58.151 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.151 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2022-23238 | MED 6.5 | netapp storagegrid Linux deployments of StorageGRID (formerly StorageGRID Webscale) versions 11.6.0 through 11.6.0.2 deployed with a Linux kernel version less than 4.7.0 are susceptible to a vulnerability which could allow a remote unauthenticated attacker to view limited metric | 0,7% | — |
| CVE-2019-17180 | HIGH 7.8 | valvesoftware steam_client Valve Steam Client before 2019-09-12 allows placing or appending partially controlled filesystem content, as demonstrated by file modifications on Windows in the context of NT AUTHORITY\SYSTEM. This could lead to denial of service, elevation of privilege, or u | 0,7% | — |
| CVE-2014-3405 | MED 4.8 | cisco ios_xe Cisco IOS XE enables the IPv6 Routing Protocol for Low-Power and Lossy Networks (aka RPL) on both the Autonomic Control Plane (ACP) and external Autonomic Networking Infrastructure (ANI) interfaces, which allows remote attackers to conduct route-injection atta | 0,7% | — |
| CVE-2026-41106 | CRIT 9.3 | microsoft 365_copilot Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network. | 0,7% | — |
| CVE-2025-59503 | CRIT 10.0 | microsoft azure_compute_resource_provider Server-side request forgery (ssrf) in Azure Compute Gallery allows an unauthorized attacker to elevate privileges over a network. | 0,7% | — |
| CVE-2024-53949 | MED 6.5 | apache superset Improper Authorization vulnerability in Apache Superset when FAB_ADD_SECURITY_API is enabled (disabled by default). Allows for lower privilege users to use this API. issue affects Apache Superset: from 2.0.0 before 4.1.0. Users are recommended to upgrade to | 0,7% | — |
| CVE-2024-43556 | HIGH 7.8 | microsoft windows_10_1507 Windows Graphics Component Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2023-20194 | MED 4.9 | cisco identity_services_engine A vulnerability in the ERS API of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system of an affected device. To exploit this vulnerability, an attacker must have valid Administrator-level privilege | 0,7% | — |
| CVE-2022-26899 | MED 6.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2021-43877 | HIGH 8.8 | microsoft asp.net_core ASP.NET Core and Visual Studio Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2021-1158 | MED 4.8 | cisco application_extension_platform Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. The vu | 0,7% | — |
| CVE-2021-1151 | MED 4.8 | cisco application_extension_platform Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. The vu | 0,7% | — |
| CVE-2020-3460 | MED 6.1 | cisco data_center_network_manager A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability exists because t | 0,7% | — |
| CVE-2019-1952 | MED 6.7 | cisco enterprise_nfv_infrastructure_software A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to overwrite or read arbitrary files. The attacker would need valid administrator privilege-level credentials. This vulnerability is | 0,7% | — |
| CVE-2018-5506 | CRIT 9.8 | f5 big-ip_access_policy_manager In F5 BIG-IP 13.0.0, 12.1.0-12.1.2, 11.6.1, 11.5.1-11.5.5, or 11.2.1 the Apache modules apache_auth_token_mod and mod_auth_f5_auth_token.cpp allow possible unauthenticated bruteforce on the em_server_ip authorization parameter to obtain which SSL client certif | 0,7% | — |
| CVE-2017-0331 | HIGH 7.8 | google android An elevation of privilege vulnerability in the NVIDIA video driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device comprom | 0,7% | — |
| CVE-2015-0710 | MED 6.1 | cisco ios_xe The Overlay Transport Virtualization (OTV) implementation in Cisco IOS XE 3.10S allows remote attackers to cause a denial of service (device reload) via a series of packets that are considered oversized and trigger improper fragmentation handling, aka Bug IDs | 0,7% | — |
| CVE-2013-7421 | LOW 2.1 | canonical ubuntu_linux The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a module name in the salg_name field, a different vulnerability than CVE-2014-9644. | 0,7% | — |
| CVE-2010-2240 | HIGH 7.2 | linux linux_kernel The do_anonymous_page function in mm/memory.c in the Linux kernel before 2.6.27.52, 2.6.32.x before 2.6.32.19, 2.6.34.x before 2.6.34.4, and 2.6.35.x before 2.6.35.2 does not properly separate the stack and the heap, which allows context-dependent attackers to | 0,7% | — |
| CVE-2001-0317 | LOW 3.7 | linux linux_kernel Race condition in ptrace in Linux kernel 2.4 and 2.2 allows local users to gain privileges by using ptrace to track and modify a running setuid process. | 0,7% | — |
| CVE-2026-29145 | CRIT 9.1 | apache tomcat CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 through 10.1.52, from 9.0 | 0,7% | — |
| CVE-2024-45324 | HIGH 7.2 | fortinet fortios A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.0 through 7.4.4, version 7.2.0 through 7.2.9, version 7.0.0 through 7.0.15 and before 6.4.15, FortiProxy version 7.4.0 through 7.4.6, version 7.2.0 through 7.2.12 and b | 0,7% | — |
| CVE-2024-28920 | HIGH 7.8 | microsoft windows_10_1809 Secure Boot Security Feature Bypass Vulnerability | 0,7% | — |
| CVE-2024-26582 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: tls: fix use-after-free with partial reads and async decrypt tls_decrypt_sg doesn't take a reference on the pages from clear_skb, so the put_page() in tls_decrypt_done releases them, an | 0,7% | — |
| CVE-2024-20458 | HIGH 8.2 | cisco ata_191_firmware A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remote attacker to view or delete the configuration or change the firmware on an affected device. This vulnerabil | 0,7% | — |