58.412 CVE seguite
792 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.412 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2021-34779 | MED 4.3 | cisco business_220-16p-2g_firmware Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business 220 Series Smart Switches. An unauthenticated, adjacent attacker could perform the following: Execute code on the affected device or cause it to | 0,5% | — |
| CVE-2021-32466 | HIGH 7.0 | trendmicro housecall_for_home_networks An uncontrolled search path element privilege escalation vulnerability in Trend Micro HouseCall for Home Networks version 5.3.1225 and below could allow an attacker to escalate privileges by placing a custom crafted file in a specific directory to load a malic | 0,5% | — |
| CVE-2020-5940 | MED 5.4 | f5 big-ip_access_policy_manager In versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, and 14.1.0-14.1.2.3, a stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Traffic Management User Interface (TMUI), also known as the BIG-IP Configuration utility. | 0,5% | — |
| CVE-2020-5853 | MED 5.4 | f5 big-ip_access_policy_manager In BIG-IP APM portal access on versions 15.0.0-15.1.0, 14.0.0-14.1.2.3, 13.1.0-13.1.3.2, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, when backend servers serve HTTP pages with special JavaScript code, this can lead to internal portal access name conflict. | 0,5% | — |
| CVE-2020-3975 | MED 5.4 | vmware app_volumes VMware App Volumes 2.x prior to 2.18.6 and VMware App Volumes 4 prior to 2006 contain a Stored Cross-Site Scripting (XSS) vulnerability. A malicious actor with access to create and edit applications or create storage groups, may be able to inject malicious scr | 0,5% | — |
| CVE-2019-15711 | HIGH 7.8 | fortinet forticlient A privilege escalation vulnerability in FortiClient for Linux 6.2.1 and below may allow an user with low privilege to run system commands under root privilege via injecting specially crafted "ExportLogs" type IPC client requests to the fctsched process. | 0,5% | — |
| CVE-2019-0023 | MED 5.4 | juniper advanced_threat_prevention A persistent cross-site scripting (XSS) vulnerability in the Golden VM menu of Juniper ATP may allow authenticated user to inject arbitrary script and steal sensitive data and credentials from a web administration session, possibly tricking a follow-on adminis | 0,5% | — |
| CVE-2019-0018 | MED 5.4 | juniper advanced_threat_prevention A persistent cross-site scripting (XSS) vulnerability in the file upload menu of Juniper ATP may allow an authenticated user to inject arbitrary scripts and steal sensitive data and credentials from a web administration session, possibly tricking a follow-on a | 0,5% | — |
| CVE-2012-2137 | MED 6.9 | canonical ubuntu_linux Buffer overflow in virt/kvm/irq_comm.c in the KVM subsystem in the Linux kernel before 3.2.24 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to Message Signaled Interrupts (MSI), irq routing entr | 0,5% | — |
| CVE-2026-50076 | CRIT 9.1 | apache fory Deserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-core Java SDK before 1.1.0 on Java/JVM platforms allows a remote attacker to bypass class registration, TypeChecker, and DisallowedList checks and invoke classpath-present r | 0,5% | — |
| CVE-2026-49099 | MED 5.3 | apache camel Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel Salesforce Component. The camel-salesforce producer resolves its operation param | 0,5% | — |
| CVE-2026-45635 | HIGH 8.1 | microsoft windows_10_1607 Access of resource using incompatible type ('type confusion') in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network. | 0,5% | — |
| CVE-2026-45599 | HIGH 8.1 | microsoft windows_10_1607 Use after free in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network. | 0,5% | — |
| CVE-2026-41613 | HIGH 8.8 | microsoft visual_studio_code Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. | 0,5% | — |
| CVE-2026-24880 | HIGH 7.5 | apache tomcat Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat via invalid chunk extension. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M1 throug | 0,5% | — |
| CVE-2026-14958 | CRIT 9.1 | ibm aspera_faspex IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to unquoted shell interpolation. | 0,5% | — |
| CVE-2025-62555 | HIGH 7.0 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0,5% | — |
| CVE-2025-48418 | MED 6.7 | fortinet fortianalyzer A hidden functionality vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2.0 through 7.2.10, FortiAnalyzer 7.0.0 through 7.0.14, FortiAnalyzer 6.4 all versions, FortiAnalyzer Cloud 7.6.2, FortiAnaly | 0,5% | — |
| CVE-2024-21439 | HIGH 7.0 | microsoft windows_10_1507 Windows Telephony Server Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2024-20502 | MED 5.8 | cisco meraki_mx100_firmware A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to insuffici | 0,5% | — |
| CVE-2023-39191 | HIGH 8.2 | fedoraproject fedora An improper input validation flaw was found in the eBPF subsystem in the Linux kernel. The issue occurs due to a lack of proper validation of dynamic pointers within user-supplied eBPF programs prior to executing them. This may allow an attacker with CAP_BPF p | 0,5% | — |
| CVE-2023-35353 | HIGH 7.8 | microsoft windows_10_1607 Connected User Experiences and Telemetry Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2023-35326 | MED 5.5 | microsoft windows_10_1809 Windows CDP User Components Information Disclosure Vulnerability | 0,5% | — |
| CVE-2023-35324 | MED 5.5 | microsoft windows_10_1507 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | 0,5% | — |
| CVE-2023-35306 | MED 5.5 | microsoft windows_10_1507 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | 0,5% | — |