58.306 CVE seguite
790 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.306 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2020-29010 | MED 5.0 | fortinet fortios An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS version 6.2.4 and below, version 6.0.10 and belowmay allow remote authenticated actors to read the SSL VPN events log entries of users in other VDOMs by executing "get vpn | 0,6% | — |
| CVE-2019-17056 | LOW 3.3 | linux linux_kernel llcp_sock_create in net/nfc/llcp_sock.c in the AF_NFC network module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means that unprivileged users can create a raw socket, aka CID-3a359798b176. | 0,6% | — |
| CVE-2018-0194 | HIGH 7.8 | cisco ios_xe Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commands into the CLI of the affected software, which could allow the attacker to gain access to the underlying Linux shell of | 0,6% | — |
| CVE-2018-0193 | HIGH 7.8 | cisco ios_xe Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commands into the CLI of the affected software, which could allow the attacker to gain access to the underlying Linux shell of | 0,6% | — |
| CVE-2018-0185 | HIGH 7.8 | cisco ios_xe Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commands into the CLI of the affected software, which could allow the attacker to gain access to the underlying Linux shell of | 0,6% | — |
| CVE-2018-0182 | HIGH 7.8 | cisco ios_xe Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commands into the CLI of the affected software, which could allow the attacker to gain access to the underlying Linux shell of | 0,6% | — |
| CVE-2026-7872 | HIGH 7.5 | langflow langflow IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files including the JWT signing key and forge authentication tokens for any user. | 0,6% | — |
| CVE-2026-65679 | HIGH 8.1 | microsoft windows_10_1607 Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network. | 0,6% | — |
| CVE-2026-26150 | HIGH 8.6 | microsoft purview_ediscovery Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network. | 0,6% | — |
| CVE-2026-26138 | HIGH 8.6 | microsoft purview Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network. | 0,6% | — |
| CVE-2026-22022 | HIGH 8.2 | apache solr Deployments of Apache Solr 5.3.0 through 9.10.0 that rely on Solr's "Rule Based Authorization Plugin" are vulnerable to allowing unauthorized access to certain Solr APIs, due to insufficiently strict input validation in those components. Only deployments that | 0,6% | — |
| CVE-2025-62565 | HIGH 7.3 | microsoft windows_10_1607 Use after free in Windows Shell allows an authorized attacker to elevate privileges locally. | 0,6% | — |
| CVE-2025-21359 | HIGH 7.8 | microsoft windows_10_1507 Windows Kernel Security Feature Bypass Vulnerability | 0,6% | — |
| CVE-2024-25037 | MED 4.3 | ibm cognos_controller IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser. | 0,6% | — |
| CVE-2023-28298 | MED 5.5 | microsoft windows_10_1607 Windows Kernel Denial of Service Vulnerability | 0,6% | — |
| CVE-2022-38604 | HIGH 7.3 | wacom driver Wacom Driver 6.3.46-1 for Windows and lower was discovered to contain an arbitrary file deletion vulnerability. | 0,6% | — |
| CVE-2022-22477 | MED 6.1 | ibm websphere_application_server IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a | 0,6% | — |
| CVE-2021-33033 | HIGH 7.8 | linux linux_kernel The Linux kernel before 5.11.14 has a use-after-free in cipso_v4_genopt in net/ipv4/cipso_ipv4.c because the CIPSO and CALIPSO refcounting for the DOI definitions is mishandled, aka CID-ad5d07f4a9cd. This leads to writing an arbitrary value. | 0,6% | — |
| CVE-2020-3505 | MED 6.5 | cisco 8000p_ip_camera_firmware A vulnerability in the Cisco Discovery Protocol of Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to cause a memory leak, which could lead to a denial of service (DoS) condition on an affected device. The vuln | 0,6% | — |
| CVE-2020-3114 | HIGH 8.8 | cisco data_center_network_manager A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insuffici | 0,6% | — |
| CVE-2020-25211 | MED 6.0 | debian debian_linux In the Linux kernel through 5.8.7, local attackers able to inject conntrack netlink configuration could overflow a local buffer, causing crashes or triggering use of incorrect protocol numbers in ctnetlink_parse_tuple_filter in net/netfilter/nf_conntrack_netli | 0,6% | — |
| CVE-2018-14734 | HIGH 7.8 | canonical ubuntu_linux drivers/infiniband/core/ucma.c in the Linux kernel through 4.17.11 allows ucma_leave_multicast to access a certain data structure after a cleanup step in ucma_process_join, which allows attackers to cause a denial of service (use-after-free). | 0,6% | — |
| CVE-2018-0446 | HIGH 8.8 | cisco network_level_service A vulnerability in the web-based management interface of Cisco Industrial Network Director could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerabil | 0,6% | — |
| CVE-2018-0445 | HIGH 8.8 | cisco packaged_contact_center_enterprise A vulnerability in the web-based management interface of Cisco Packaged Contact Center Enterprise could allow an unauthenticated, remote attacker to conduct a CSRF attack and perform arbitrary actions on an affected device. The vulnerability is due to insuffic | 0,6% | — |
| CVE-2017-10620 | HIGH 7.4 | juniper junos Juniper Networks Junos OS on SRX series devices do not verify the HTTPS server certificate before downloading anti-virus updates. This may allow a man-in-the-middle attacker to inject bogus signatures to cause service disruptions or make the device not detect | 0,6% | — |