58.414 CVE seguite
792 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.414 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2023-33152 | HIGH 7.0 | microsoft 365_apps Microsoft ActiveX Remote Code Execution Vulnerability | 0,5% | — |
| CVE-2023-20181 | MED 6.1 | cisco spa500ds_firmware A vulnerability in the web-based management interface of Cisco Small Business SPA500 Series IP Phones could allow an unauthenticated, remote attacker to conduct XSS attacks. This vulnerability is due to insufficient validation of user-supplied input by the web | 0,5% | — |
| CVE-2022-37992 | HIGH 7.8 | microsoft windows_10 Windows Group Policy Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2021-1496 | HIGH 7.0 | cisco anyconnect_secure_mobility_client Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the application. A successful explo | 0,5% | — |
| CVE-2020-3385 | MED 6.5 | cisco sd-wan_firmware A vulnerability in the deep packet inspection (DPI) engine of Cisco SD-WAN vEdge Routers could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected system. The vulnerability is due to insufficient handling of | 0,5% | — |
| CVE-2017-4028 | MED 5.0 | mcafee anti-virus_plus Maliciously misconfigured registry vulnerability in all Microsoft Windows products in McAfee consumer and corporate products allows an administrator to inject arbitrary code into a debugged McAfee process via manipulation of registry parameters. | 0,5% | — |
| CVE-2013-1124 | MED 5.8 | cisco network_admission_control The Cisco Network Admission Control (NAC) agent on Mac OS X does not verify the X.509 certificate of an Identity Services Engine (ISE) server during an SSL session, which allows man-in-the-middle attackers to spoof ISE servers via an arbitrary certificate, aka | 0,5% | — |
| CVE-2012-6399 | MED 5.8 | cisco webex Cisco WebEx 4.1 on iOS does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certi | 0,5% | — |
| CVE-2012-4117 | MED 5.8 | cisco unified_computing_system The fabric-interconnect component in Cisco Unified Computing System (UCS) does not properly verify X.509 certificates, which allows man-in-the-middle attackers to watch SSL KVM video-channel traffic or modify this traffic via a crafted certificate, aka Bug ID | 0,5% | — |
| CVE-2012-2499 | MED 5.8 | cisco anyconnect_secure_mobility_client The IPsec implementation in Cisco AnyConnect Secure Mobility Client 3.0 before 3.0.08057 does not verify the certificate name in an X.509 certificate, which allows man-in-the-middle attackers to spoof servers via a crafted certificate, aka Bug ID CSCtz26985. | 0,5% | — |
| CVE-2008-1675 | HIGH 7.2 | linux linux_kernel The bdx_ioctl_priv function in the tehuti driver (tehuti.c) in Linux kernel 2.6.x before 2.6.25.1 does not properly check certain information related to register size, which has unspecified impact and local attack vectors, probably related to reading or writin | 0,5% | — |
| CVE-2005-0529 | LOW 2.1 | linux linux_kernel Linux kernel 2.6.10 and 2.6.11rc1-bk6 uses different size types for offset arguments to the proc_file_read and locks_read_proc functions, which leads to a heap-based buffer overflow when a signed comparison causes negative integers to be used in a positive con | 0,5% | — |
| CVE-2026-77487 | HIGH 8.8 | microsoft sql_server_2017 Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network. | 0,5% | — |
| CVE-2026-77483 | HIGH 8.8 | microsoft sql_server_2017 Weak authentication in SQL Server allows an authorized attacker to elevate privileges over a network. | 0,5% | — |
| CVE-2026-77480 | HIGH 8.8 | microsoft sql_server_2017 Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network. | 0,5% | — |
| CVE-2026-73028 | HIGH 8.8 | microsoft sql_server_2017 Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network. | 0,5% | — |
| CVE-2026-66305 | HIGH 7.1 | microsoft skype_for_business_server Use of client-side authentication in Skype for Business allows an authorized attacker to perform spoofing over a network. | 0,5% | — |
| CVE-2026-49872 | HIGH 8.1 | apache apisix Improper Authentication vulnerability in Apache APISIX. When the cas-auth plugin is used in a route, an attacker can possibly authenticate itself with credentials from a different source. This issue affects Apache APISIX: from 3.0.0 through 3.16.0. Users are | 0,5% | — |
| CVE-2026-25854 | MED 6.1 | apache tomcat Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via the LoadBalancerDrainingValve. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M23 through 9.0.115, | 0,5% | — |
| CVE-2025-47436 | CRIT 9.8 | apache orc Heap-based Buffer Overflow vulnerability in Apache ORC. A vulnerability has been identified in the ORC C++ LZO decompression logic, where specially crafted malformed ORC files can cause the decompressor to allocate a 250-byte buffer but then attempts to copy | 0,5% | — |
| CVE-2024-53679 | MED 5.4 | apache vcl Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache VCL in the User Lookup form. A user with sufficient rights to be able to view this part of the site can craft a URL or be tricked in to clicking a URL | 0,5% | — |
| CVE-2024-42225 | HIGH 8.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: replace skb_put with skb_put_zero Avoid potentially reusing uninitialized data | 0,5% | — |
| CVE-2024-38623 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Use variable length array instead of fixed size Should fix smatch warning: ntfs_set_label() error: __builtin_memcpy() 'uni->name' too small (20 vs 256) | 0,5% | — |
| CVE-2024-31495 | MED 4.3 | fortinet fortiportal A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiPortal versions 7.0.0 through 7.0.6 and version 7.2.0 allows privileged user to obtain unauthorized information via the report download functionality. | 0,5% | — |
| CVE-2023-6606 | HIGH 7.1 | linux linux_kernel An out-of-bounds read vulnerability was found in smbCalcSize in fs/smb/client/netmisc.c in the Linux Kernel. This issue could allow a local attacker to crash the system or leak internal kernel information. | 0,5% | — |