EN
58.306 CVE seguite
789 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.306 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più alto In KEV dal, ordina dal più alto
CVE-2019-16008 MED 5.4 cisco ip_phone_6821_firmware A vulnerability in the web-based GUI of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface of an affected 0,6% —
CVE-2019-15968 MED 5.4 cisco hosted_collaboration_solution A vulnerability in the web-based management interface of Cisco Unified Communications Domain Manager (Unified CDM) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface 0,6% —
CVE-2019-12702 MED 5.4 cisco spa112_firmware A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to conduct cross-site scripting attacks. The vulnerability is due to insufficient validation of user-sup 0,6% —
CVE-2019-12638 MED 5.4 cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web-based management interface. The vulnerability is 0,6% —
CVE-2019-12637 MED 5.4 cisco identity_services_engine Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web-based management interface. The vulnera 0,6% —
CVE-2019-0024 MED 5.4 juniper advanced_threat_prevention A persistent cross-site scripting (XSS) vulnerability in the Email Collectors menu of Juniper ATP may allow authenticated user to inject arbitrary script and steal sensitive data and credentials from a web administration session, possibly tricking a follow-on 0,6% —
CVE-2013-6763 MED 6.9 linux linux_kernel The uio_mmap_physical function in drivers/uio/uio.c in the Linux kernel before 3.12 does not validate the size of a memory block, which allows local users to cause a denial of service (memory corruption) or possibly gain privileges via crafted mmap operations, 0,6% —
CVE-2026-84001 HIGH 7.5 microsoft windows_10_1607 Out-of-bounds read in Windows Key Distribution Center allows an unauthorized attacker to deny service over a network. 0,6% —
CVE-2026-81380 MED 5.3 microsoft visual_studio_code Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network. 0,6% —
CVE-2026-70332 CRIT 9.6 microsoft sharepoint_online Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. 0,6% —
CVE-2026-70178 HIGH 8.5 microsoft fabric Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a network. 0,6% —
CVE-2026-65818 HIGH 8.5 microsoft power_platform Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network. 0,6% —
CVE-2026-48586 HIGH 7.5 apache thrift Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the is 0,6% —
CVE-2026-43869 HIGH 7.3 apache thrift Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. 0,6% —
CVE-2026-30897 MED 6.6 fortinet fortiweb A stack-based buffer overflow vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow a remote authenticated attacker who can bypass sta 0,6% —
CVE-2026-24640 MED 6.6 fortinet fortiweb A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0.2 through 7.0.12 may allow a remote authenticated att 0,6% —
CVE-2025-48208 HIGH 8.8 apache hertzbeat Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache HertzBeat . The attacker needs to have an authenticated account with access, and the attack can only be triggered by crafting custom comman 0,6% —
CVE-2024-53206 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tcp: Fix use-after-free of nreq in reqsk_timer_handler(). The cited commit replaced inet_csk_reqsk_queue_drop_and_put() with __inet_csk_reqsk_queue_drop() and reqsk_put() in reqsk_timer_hand 0,6% —
CVE-2024-49051 HIGH 7.8 microsoft pc_manager Microsoft PC Manager Elevation of Privilege Vulnerability 0,6% —
CVE-2024-46670 HIGH 7.5 fortinet fortios An Out-of-bounds Read vulnerability [CWE-125] in FortiOS version 7.6.0, version 7.4.4 and below, version 7.2.9 and below and FortiSASE FortiOS tenant version 24.3.b IPsec IKE service may allow an unauthenticated remote attacker to trigger memory consumption le 0,6% —
CVE-2024-43551 HIGH 7.8 microsoft windows_10_1607 Windows Storage Elevation of Privilege Vulnerability 0,6% —
CVE-2024-38098 HIGH 7.8 microsoft azure_connected_machine_agent Azure Connected Machine Agent Elevation of Privilege Vulnerability 0,6% —
CVE-2023-36831 HIGH 7.5 juniper junos An Improper Check or Handling of Exceptional Conditions vulnerability in the UTM (Unified Threat Management) Web-Filtering feature of Juniper Networks Junos OS on SRX Series causes a jbuf memory leak to occur when accessing certain websites, eventually leading 0,6% —
CVE-2023-21820 HIGH 7.4 microsoft windows_10 Windows Distributed File System (DFS) Remote Code Execution Vulnerability 0,6% —
CVE-2023-20899 HIGH 7.5 vmware sd-wan_edge_firmware VMware SD-WAN (Edge) contains a bypass authentication vulnerability. An unauthenticated attacker can download the Diagnostic bundle of the application under VMware SD-WAN Management. 0,6% —