57.613 CVE seguite
783 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.613 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2019-0063 | MED 6.5 | juniper junos When an MX Series Broadband Remote Access Server (BRAS) is configured as a Broadband Network Gateway (BNG) with DHCPv6 enabled, jdhcpd might crash when receiving a specific crafted DHCP response message on a subscriber interface. The daemon automatically resta | 1,3% | — |
| CVE-2019-0050 | HIGH 7.5 | juniper junos Under certain heavy traffic conditions srxpfe process can crash and result in a denial of service condition for the SRX1500 device. Repeated crashes of the srxpfe can result in an extended denial of service condition. The SRX device may fail to forward traffic | 1,3% | — |
| CVE-2016-6419 | HIGH 7.5 | cisco secure_firewall_management_center SQL injection vulnerability in Cisco Firepower Management Center 4.10.3 through 5.4.0 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCur25485. | 1,3% | — |
| CVE-2010-4202 | CRIT 9.8 | google chrome Multiple integer overflows in Google Chrome before 7.0.517.44 on Linux allow remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted font. | 1,3% | — |
| CVE-2010-2977 | HIGH 10.0 | cisco unified_wireless_network_solution_software Cisco Unified Wireless Network (UWN) Solution 7.x before 7.0.98.0 does not properly implement TLS and SSL, which has unspecified impact and remote attack vectors, aka Bug ID CSCtd01611. | 1,3% | — |
| CVE-2026-70321 | HIGH 8.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 1,3% | — |
| CVE-2024-47810 | HIGH 8.8 | foxit pdf_editor A use-after-free vulnerability exists in the way Foxit Reader 2024.3.0.26795 handles a 3D page object. A specially crafted Javascript code inside a malicious PDF document can trigger this vulnerability, which can lead to memory corruption and result in arbitra | 1,3% | — |
| CVE-2021-40127 | MED 5.3 | cisco sf200-24_firmware A vulnerability in the web-based management interface of Cisco Small Business 200 Series Smart Switches, Cisco Small Business 300 Series Managed Switches, and Cisco Small Business 500 Series Stackable Managed Switches could allow an unauthenticated, remote att | 1,3% | — |
| CVE-2021-34785 | MED 6.5 | cisco broadworks_commpilot_application_software Multiple vulnerabilities in Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to delete arbitrary user accounts or gain elevated privileges on an affected system. | 1,3% | — |
| CVE-2021-28321 | HIGH 7.8 | microsoft visual_studio Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability | 1,3% | — |
| CVE-2021-1350 | MED 5.3 | cisco umbrella A vulnerability in the web UI of Cisco Umbrella could allow an unauthenticated, remote attacker to negatively affect the performance of this service. The vulnerability exists due to insufficient rate limiting controls in the web UI. An attacker could exploit t | 1,3% | — |
| CVE-2020-3405 | HIGH 7.3 | cisco sd-wan_firmware A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system. The vulnerability is due to improper handling of XML External Entity | 1,3% | — |
| CVE-2020-3164 | MED 5.3 | cisco cloud_email_security A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated remote attacker to cause h | 1,3% | — |
| CVE-2019-4568 | MED 5.9 | ibm mq IBM MQ and IBM MQ Appliance 8.0 and 9.0 LTS could allow a remote attacker with intimate knowledge of the server to cause a denial of service when receiving data on the channel. IBM X-Force ID: 166629. | 1,3% | — |
| CVE-2018-15456 | MED 4.3 | cisco identity_services_engine A vulnerability in the Admin Portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to view saved passwords in plain text. The vulnerability is due to the incorrect inclusion of saved passwords when loading configuration p | 1,3% | — |
| CVE-2018-15382 | HIGH 8.6 | cisco hyperflex_hx_data_platform A vulnerability in Cisco HyperFlex Software could allow an unauthenticated, remote attacker to generate valid, signed session tokens. The vulnerability is due to a static signing key that is present in all Cisco HyperFlex systems. An attacker could exploit thi | 1,3% | — |
| CVE-2017-0585 | MED 4.7 | linux linux_kernel An information disclosure vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Produc | 1,3% | — |
| CVE-2025-58782 | MED 6.5 | apache jackrabbit Deserialization of Untrusted Data vulnerability in Apache Jackrabbit Core and Apache Jackrabbit JCR Commons. This issue affects Apache Jackrabbit Core: from 1.0.0 through 2.22.1; Apache Jackrabbit JCR Commons: from 1.0.0 through 2.22.1. Deployments that acce | 1,3% | — |
| CVE-2024-38194 | HIGH 8.4 | microsoft azure_web_apps An authenticated attacker can exploit an improper authorization vulnerability in Azure Web Apps to elevate privileges over a network. | 1,3% | — |
| CVE-2024-38099 | MED 5.9 | microsoft windows_server_2008 Windows Remote Desktop Licensing Service Denial of Service Vulnerability | 1,3% | — |
| CVE-2024-32007 | HIGH 7.5 | apache cxf An improper input validation of the p2c parameter in the Apache CXF JOSE code before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform a denial of service attack by specifying a large value for this parameter in a token. | 1,3% | — |
| CVE-2020-8258 | HIGH 7.5 | citrix gateway_plug-in Improper privilege management on services run by Citrix Gateway Plug-in for Windows, versions before and including 13.0-61.48 and 12.1-58.15, allows an attacker to modify arbitrary files. | 1,3% | — |
| CVE-2020-3561 | MED 4.7 | cisco adaptive_security_appliance A vulnerability in the Clientless SSL VPN (WebVPN) of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to inject arbitrary HTTP headers in the responses of the af | 1,3% | — |
| CVE-2017-7733 | MED 6.1 | fortinet fortios A Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiOS 5.4.0 to 5.4.5 and 5.6.0 allows a remote unauthenticated attacker to execute arbitrary javascript code via webUI "Login Disclaimer" redir parameter. | 1,3% | — |
| CVE-2017-6755 | MED 6.1 | cisco prime_collaboration_provisioning A vulnerability in the web portal of the Cisco Prime Collaboration Provisioning (PCP) Tool could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system. More Informatio | 1,3% | — |