57.971 CVE seguite
784 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.971 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2017-14190 | MED 6.1 | fortinet fortios A Cross-site Scripting vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.7, 5.2 and earlier, allows attacker to inject arbitrary web script or HTML via maliciously crafted "Host" header in user HTTP requests. | 1,1% | — |
| CVE-2017-10610 | HIGH 7.5 | juniper junos On SRX Series devices, a crafted ICMP packet embedded within a NAT64 IPv6 to IPv4 tunnel may cause the flowd process to crash. Repeated crashes of the flowd process constitutes an extended denial of service condition for the SRX Series device. This issue only | 1,1% | — |
| CVE-2009-0521 | MED 4.6 | adobe flash_player_for_linux Untrusted search path vulnerability in Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 on Linux allows local users to obtain sensitive information or gain privileges via a crafted library in a directory contained in the RPATH. | 1,1% | — |
| CVE-2026-69829 | CRIT 9.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Shell allows an unauthorized attacker to execute code over a network. | 1,1% | — |
| CVE-2025-23304 | HIGH 7.8 | nvidia nemo NVIDIA NeMo library for all platforms contains a vulnerability in the model loading component, where an attacker could cause code injection by loading .nemo files with maliciously crafted metadata. A successful exploit of this vulnerability may lead to remote | 1,1% | — |
| CVE-2022-25375 | MED 5.5 | debian debian_linux An issue was discovered in drivers/usb/gadget/function/rndis.c in the Linux kernel before 5.16.10. The RNDIS USB gadget lacks validation of the size of the RNDIS_MSG_SET command. Attackers can obtain sensitive information from kernel memory. | 1,1% | — |
| CVE-2022-25265 | HIGH 7.8 | linux linux_kernel In the Linux kernel through 5.16.10, certain binary files may have the exec-all attribute if they were built in approximately 2003 (e.g., with GCC 3.2.2 and Linux kernel 2.4.20). This can cause execution of bytes located in supposedly non-executable regions of | 1,1% | — |
| CVE-2019-1757 | MED 5.9 | cisco ios A vulnerability in the Cisco Smart Call Home feature of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data using an invalid certificate. The vulnerability is due to insufficient cert | 1,1% | — |
| CVE-2018-5510 | HIGH 7.5 | f5 big-ip_access_policy_manager On F5 BIG-IP 11.5.4 HF4-11.5.5, the Traffic Management Microkernel (TMM) may restart when processing a specific sequence of packets on IPv6 virtual servers. | 1,1% | — |
| CVE-2011-3309 | MED 4.3 | cisco 5500_series_adaptive_security_appliance Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.2 through 8.4 process IKE requests despite a vpnclient mode configuration, which allows remote attackers to obtain potentially sensitive information by reading IKE responder traffic, | 1,1% | — |
| CVE-2002-1658 | MED 4.6 | apache http_server Buffer overflow in htdigest in Apache 1.3.26 and 1.3.27 may allow attackers to execute arbitrary code via a long user argument. NOTE: since htdigest is normally only locally accessible and not setuid or setgid, there are few attack vectors which would lead to | 1,1% | — |
| CVE-2026-23906 | CRIT 9.8 | apache druid Affected Products and Versions * Apache Druid * Affected Versions: 0.17.0 through 35.x (all versions prior to 36.0.0) * Prerequisites: * druid-basic-security extension enabled * LDAP authenticator configured * Underlying LDAP server permits an | 1,1% | — |
| CVE-2026-0265 | HIGH 8.1 | paloaltonetworks pan-os An authentication bypass vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to bypass authentication controls when Cloud Authentication Service (CAS) is enabled. The risk is higher if CAS is enabled | 1,1% | — |
| CVE-2023-40687 | MED 5.3 | ibm db2 IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted RUNSTATS command on an 8TB table. IBM X-Force ID: 264809. | 1,1% | — |
| CVE-2023-38727 | MED 5.3 | ibm db2 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted SQL statement. IBM X-Force ID: 262257. | 1,1% | — |
| CVE-2023-29258 | MED 5.3 | ibm db2 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1, and 11.5 is vulnerable to a denial of service through a specially crafted federated query on specific federation objects. IBM X-Force ID: 252048. | 1,1% | — |
| CVE-2021-36961 | MED 5.5 | microsoft windows_10 Windows Installer Denial of Service Vulnerability | 1,1% | — |
| CVE-2021-1540 | HIGH 8.1 | cisco staros Multiple vulnerabilities in the authorization process of Cisco ASR 5000 Series Software (StarOS) could allow an authenticated, remote attacker to bypass authorization and execute a subset of CLI commands on an affected device. For more information about these | 1,1% | — |
| CVE-2020-5914 | HIGH 7.5 | f5 big-ip_application_security_manager In BIG-IP ASM versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, undisclosed server cookie scenario may cause BD to restart under some circumstances. | 1,1% | — |
| CVE-2020-17097 | LOW 3.3 | microsoft windows_10 Windows Digital Media Receiver Elevation of Privilege Vulnerability | 1,1% | — |
| CVE-2018-0015 | CRIT 9.8 | juniper appformix A malicious user with unrestricted access to the AppFormix application management platform may be able to access a Python debug console and execute system commands with root privilege. The AppFormix Agent exposes the debug console on a host where AppFormix Age | 1,1% | — |
| CVE-2017-6145 | HIGH 7.3 | f5 big-ip_access_policy_manager iControl REST in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, and WebSafe 12.0.0 through 12.1.2 and 13.0.0 includes a service to convert authorization BIGIPAuthCookie cookies to X-F5-Auth-Token tokens. This service does not properly | 1,1% | — |
| CVE-2025-62821 | CRIT 9.1 | microsoft heif_image_extension Microsoft HEIF Image Extensions 1.2.22.0 has an out-of-bounds read because CHEIFItemInfoEntry_GetDataSize can return success while leaving the reported data size as 0. This causes a caller to make a 1-byte allocation. Later, CopyPixels computes copy_size = str | 1,1% | — |
| CVE-2023-49068 | HIGH 7.5 | apache dolphinscheduler Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache DolphinScheduler.This issue affects Apache DolphinScheduler: before 3.2.1. Users are recommended to upgrade to version 3.2.1, which fixes the issue. At the time of disclosure o | 1,1% | — |
| CVE-2023-35387 | HIGH 8.8 | microsoft windows_10_1507 Windows Bluetooth A2DP driver Elevation of Privilege Vulnerability | 1,1% | — |