EN
57.620 CVE seguite
783 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

57.620 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più alto In KEV dal, ordina dal più alto
CVE-2017-20123 HIGH 8.8 sparklabs viscosity A vulnerability was found in Viscosity 1.6.7. It has been classified as critical. This affects an unknown part of the component DLL Handler. The manipulation leads to untrusted search path. It is possible to initiate the attack remotely. The exploit has been d 1,3%
CVE-2025-29828 HIGH 8.1 microsoft windows_11_22h2 Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to execute code over a network. 1,3%
CVE-2024-31864 CRIT 9.8 apache zeppelin Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Zeppelin. The attacker can inject sensitive configuration or malicious code when connecting MySQL database via JDBC driver. This issue affects Apache Zeppelin: before 0.11.1. U 1,3%
CVE-2020-1331 MED 5.4 microsoft system_center_operations_manager A spoofing vulnerability exists when System Center Operations Manager (SCOM) does not properly sanitize a specially crafted web request to an affected SCOM instance, aka 'System Center Operations Manager Spoofing Vulnerability'. 1,3%
CVE-2019-9962 HIGH 7.8 xnview xnview_mp XnView MP 0.93.1 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to VCRUNTIME140!memcpy. 1,3%
CVE-2019-1860 MED 5.9 cisco unified_intelligence_center A vulnerability in the dashboard gadget rendering of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to obtain or manipulate sensitive information between a user’s browser and Cisco Unified Intelligence Center. The vulne 1,3%
CVE-2018-0195 HIGH 8.8 cisco ios_xe A vulnerability in the Cisco IOS XE Software REST API could allow an authenticated, remote attacker to bypass API authorization checks and use the API to perform privileged actions on an affected device. The vulnerability is due to insufficient authorization c 1,3%
CVE-2023-41771 HIGH 8.1 microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability 1,3%
CVE-2023-41770 HIGH 8.1 microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability 1,3%
CVE-2023-41769 HIGH 8.1 microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability 1,3%
CVE-2023-41768 HIGH 8.1 microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability 1,3%
CVE-2023-41767 HIGH 8.1 microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability 1,3%
CVE-2023-41765 HIGH 8.1 microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability 1,3%
CVE-2023-38166 HIGH 8.1 microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability 1,3%
CVE-2023-23400 HIGH 7.2 microsoft windows_server_2012 Windows DNS Server Remote Code Execution Vulnerability 1,3%
CVE-2022-42466 MED 6.1 apache isis Prior to 2.0.0-M9, it was possible for an end-user to set the value of an editable string property of a domain object to a value that would be rendered unchanged when the value was saved. In particular, the end-user could enter javascript or similar and this w 1,3%
CVE-2016-1322 HIGH 7.5 cisco spark The REST interface in Cisco Spark 2015-07-04 allows remote attackers to bypass intended access restrictions and create arbitrary user accounts via unspecified web requests, aka Bug ID CSCuv72584. 1,3%
CVE-2016-1299 MED 5.3 cisco 300_series_managed_switch_firmware The web-management GUI implementation on Cisco Small Business SG300 devices 1.4.1.x allows remote attackers to cause a denial of service (HTTPS outage) via crafted HTTPS requests, aka Bug ID CSCuw87174. 1,3%
CVE-2011-2731 MED 5.1 vmware springsource_spring_security Race condition in the RunAsManager mechanism in VMware SpringSource Spring Security before 2.0.7 and 3.0.x before 3.0.6 stores the Authentication object in the shared security context, which allows attackers to gain privileges via a crafted thread. 1,3%
CVE-2023-20900 HIGH 7.1 debian debian_linux A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html  in a target virtual machine may be able to elevate their privileges if that targe 1,3%
CVE-2021-43220 LOW 3.1 microsoft edge_ios Microsoft Edge for iOS Spoofing Vulnerability 1,3%
CVE-2021-42308 LOW 3.1 microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability 1,3%
CVE-2018-0149 MED 4.8 cisco integrated_management_controller_supervisor A vulnerability in the web-based management interface of Cisco Integrated Management Controller Supervisor Software and Cisco UCS Director Software could allow an authenticated, remote attacker to conduct a Document Object Model-based (DOM-based), stored cross 1,3%
CVE-2014-2146 MED 6.5 cisco ios The Zone-Based Firewall (ZBFW) functionality in Cisco IOS, possibly 15.4 and earlier, and IOS XE, possibly 3.13 and earlier, mishandles zone checking for existing sessions, which allows remote attackers to bypass intended resource-access restrictions via spoof 1,3%
CVE-2009-1337 MED 4.4 linux linux_kernel The exit_notify function in kernel/exit.c in the Linux kernel before 2.6.30-rc1 does not restrict exit signals when the CAP_KILL capability is held, which allows local users to send an arbitrary signal to a process by running a program that modifies the exit_s 1,3%