EN
58.165 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.165 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più alto In KEV dal, ordina dal più alto
CVE-2017-3128 MED 4.8 fortinet fortios A stored XSS (Cross-Site-Scripting) vulnerability in Fortinet FortiOS allows attackers to execute unauthorized code or commands via the policy global-label parameter. 0,7%
CVE-2010-3699 LOW 2.7 citrix xen The backend driver in Xen 3.x allows guest OS users to cause a denial of service via a kernel thread leak, which prevents the device and guest OS from being shut down or create a zombie domain, causes a hang in zenwatch, or prevents unspecified xm commands fro 0,7%
CVE-2025-21214 MED 4.2 microsoft windows_10_1507 Windows BitLocker Information Disclosure Vulnerability 0,7%
CVE-2024-46763 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: fou: Fix null-ptr-deref in GRO. We observed a null-ptr-deref in fou_gro_receive() while shutting down a host. [0] The NULL pointer is sk->sk_user_data, and the offset 8 is of protocol in s 0,7%
CVE-2024-38050 HIGH 7.8 microsoft windows_10_1507 Windows Workstation Service Elevation of Privilege Vulnerability 0,7%
CVE-2024-30049 HIGH 7.8 microsoft windows_10_1507 Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability 0,7%
CVE-2024-26854 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ice: fix uninitialized dplls mutex usage The pf->dplls.lock mutex is initialized too late, after its first use. Move it to the top of ice_dpll_init. Note that the "err_exit" error path destr 0,7%
CVE-2023-43021 MED 5.3 ibm infosphere_information_server IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 2661 0,7%
CVE-2023-42785 MED 6.5 fortinet fortios A null pointer dereference in FortiOS versions 7.4.0 through 7.4.1, 7.2.0 through 7.2.5, 7.0 all versions, 6.4 all versions , 6.2 all versions and 6.0 all versions allows attacker to trigger a denial of service via a crafted http request. 0,7%
CVE-2023-35080 HIGH 7.8 ivanti secure_access_client A vulnerability has been identified in the Ivanti Secure Access Windows client, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to various security risks, including the escalation of privileges, den 0,7%
CVE-2022-41085 HIGH 7.5 microsoft azure_cyclecloud Azure CycleCloud Elevation of Privilege Vulnerability 0,7%
CVE-2022-34306 MED 5.4 ibm cics_tx IBM CICS TX Standard and Advanced 11.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, ca 0,7%
CVE-2021-47244 HIGH 8.2 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mptcp: Fix out of bounds when parsing TCP options The TCP option parser in mptcp (mptcp_get_options) could read one byte out of bounds. When the length is 1, the execution flow gets into the 0,7%
CVE-2021-31386 MED 5.3 juniper junos A Protection Mechanism Failure vulnerability in the J-Web HTTP service of Juniper Networks Junos OS allows a remote unauthenticated attacker to perform Person-in-the-Middle (PitM) attacks against the device. This issue affects: Juniper Networks Junos OS 12.3 v 0,7%
CVE-2019-1750 HIGH 7.4 cisco ios_xe A vulnerability in the Easy Virtual Switching System (VSS) of Cisco IOS XE Software on Catalyst 4500 Series Switches could allow an unauthenticated, adjacent attacker to cause the switches to reload. The vulnerability is due to incomplete error handling when p 0,7%
CVE-2018-17195 HIGH 7.5 apache nifi The template upload API endpoint accepted requests from different domain when sent in conjunction with ARP spoofing + man in the middle (MiTM) attack, resulting in a CSRF attack. The required attack vector is complex, requiring a scenario with client certifica 0,7%
CVE-2017-3129 MED 6.1 fortinet fortiweb A Cross-Site Scripting vulnerability in Fortinet FortiWeb versions 5.7.1 and below allows attacker to execute unauthorized code or commands via an improperly sanitized POST parameter in the FortiWeb Site Publisher feature. 0,7%
CVE-2012-2119 MED 5.2 linux linux_kernel Buffer overflow in the macvtap device driver in the Linux kernel before 3.4.5, when running in certain configurations, allows privileged KVM guest users to cause a denial of service (crash) via a long descriptor with a long vector length. 0,7%
CVE-2026-20034 HIGH 8.8 cisco unity_connection A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An at 0,7%
CVE-2025-64675 HIGH 8.3 microsoft azure_cosmos_db Improper neutralization of input during web page generation ('cross-site scripting') in Azure Cosmos DB allows an unauthorized attacker to perform spoofing over a network. 0,7%
CVE-2025-53787 HIGH 8.2 microsoft 365_copilot_chat Microsoft 365 Copilot BizChat Information Disclosure Vulnerability 0,7%
CVE-2024-35261 HIGH 7.8 microsoft azure_network_watcher_agent Azure Network Watcher VM Extension Elevation of Privilege Vulnerability 0,7%
CVE-2024-24859 MED 4.6 linux linux_kernel A race condition was found in the Linux kernel's net/bluetooth in sniff_{min,max}_interval_set() function. This can result in a bluetooth sniffing exception issue, possibly leading denial of service. 0,7%
CVE-2023-33857 MED 5.3 ibm infosphere_information_server IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain system information using a specially crafted query that could aid in further attacks against the system. IBM X-Force ID: 257695. 0,7%
CVE-2023-29413 HIGH 7.5 schneider-electric apc_easy_ups_online_monitoring_software A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause Denial-of-Service when accessed by an unauthenticated user on the Schneider UPS Monitor service. 0,7%