57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.971 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2016-7541 | MED 5.9 | fortinet fortios Long lived sessions in Fortinet FortiGate devices with FortiOS 5.x before 5.4.0 could violate a security policy during IPS signature updates when the FortiGate's IPSengine is configured in flow mode. All FortiGate versions with IPS configured in proxy mode (th | 1,0% | — |
| CVE-2015-6417 | MED 6.5 | cisco videoscape_distribution_suite_service_manager Cisco Videoscape Distribution Suite Service Manager (VDS-SM) 3.4.0 and earlier does not always use RBAC for backend database access, which allows remote authenticated users to read or write to database entries via (1) the GUI or (2) a crafted HTTP request, aka | 1,0% | — |
| CVE-2014-2174 | HIGH 8.3 | cisco telepresence_tc_software Cisco TelePresence T, TelePresence TE, and TelePresence TC before 7.1 do not properly implement access control, which allows remote attackers to obtain root privileges by sending packets on the local network and allows physically proximate attackers to obtain | 1,0% | — |
| CVE-2012-3430 | LOW 2.1 | linux linux_kernel The rds_recvmsg function in net/rds/recv.c in the Linux kernel before 3.0.44 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via a (1) recvfrom or (2) recvmsg system | 1,0% | — |
| CVE-2012-2854 | MED 5.0 | google chrome Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allows remote attackers to obtain potentially sensitive information about pointer values by leveraging access to a WebUI renderer process. | 1,0% | — |
| CVE-2025-59248 | HIGH 7.5 | microsoft exchange_server Improper input validation in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | 1,0% | — |
| CVE-2024-28896 | HIGH 7.5 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 1,0% | — |
| CVE-2024-26184 | MED 6.8 | microsoft windows_10_21h2 Secure Boot Security Feature Bypass Vulnerability | 1,0% | — |
| CVE-2023-36557 | HIGH 7.8 | microsoft windows_10_1507 PrintHTML API Remote Code Execution Vulnerability | 1,0% | — |
| CVE-2023-20080 | HIGH 8.6 | cisco ios A vulnerability in the IPv6 DHCP version 6 (DHCPv6) relay and server features of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerability is due to insufficient validation | 1,0% | — |
| CVE-2020-3549 | HIGH 8.1 | cisco secure_firewall_management_center A vulnerability in the sftunnel functionality of Cisco Firepower Management Center (FMC) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to obtain the device registration hash. The vulnerability is due | 1,0% | — |
| CVE-2020-0707 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows IME improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows IME Elevation of Privilege Vulnerability'. | 1,0% | — |
| CVE-2020-0704 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Wireless Network Manager improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Wireless Network Manager Elevati | 1,0% | — |
| CVE-2014-3302 | MED 5.8 | cisco webex_meetings_server user.php in Cisco WebEx Meetings Server 1.5(.1.131) and earlier does not properly implement the token timer for authenticated encryption, which allows remote attackers to obtain sensitive information via a crafted URL, aka Bug ID CSCuj81708. | 1,0% | — |
| CVE-2002-1106 | HIGH 7.5 | cisco vpn_client Cisco Virtual Private Network (VPN) Client software 2.x.x, and 3.x before 3.5.1C, does not properly verify that certificate DN fields match those of the certificate from the VPN Concentrator, which allows remote attackers to conduct man-in-the-middle attacks. | 1,0% | — |
| CVE-2025-29802 | HIGH 7.3 | microsoft visual_studio_2022 Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally. | 0,9% | — |
| CVE-2024-38249 | HIGH 7.8 | microsoft windows_10_1507 Windows Graphics Component Elevation of Privilege Vulnerability | 0,9% | — |
| CVE-2024-26168 | MED 6.8 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 0,9% | — |
| CVE-2023-49734 | HIGH 7.7 | apache superset An authenticated Gamma user has the ability to create a dashboard and add charts to it, this user would automatically become one of the owners of the charts allowing him to incorrectly have write permissions to these charts.This issue affects Apache Superset: | 0,9% | — |
| CVE-2023-20250 | MED 6.5 | cisco rv110w_firmware A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to improper vali | 0,9% | — |
| CVE-2022-20942 | MED 6.5 | cisco asyncos A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA), Cisco Secure Email and Web Manager, and Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA), could allow an authenticated, remote attack | 0,9% | — |
| CVE-2021-41361 | MED 5.4 | microsoft windows_server_2016 Active Directory Federation Server Spoofing Vulnerability | 0,9% | — |
| CVE-2021-41354 | MED 5.4 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 0,9% | — |
| CVE-2021-41353 | MED 5.4 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Spoofing Vulnerability | 0,9% | — |
| CVE-2021-23039 | HIGH 7.5 | f5 big-ip_access_policy_manager On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.2.8, and all versions of 13.1.x and 12.1.x, when IPSec is configured on a BIG-IP system, undisclosed requests from an authorized remote (IPSec) peer, which already has a negotiated Sec | 0,9% | — |