57.057 CVE seguite
777 Sfruttate ora
184 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.057 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2016-1352 | CRIT 9.8 | cisco unified_computing_system_central_software Cisco Unified Computing System (UCS) Central Software 1.3(1b) and earlier allows remote attackers to execute arbitrary OS commands via a crafted HTTP request, aka Bug ID CSCuv33856. | 2,2% | — |
| CVE-2017-3818 | MED 5.8 | cisco email_security_appliance_firmware A vulnerability in the Multipurpose Internet Mail Extensions (MIME) scanner of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker to bypass configured user filters on the device, aka a Malformed MIM | 2,2% | — |
| CVE-2013-1295 | HIGH 7.2 | microsoft windows_server_2003 The Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP2, and Server 2008 SP2 does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "CSRSS Memo | 2,2% | — |
| CVE-2022-30193 | HIGH 7.8 | microsoft av1_video_extension AV1 Video Extension Remote Code Execution Vulnerability | 2,2% | — |
| CVE-2022-22018 | HIGH 7.8 | microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability | 2,2% | — |
| CVE-2015-0600 | MED 5.0 | cisco unified_ip_phones_9900_series_firmware The mobility extension on Cisco Unified IP 9900 phones with firmware 9.4(.1) and earlier allows remote attackers to cause a denial of service (logoff) via crafted packets, aka Bug ID CSCuq12139. | 2,2% | — |
| CVE-2014-3345 | MED 5.0 | cisco transport_gateway_installation_software The web framework in Cisco Transport Gateway for Smart Call Home (aka TG-SCH or Transport Gateway Installation Software) 4.0 does not properly check authorization for administrative web pages, which allows remote attackers to modify the product via a crafted U | 2,2% | — |
| CVE-2020-23922 | HIGH 7.1 | apache bookkeeper An issue was discovered in giflib through 5.1.4. DumpScreen2RGB in gif2rgb.c has a heap-based buffer over-read. | 2,2% | — |
| CVE-2014-2109 | HIGH 7.8 | cisco ios The TCP Input module in Cisco IOS 12.2 through 12.4 and 15.0 through 15.4, when NAT is used, allows remote attackers to cause a denial of service (memory consumption or device reload) via crafted TCP packets, aka Bug IDs CSCuh33843 and CSCuj41494. | 2,2% | — |
| CVE-2008-0029 | HIGH 10.0 | cisco application_velocity_system Cisco Application Velocity System (AVS) before 5.1.0 is installed with default passwords for some system accounts, which allows remote attackers to gain privileges. | 2,2% | — |
| CVE-2005-3059 | HIGH 10.0 | opera opera_browser Multiple unspecified vulnerabilities in Opera 8.50 on Linux and Windows have unknown impact and attack vectors, related to (1) " handling of must-revalidate cache directive for HTTPS pages" or (2) a "display issue with cookie comment encoding." | 2,2% | — |
| CVE-2022-35772 | HIGH 7.2 | microsoft azure_site_recovery_vmware_to_azure Azure Site Recovery Remote Code Execution Vulnerability | 2,2% | — |
| CVE-2022-30139 | HIGH 7.5 | microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 2,2% | — |
| CVE-2021-43233 | HIGH 7.5 | microsoft windows_10 Remote Desktop Client Remote Code Execution Vulnerability | 2,2% | — |
| CVE-2020-1172 | MED 4.2 | microsoft chakracore <p>A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An | 2,2% | — |
| CVE-2020-1057 | MED 4.2 | microsoft chakracore <p>A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An | 2,2% | — |
| CVE-2019-1704 | HIGH 7.5 | cisco secure_firewall_threat_defense Multiple vulnerabilities in the Server Message Block (SMB) Protocol preprocessor detection engine for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, adjacent or remote attacker to cause a denial of service (DoS) condition. For mo | 2,2% | — |
| CVE-2018-17539 | HIGH 7.5 | f5 big-ip_local_traffic_manager The BGP daemon (bgpd) in all IP Infusion ZebOS versions to 7.10.6 and all OcNOS versions to 1.3.3.145 allow remote attackers to cause a denial of service attack via an autonomous system (AS) path containing 8 or more autonomous system number (ASN) elements. | 2,2% | — |
| CVE-2009-3885 | MED 5.0 | sun jre Sun Java SE 5.0 before Update 22 and 6 before Update 17 on Windows allows remote attackers to cause a denial of service via a BMP file containing a link to a UNC share pathname for an International Color Consortium (ICC) profile file, probably a related issue | 2,2% | — |
| CVE-2006-6588 | HIGH 7.5 | apache ofbiz The forum implementation in the ecommerce component in the Apache Open For Business Project (OFBiz) trusts the (1) dataResourceTypeId, (2) contentTypeId, and certain other hidden form fields, which allows remote attackers to create unauthorized types of conten | 2,2% | — |
| CVE-2026-64881 | HIGH 8.8 | tenable security_center The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command execution. This input validation failure enables command injection when chained with a related vulnerability. | 2,2% | — |
| CVE-2025-26647 | HIGH 8.8 | microsoft windows_server_2008 Improper input validation in Windows Kerberos allows an authorized attacker to elevate privileges over a network. | 2,2% | — |
| CVE-2021-34525 | HIGH 8.8 | microsoft windows_server_2012 Windows DNS Server Remote Code Execution Vulnerability | 2,2% | — |
| CVE-2021-34508 | HIGH 8.8 | microsoft windows_10 Windows Kernel Remote Code Execution Vulnerability | 2,2% | — |
| CVE-2017-2340 | MED 5.3 | juniper junos On Juniper Networks Junos OS 15.1 releases from 15.1R3 to 15.1R4, 16.1 prior to 16.1R3, on M/MX platforms where Enhanced Subscriber Management for DHCPv6 subscribers is configured, a vulnerability in processing IPv6 ND packets originating from subscribers and | 2,2% | — |