to inject arbitrary web script or HTML by leveraging an unspecified configuration. | 1,1% | — |
| CVE-2016-1298 | MED 6.1 | cisco unified_contact_center_express Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified Contact Center Express 10.0(1), 10.5(1), 10.6(1), and 11.0(1) allow remote attackers to inject arbitrary web script or HTML via vectors related to permalinks, aka Bug ID CSCux92033. | 1,1% | — |
| CVE-2016-1294 | MED 6.1 | cisco firesight_system_software Cross-site scripting (XSS) vulnerability in the Management Center in Cisco FireSIGHT System Software 6.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted cookie, aka Bug ID CSCuw89094. | 1,1% | — |
| CVE-2016-1293 | MED 6.1 | cisco firesight_system_software Multiple cross-site scripting (XSS) vulnerabilities in the Management Center in Cisco FireSIGHT System Software 6.0.0 and 6.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCux40414. | 1,1% | — |
| CVE-2024-38051 | HIGH 7.8 | microsoft windows_10_1507 Windows Graphics Component Remote Code Execution Vulnerability | 1,1% | — |
| CVE-2023-36027 | HIGH 7.1 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 1,1% | — |
| CVE-2022-45064 | HIGH 8.0 | apache apache_sling_engine The SlingRequestDispatcher doesn't correctly implement the RequestDispatcher API resulting in a generic type of include-based cross-site scripting issues on the Apache Sling level. The vulnerability is exploitable by an attacker that is able to include a resou | 1,1% | — |
| CVE-2022-21155 | HIGH 7.5 | fernhillsoftware scada_server A specially crafted packet sent to the Fernhill SCADA Server Version 3.77 and earlier may cause an exception, causing the server process (FHSvrService.exe) to exit. | 1,1% | — |
| CVE-2020-8145 | MED 6.5 | ui unifi_video The UniFi Video Server (Windows) web interface configuration restore functionality at the “backup” and “wizard” endpoints does not implement sufficient privilege checks. Low privileged users, belonging to the PUBLIC_GROUP or CUSTOM_GROUP groups, can access the | 1,1% | — |
| CVE-2017-3794 | HIGH 8.8 | cisco webex_meetings_server A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against an administrative user. More Information: CSCuz03317. Known Affected Releases: 2.6. Known Fixed Release | 1,1% | — |
| CVE-2016-1411 | MED 5.9 | cisco content_security_management_appliance A vulnerability in the update functionality of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), and Cisco Content Management Security Appliance (SMA) could allow an unauthenticated, remote attacker to imperso | 1,1% | — |
| CVE-2014-1739 | LOW 2.1 | canonical ubuntu_linux The media_device_enum_entities function in drivers/media/media-device.c in the Linux kernel before 3.14.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel memory by leveraging /dev/media0 read a | 1,1% | — |
| CVE-2025-25002 | MED 6.8 | microsoft azure_local_cluster Insertion of sensitive information into log file in Azure Local Cluster allows an authorized attacker to disclose information over an adjacent network. | 1,1% | — |
| CVE-2024-48890 | MED 6.6 | fortinet fortisoar_imap_connector An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiSOAR IMAP connector version 3.5.7 and below may allow an authenticated attacker to execute unauthorized code or commands via a specific | 1,1% | — |
| CVE-2024-26177 | MED 5.5 | microsoft windows_10_1507 Windows Kernel Information Disclosure Vulnerability | 1,1% | — |
| CVE-2022-33674 | HIGH 8.3 | microsoft azure_site_recovery_vmware_to_azure Azure Site Recovery Elevation of Privilege Vulnerability | 1,1% | — |
| CVE-2021-42301 | LOW 3.3 | microsoft azure_rtos Azure RTOS Information Disclosure Vulnerability | 1,1% | — |