57.620 CVE seguite
783 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.620 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2025-21273 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability | 1,3% | — |
| CVE-2025-21266 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability | 1,3% | — |
| CVE-2022-34862 | HIGH 7.5 | f5 big-ip_access_policy_manager In BIG-IP Versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, when an LTM virtual server is configured to perform normalization, undisclosed requests can cause the Traffic Management Microkernel (TMM) to t | 1,3% | — |
| CVE-2020-3537 | MED 5.7 | cisco jabber A vulnerability in Cisco Jabber for Windows software could allow an authenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper validation of message contents. An attacker could exploit this vulnerability by sen | 1,3% | — |
| CVE-2020-16961 | HIGH 7.8 | microsoft windows_10 Windows Backup Engine Elevation of Privilege Vulnerability | 1,3% | — |
| CVE-2020-16960 | HIGH 7.8 | microsoft windows_10 Windows Backup Engine Elevation of Privilege Vulnerability | 1,3% | — |
| CVE-2020-1268 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when a Windows service improperly handles objects in memory, aka 'Windows Service Information Disclosure Vulnerability'. | 1,3% | — |
| CVE-2020-1263 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists in the way Windows Error Reporting (WER) handles objects in memory, aka 'Windows Error Reporting Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1261. | 1,3% | — |
| CVE-2020-1261 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists in the way Windows Error Reporting (WER) handles objects in memory, aka 'Windows Error Reporting Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1263. | 1,3% | — |
| CVE-2020-1120 | MED 5.5 | microsoft windows_10 A denial of service vulnerability exists when Connected User Experiences and Telemetry Service improperly handles file operations, aka 'Connected User Experiences and Telemetry Service Denial of Service Vulnerability'. This CVE ID is unique from CVE-2020-1244. | 1,3% | — |
| CVE-2016-9217 | HIGH 8.8 | cisco intercloud_fabric A vulnerability in Cisco Intercloud Fabric for Business and Cisco Intercloud Fabric for Providers could allow an unauthenticated, remote attacker to connect to the database used by these products. More Information: CSCus99394. Known Affected Releases: 7.3(0)ZN | 1,3% | — |
| CVE-2015-0588 | MED 6.8 | cisco unified_communications_domain_manager Cross-site request forgery (CSRF) vulnerability in Cisco Unified Communications Domain Manager (UCDM) 10 allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuo77055. | 1,3% | — |
| CVE-2014-3305 | MED 6.8 | cisco webex_meetings_server Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers to hijack the authentication of unspecified victims via unknown vectors, aka Bug ID CSCuj81735. | 1,3% | — |
| CVE-2024-21390 | HIGH 7.1 | microsoft authenticator Microsoft Authenticator Elevation of Privilege Vulnerability | 1,3% | — |
| CVE-2023-33144 | MED 6.6 | microsoft visual_studio_code Visual Studio Code Spoofing Vulnerability | 1,3% | — |
| CVE-2018-0963 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka "Windows Kernel Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. | 1,3% | — |
| CVE-2017-3887 | MED 5.9 | cisco secure_firewall_threat_defense A vulnerability in the detection engine that handles Secure Sockets Layer (SSL) packets for Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition because the Snort process unexpectedly rest | 1,3% | — |
| CVE-2024-38129 | HIGH 7.5 | microsoft windows_server_2022_23h2 Windows Kerberos Elevation of Privilege Vulnerability | 1,3% | — |
| CVE-2024-25693 | CRIT 9.9 | esri portal_for_arcgis There is a path traversal in Esri Portal for ArcGIS versions <= 11.2. Successful exploitation may allow a remote, authenticated attacker to traverse the file system to access files or execute code outside of the intended directory. | 1,3% | — |
| CVE-2023-48791 | HIGH 8.8 | fortinet fortiportal An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in FortiPortal version 7.2.0, version 7.0.6 and below may allow a remote authenticated attacker with at least R/W permission to execute unauthorized c | 1,3% | — |
| CVE-2023-20855 | HIGH 8.8 | vmware vrealize_automation VMware vRealize Orchestrator contains an XML External Entity (XXE) vulnerability. A malicious actor, with non-administrative access to vRealize Orchestrator, may be able to use specially crafted input to bypass XML parsing restrictions leading to access to sen | 1,3% | — |
| CVE-2019-1053 | MED 6.3 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Shell fails to validate folder shortcuts. An attacker who successfully exploited the vulnerability could elevate privileges by escaping a sandbox. To exploit this vulnerability, an attacker would | 1,3% | — |
| CVE-2016-1324 | MED 5.3 | cisco spark The REST interface in Cisco Spark 2015-06 allows remote attackers to cause a denial of service (resource outage) by accessing an administrative page, aka Bug ID CSCuv84125. | 1,3% | — |
| CVE-2009-0623 | HIGH 7.8 | cisco ace_4710 Unspecified vulnerability in Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers before A2(1.3) and Cisco ACE 4710 Application Control Engine Appliance before A3(2.1) allows remote attackers to cause a denial of service (dev | 1,3% | — |
| CVE-2025-24064 | HIGH 8.1 | microsoft windows_server_2008 Use after free in DNS Server allows an unauthorized attacker to execute code over a network. | 1,3% | — |