58.306 CVE seguite
789 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.306 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2019-16008 | MED 5.4 | cisco ip_phone_6821_firmware A vulnerability in the web-based GUI of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface of an affected | 0,6% | — |
| CVE-2019-15968 | MED 5.4 | cisco hosted_collaboration_solution A vulnerability in the web-based management interface of Cisco Unified Communications Domain Manager (Unified CDM) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface | 0,6% | — |
| CVE-2019-12702 | MED 5.4 | cisco spa112_firmware A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to conduct cross-site scripting attacks. The vulnerability is due to insufficient validation of user-sup | 0,6% | — |
| CVE-2019-12638 | MED 5.4 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web-based management interface. The vulnerability is | 0,6% | — |
| CVE-2019-12637 | MED 5.4 | cisco identity_services_engine Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web-based management interface. The vulnera | 0,6% | — |
| CVE-2019-0024 | MED 5.4 | juniper advanced_threat_prevention A persistent cross-site scripting (XSS) vulnerability in the Email Collectors menu of Juniper ATP may allow authenticated user to inject arbitrary script and steal sensitive data and credentials from a web administration session, possibly tricking a follow-on | 0,6% | — |
| CVE-2013-6763 | MED 6.9 | linux linux_kernel The uio_mmap_physical function in drivers/uio/uio.c in the Linux kernel before 3.12 does not validate the size of a memory block, which allows local users to cause a denial of service (memory corruption) or possibly gain privileges via crafted mmap operations, | 0,6% | — |
| CVE-2026-84001 | HIGH 7.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Key Distribution Center allows an unauthorized attacker to deny service over a network. | 0,6% | — |
| CVE-2026-81380 | MED 5.3 | microsoft visual_studio_code Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network. | 0,6% | — |
| CVE-2026-70332 | CRIT 9.6 | microsoft sharepoint_online Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | 0,6% | — |
| CVE-2026-70178 | HIGH 8.5 | microsoft fabric Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a network. | 0,6% | — |
| CVE-2026-65818 | HIGH 8.5 | microsoft power_platform Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network. | 0,6% | — |
| CVE-2026-48586 | HIGH 7.5 | apache thrift Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the is | 0,6% | — |
| CVE-2026-43869 | HIGH 7.3 | apache thrift Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. | 0,6% | — |
| CVE-2026-30897 | MED 6.6 | fortinet fortiweb A stack-based buffer overflow vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow a remote authenticated attacker who can bypass sta | 0,6% | — |
| CVE-2026-24640 | MED 6.6 | fortinet fortiweb A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0.2 through 7.0.12 may allow a remote authenticated att | 0,6% | — |
| CVE-2025-48208 | HIGH 8.8 | apache hertzbeat Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache HertzBeat . The attacker needs to have an authenticated account with access, and the attack can only be triggered by crafting custom comman | 0,6% | — |
| CVE-2024-53206 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tcp: Fix use-after-free of nreq in reqsk_timer_handler(). The cited commit replaced inet_csk_reqsk_queue_drop_and_put() with __inet_csk_reqsk_queue_drop() and reqsk_put() in reqsk_timer_hand | 0,6% | — |
| CVE-2024-49051 | HIGH 7.8 | microsoft pc_manager Microsoft PC Manager Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2024-46670 | HIGH 7.5 | fortinet fortios An Out-of-bounds Read vulnerability [CWE-125] in FortiOS version 7.6.0, version 7.4.4 and below, version 7.2.9 and below and FortiSASE FortiOS tenant version 24.3.b IPsec IKE service may allow an unauthenticated remote attacker to trigger memory consumption le | 0,6% | — |
| CVE-2024-43551 | HIGH 7.8 | microsoft windows_10_1607 Windows Storage Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2024-38098 | HIGH 7.8 | microsoft azure_connected_machine_agent Azure Connected Machine Agent Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2023-36831 | HIGH 7.5 | juniper junos An Improper Check or Handling of Exceptional Conditions vulnerability in the UTM (Unified Threat Management) Web-Filtering feature of Juniper Networks Junos OS on SRX Series causes a jbuf memory leak to occur when accessing certain websites, eventually leading | 0,6% | — |
| CVE-2023-21820 | HIGH 7.4 | microsoft windows_10 Windows Distributed File System (DFS) Remote Code Execution Vulnerability | 0,6% | — |
| CVE-2023-20899 | HIGH 7.5 | vmware sd-wan_edge_firmware VMware SD-WAN (Edge) contains a bypass authentication vulnerability. An unauthenticated attacker can download the Diagnostic bundle of the application under VMware SD-WAN Management. | 0,6% | — |