57.305 CVE seguite
782 Sfruttate ora
186 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.305 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2017-6614 | MED 6.5 | cisco findit_network_probe A vulnerability in the file-download feature of the web user interface for Cisco FindIT Network Probe Software 1.0.0 could allow an authenticated, remote attacker to download and view any system file by using the affected software. The vulnerability is due to | 1,7% | — |
| CVE-2007-4774 | MED 5.9 | linux linux_kernel The Linux kernel before 2.4.36-rc1 has a race condition. It was possible to bypass systrace policies by flooding the ptraced process with SIGCONT signals, which can can wake up a PTRACED process. | 1,7% | — |
| CVE-2020-3496 | MED 5.3 | cisco sf200-24_firmware A vulnerability in the IPv6 packet processing engine of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient | 1,7% | — |
| CVE-2016-7915 | MED 5.5 | linux linux_kernel The hid_input_field function in drivers/hid/hid-core.c in the Linux kernel before 4.6 allows physically proximate attackers to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read) by connecting a device, as demonstr | 1,7% | — |
| CVE-2013-3079 | HIGH 9.0 | vmware vcenter_server_appliance VMware vCenter Server Appliance (vCSA) 5.1 before Update 1 allows remote authenticated users to execute arbitrary programs with root privileges by leveraging Virtual Appliance Management Interface (VAMI) access. | 1,7% | — |
| CVE-2013-1334 | HIGH 7.2 | microsoft windows_7 win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, | 1,7% | — |
| CVE-2024-52318 | MED 6.1 | apache tomcat Incorrect object recycling and reuse vulnerability in Apache Tomcat. This issue affects Apache Tomcat: 11.0.0, 10.1.31, 9.0.96. Users are recommended to upgrade to version 11.0.1, 10.1.32 or 9.0.97, which fixes the issue. | 1,7% | — |
| CVE-2021-3752 | HIGH 7.1 | debian debian_linux A use-after-free flaw was found in the Linux kernel’s Bluetooth subsystem in the way user calls connect to the socket and disconnect simultaneously due to a race condition. This flaw allows a user to crash the system or escalate their privileges. The highest t | 1,7% | — |
| CVE-2018-8025 | HIGH 8.1 | apache hbase CVE-2018-8025 describes an issue in Apache HBase that affects the optional "Thrift 1" API server when running over HTTP. There is a race-condition which could lead to authenticated sessions being incorrectly applied to users, e.g. one authenticated user would | 1,7% | — |
| CVE-2017-6150 | HIGH 7.5 | f5 big-ip_access_policy_manager Under certain conditions for F5 BIG-IP systems 13.0.0 or 12.1.0 - 12.1.3.1, using FastL4 profiles, when the Reassemble IP Fragments option is disabled (default), some specific large fragmented packets may restart the Traffic Management Microkernel (TMM). | 1,7% | — |
| CVE-2016-9120 | HIGH 7.8 | linux linux_kernel Race condition in the ion_ioctl function in drivers/staging/android/ion/ion.c in the Linux kernel before 4.6 allows local users to gain privileges or cause a denial of service (use-after-free) by calling ION_IOC_FREE on two CPUs at the same time. | 1,7% | — |
| CVE-2014-3331 | MED 4.3 | cisco asr_5000_series_software The Session Manager component in Packet Data Network Gateway (aka PGW) in Cisco ASR 5000 Series Software 11.0, 12.0, 12.1, 12.2, 14.0, 15.0, 16.x through 16.1.2, and 17.0 allows remote attackers to cause a denial of service (process crash) via a crafted TCP pa | 1,7% | — |
| CVE-2008-1340 | HIGH 7.1 | vmware ace Virtual Machine Communication Interface (VMCI) in VMware Workstation 6.0.x before 6.0.3, VMware Player 2.0.x before 2.0.3, and VMware ACE 2.0.x before 2.0.1 allows attackers to cause a denial of service (host OS crash) via crafted VMCI calls that trigger "memo | 1,7% | — |
| CVE-2025-22226 | HIGH 7.1 | vmware cloud_foundation VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit this issue to leak memory from the vmx proce | 1,7% | |
| CVE-2023-21816 | HIGH 7.5 | microsoft windows_10 Windows Active Directory Domain Services API Denial of Service Vulnerability | 1,7% | — |
| CVE-2014-3376 | MED 5.0 | cisco ios_xr Cisco IOS XR 5.1 and earlier allows remote attackers to cause a denial of service (process reload) via a malformed RSVP packet, aka Bug ID CSCuq12031. | 1,7% | — |
| CVE-2014-3293 | MED 5.0 | cisco asr901 Cisco IOS 15.4(3)S0b on ASR901 devices makes incorrect decisions to use the CPU for IPv4 packet processing, which allows remote attackers to cause a denial of service (BGP neighbor flapping) by sending many crafted IPv4 packets, aka Bug ID CSCuo29736. | 1,7% | — |
| CVE-2001-0783 | MED 5.0 | cisco tftp_server Cisco TFTP server 1.1 allows remote attackers to read arbitrary files via a ..(dot dot) attack in the GET command. | 1,7% | — |
| CVE-2021-1574 | HIGH 8.8 | cisco business_process_automation Multiple vulnerabilities in the web-based management interface of Cisco Business Process Automation (BPA) could allow an authenticated, remote attacker to elevate privileges to Administrator. These vulnerabilities are due to improper authorization enforcement | 1,7% | — |
| CVE-2017-12215 | HIGH 7.1 | cisco asyncos A vulnerability in the email message filtering feature of Cisco AsyncOS Software for the Cisco Email Security Appliance could allow an unauthenticated, remote attacker to cause an affected device to run out of memory and stop scanning and forwarding email mess | 1,7% | — |
| CVE-2016-5344 | CRIT 9.8 | google android Multiple integer overflows in the MDSS driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allow attackers to cause a denial of service or possibly have unspecified other impac | 1,7% | — |
| CVE-2023-36907 | MED 5.5 | microsoft windows_10 Windows Cryptographic Services Information Disclosure Vulnerability | 1,7% | — |
| CVE-2023-36905 | MED 5.5 | microsoft windows_10 Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability | 1,7% | — |
| CVE-2023-36419 | HIGH 8.8 | microsoft azure_hdinsight Azure HDInsight Apache Oozie Workflow Scheduler XXE Elevation of Privilege Vulnerability | 1,7% | — |
| CVE-2015-6427 | MED 5.0 | cisco firesight_system_software Cisco FireSIGHT Management Center allows remote attackers to bypass the HTTP attack detection feature and avoid triggering Snort IDS rules via an SSL session that is mishandled after decryption, aka Bug ID CSCux53437. | 1,7% | — |