57.551 CVE seguite
783 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.551 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2017-5060 | MED 6.5 | google chrome Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 58.0.3029.81 for Mac, Windows, and Linux, and 58.0.3029.83 for Android, allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name. | 1,3% | — |
| CVE-2016-9072 | HIGH 7.5 | mozilla firefox When a new Firefox profile is created on 64-bit Windows installations, the sandbox for 64-bit NPAPI plugins is not enabled by default. Note: This issue only affects 64-bit Windows. 32-bit Windows and other operating systems are unaffected. This vulnerability a | 1,3% | — |
| CVE-2015-4314 | MED 4.0 | cisco telepresence_video_communication_server_software The System Snapshot feature in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.1 allows remote authenticated users to obtain sensitive password-hash information by reading the snapshot file, aka Bug ID CSCuv40422. | 1,3% | — |
| CVE-2015-4295 | MED 4.0 | cisco unified_communications_manager The Prime Collaboration Deployment component in Cisco Unified Communications Manager 10.5(3.10000.9) allows remote authenticated users to discover root credentials via a direct request to an unspecified URL, aka Bug ID CSCuv21819. | 1,3% | — |
| CVE-2022-24280 | MED 6.5 | apache pulsar Improper Input Validation vulnerability in Proxy component of Apache Pulsar allows an attacker to make TCP/IP connection attempts that originate from the Pulsar Proxy's IP address. When the Apache Pulsar Proxy component is used, it is possible to attempt to op | 1,3% | — |
| CVE-2021-23008 | CRIT 9.8 | f5 big-ip_access_policy_manager On version 15.1.x before 15.1.3, 14.1.x before 14.1.4, 13.1.x before 13.1.4, 12.1.x before 12.1.6, and all versions of 16.0.x and 11.6.x., BIG-IP APM AD (Active Directory) authentication can be bypassed via a spoofed AS-REP (Kerberos Authentication Service Res | 1,3% | — |
| CVE-2019-1254 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when Windows Hyper-V writes uninitialized memory to disk, aka 'Windows Hyper-V Information Disclosure Vulnerability'. | 1,3% | — |
| CVE-2001-0741 | LOW 2.1 | cisco hsrp Cisco Hot Standby Routing Protocol (HSRP) allows local attackers to cause a denial of service by spoofing HSRP packets. | 1,3% | — |
| CVE-2024-38029 | HIGH 7.5 | microsoft windows_server_2022_23h2 Microsoft OpenSSH for Windows Remote Code Execution Vulnerability | 1,3% | — |
| CVE-2024-20690 | MED 6.5 | microsoft windows_10_1809 Windows Nearby Sharing Spoofing Vulnerability | 1,3% | — |
| CVE-2023-42788 | HIGH 7.8 | fortinet fortianalyzer An improper neutralization of special elements used in an os command ('OS Command Injection') vulnerability [CWE-78] in FortiManager & FortiAnalyzer version 7.4.0, version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.8, version 6.4.0 through 6.4.12 and versi | 1,3% | — |
| CVE-2023-36564 | MED 6.5 | microsoft windows_10_1507 Windows Search Security Feature Bypass Vulnerability | 1,3% | — |
| CVE-2022-20751 | HIGH 8.6 | cisco secure_firewall_threat_defense A vulnerability in the Snort detection engine integration for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause unlimited memory consumption, which could lead to a denial of service (DoS) condition on an aff | 1,3% | — |
| CVE-2022-20746 | HIGH 8.6 | cisco secure_firewall_threat_defense A vulnerability in the TCP proxy functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerability is due to improper handling of TCP flows. An atta | 1,3% | — |
| CVE-2022-20715 | HIGH 8.6 | cisco adaptive_security_appliance_software A vulnerability in the remote access SSL VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affec | 1,3% | — |
| CVE-2018-5502 | HIGH 7.5 | f5 big-ip_access_policy_manager On F5 BIG-IP versions 13.0.0 - 13.1.0.3, attackers may be able to disrupt services on the BIG-IP system with maliciously crafted client certificate. This vulnerability affects virtual servers associated with Client SSL profile which enables the use of client c | 1,3% | — |
| CVE-2018-1751 | MED 5.9 | ibm security_key_lifecycle_manager IBM Security Key Lifecycle Manager 3.0 through 3.0.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 148512. | 1,3% | — |
| CVE-2017-4922 | MED 6.5 | vmware vcenter_server VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure issue due to the service startup script using world writable directories as temporary storage for critical information. Successful exploitation of this issue may allow unprivileged | 1,3% | — |
| CVE-2013-5505 | MED 4.3 | cisco identity_services_engine_software Cross-site scripting (XSS) vulnerability in an administration page in Cisco Identity Services Engine (ISE) allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCui30275. | 1,3% | — |
| CVE-2013-3448 | MED 4.0 | cisco webex_meetings_server Cisco WebEx Meetings Server does not check whether a user account is active, which allows remote authenticated users to bypass intended access restrictions by performing meeting operations after account deactivation, aka Bug ID CSCuh33315. | 1,3% | — |
| CVE-2026-62911 | HIGH 8.0 | microsoft exchange_server Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | 1,3% | — |
| CVE-2024-0590 | MED 6.1 | microsoft clarity The Microsoft Clarity plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.9.3. This is due to missing nonce validation on the edit_clarity_project_id() function. This makes it possible for unauthenticated at | 1,3% | — |
| CVE-2023-23779 | MED 6.8 | fortinet fortiweb Multiple improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in FortiWeb version 7.0.1 and below, 6.4 all versions, version 6.3.19 and below may allow an authenticated attacker to execute unauthor | 1,3% | — |
| CVE-2022-3621 | MED 4.3 | debian debian_linux A vulnerability was found in Linux Kernel. It has been classified as problematic. Affected is the function nilfs_bmap_lookup_at_level of the file fs/nilfs2/inode.c of the component nilfs2. The manipulation leads to null pointer dereference. It is possible to l | 1,3% | — |
| CVE-2022-20724 | MED 5.5 | cisco cgr1000_compute_module Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system | 1,3% | — |