58.140 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.140 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2023-29365 | HIGH 7.8 | microsoft windows_10_1507 Windows Media Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2022-45052 | HIGH 8.8 | axiell iguana A Local File Inclusion vulnerability has been found in Axiell Iguana CMS. Due to insufficient neutralisation of user input on the url parameter on the Proxy.type.php endpoint, external users are capable of accessing files on the server. | 0,7% | — |
| CVE-2022-35706 | HIGH 7.8 | adobe bridge Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction | 0,7% | — |
| CVE-2022-20810 | MED 6.5 | cisco ios_xe A vulnerability in the Simple Network Management Protocol (SNMP) of Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family could allow an authenticated, remote attacker to access sensitive information. This vulnerability is due to insufficient | 0,7% | — |
| CVE-2021-43389 | MED 5.5 | debian debian_linux An issue was discovered in the Linux kernel before 5.14.15. There is an array-index-out-of-bounds flaw in the detach_capi_ctr function in drivers/isdn/capi/kcapi.c. | 0,7% | — |
| CVE-2012-4131 | MED 4.6 | cisco nx-os Directory traversal vulnerability in tar in Cisco NX-OS allows local users to access arbitrary files via crafted command-line arguments, aka Bug IDs CSCty07157, CSCty07159, CSCty07162, and CSCty07164. | 0,7% | — |
| CVE-2025-30677 | MED 6.5 | apache pulsar Apache Pulsar contains multiple connectors for integrating with Apache Kafka. The Pulsar IO Apache Kafka Source Connector, Sink Connector, and Kafka Connect Adaptor Sink Connector log sensitive configuration properties in plain text in application logs. This | 0,7% | — |
| CVE-2025-21312 | LOW 2.4 | microsoft windows_10_1507 Windows Smart Card Reader Information Disclosure Vulnerability | 0,7% | — |
| CVE-2024-43579 | HIGH 7.6 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2024-43578 | HIGH 7.6 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2024-38123 | MED 4.4 | microsoft windows_11_24h2 Windows Bluetooth Driver Information Disclosure Vulnerability | 0,7% | — |
| CVE-2023-0882 | HIGH 8.8 | krontech single_connect Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Kron Tech Single Connect on Windows allows Privilege Abuse. This issue affects Single Connect: 2.16. | 0,7% | — |
| CVE-2022-49670 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: linux/dim: Fix divide by 0 in RDMA DIM Fix a divide 0 error in rdma_dim_stats_compare() when prev->cpe_ratio == 0. CallTrace: Hardware name: H3C R4900 G3/RS33M2C9S, BIOS 2.00.37P21 03/12/ | 0,7% | — |
| CVE-2022-22229 | HIGH 8.4 | juniper paragon_active_assurance_control_center An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability, a stored XSS (or persistent), in the Control Center Controller web pages of Juniper Networks Paragon Active Assurance (Formerly Netrounds) allows a high-priv | 0,7% | — |
| CVE-2020-26080 | MED 4.1 | cisco iot_field_network_director A vulnerability in the user management functionality of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to manage user information for users in different domains on an affected system. The vulnerability is due to improper d | 0,7% | — |
| CVE-2012-5723 | MED 6.1 | cisco asr_1001 Cisco ASR 1000 devices with software before 3.8S, when BDI routing is enabled, allow remote attackers to cause a denial of service (device reload) via crafted (1) broadcast or (2) multicast ICMP packets with fragmentation, aka Bug ID CSCub55948. | 0,7% | — |
| CVE-2026-20129 | CRIT 9.8 | cisco catalyst_sd-wan_manager A vulnerability in the API user authentication of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain access to an affected system as a user who has the netadmin role. The vulnerability is due to improper authenticatio | 0,7% | — |
| CVE-2024-38256 | MED 5.5 | microsoft windows_10_1507 Windows Kernel-Mode Driver Information Disclosure Vulnerability | 0,7% | — |
| CVE-2024-38235 | MED 6.5 | microsoft windows_10_1507 Windows Hyper-V Denial of Service Vulnerability | 0,7% | — |
| CVE-2024-36504 | MED 6.5 | fortinet fortios An out-of-bounds read vulnerability [CWE-125] in FortiOS SSLVPN web portal versions 7.4.0 through 7.4.4, versions 7.2.0 through 7.2.8, 7.0 all verisons, and 6.4 all versions may allow an authenticated attacker to perform a denial of service on the SSLVPN web p | 0,7% | — |
| CVE-2024-29992 | MED 5.5 | microsoft azure_identity_library_for_.net Azure Identity Library for .NET Information Disclosure Vulnerability | 0,7% | — |
| CVE-2023-4595 | HIGH 7.5 | seattlelab slmail An information exposure vulnerability has been found, the exploitation of which could allow a remote user to retrieve sensitive information stored on the server such as credential files, configuration files, application files, etc., simply by appending any of | 0,7% | — |
| CVE-2023-20107 | HIGH 7.5 | cisco adaptive_security_appliance A vulnerability in the deterministic random bit generator (DRBG), also known as pseudorandom number generator (PRNG), in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco ASA 5506-X, ASA 5508-X, and AS | 0,7% | — |
| CVE-2022-39946 | HIGH 7.6 | fortinet fortinac An access control vulnerability [CWE-284] in FortiNAC version 9.4.2 and below, version 9.2.7 and below, 9.1 all versions, 8.8 all versions, 8.7 all versions, 8.6 all versions, 8.5 all versions may allow a remote attacker authenticated on the administrative int | 0,7% | — |
| CVE-2022-26932 | HIGH 8.2 | microsoft windows_server Storage Spaces Direct Elevation of Privilege Vulnerability | 0,7% | — |