57.638 CVE seguite
783 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.638 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2016-3134 | HIGH 8.4 | linux linux_kernel The netfilter subsystem in the Linux kernel through 4.5.2 does not validate certain offset fields, which allows local users to gain privileges or cause a denial of service (heap memory corruption) via an IPT_SO_SET_REPLACE setsockopt call. | 1,2% | — |
| CVE-2026-43512 | CRIT 9.8 | apache tomcat DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from | 1,2% | — |
| CVE-2025-33230 | HIGH 7.3 | nvidia cuda_toolkit NVIDIA Nsight Systems for Linux contains a vulnerability in the .run installer, where an attacker could cause an OS command injection by supplying a malicious string to the installation path. A successful exploit of this vulnerability might lead to escalation | 1,2% | — |
| CVE-2024-26196 | MED 4.3 | microsoft edge Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability | 1,2% | — |
| CVE-2023-31098 | CRIT 9.8 | apache inlong Weak Password Requirements vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.6.0. When users change their password to a simple password (with any character or symbol), attackers can easily guess | 1,2% | — |
| CVE-2022-20659 | MED 6.1 | cisco evolved_programmable_network_manager A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interf | 1,2% | — |
| CVE-2020-3306 | HIGH 7.5 | cisco adaptive_security_appliance A vulnerability in the DHCP module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. The vu | 1,2% | — |
| CVE-2020-3305 | HIGH 7.5 | cisco adaptive_security_appliance A vulnerability in the implementation of the Border Gateway Protocol (BGP) module in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service | 1,2% | — |
| CVE-2020-3303 | HIGH 7.5 | cisco adaptive_security_appliance A vulnerability in the Internet Key Exchange version 1 (IKEv1) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) cond | 1,2% | — |
| CVE-2019-7218 | MED 5.9 | citrix sharefile Citrix ShareFile before 19.23 allows a downgrade from two-factor authentication to one-factor authentication. An attacker with access to the offline victim's otp physical token or virtual app (like google authenticator) is able to bypass the first authenticati | 1,2% | — |
| CVE-2019-1382 | MED 5.5 | microsoft windows_10 An elevation of privilege vulnerability exists when ActiveX Installer service may allow access to files without proper authentication, aka 'Microsoft ActiveX Installer Service Elevation of Privilege Vulnerability'. | 1,2% | — |
| CVE-2017-14947 | HIGH 7.8 | artifex gsview Artifex GSView 6.0 Beta on Windows allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, related to a "Read Access Violation on Block Data Move starting at mupdfnet64!mIncrementalSaveFile+0x0000000000193359." | 1,2% | — |
| CVE-2003-0985 | HIGH 7.2 | linux linux_kernel The mremap system call (do_mremap) in Linux kernel 2.4.x before 2.4.21, and possibly other versions before 2.4.24, does not properly perform bounds checks, which allows local users to cause a denial of service and possibly gain privileges by causing a remappin | 1,2% | — |
| CVE-2026-50328 | HIGH 7.5 | microsoft windows_10_1607 Uncaught exception in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network. | 1,2% | — |
| CVE-2023-45725 | MED 5.7 | apache couchdb Design document functions which receive a user http request object may expose authorization or session cookie headers of the user who accesses the document. These design document functions are: * list * show * rewrite * update An attacker | 1,2% | — |
| CVE-2023-45348 | MED 4.3 | apache airflow Apache Airflow, versions 2.7.0 and 2.7.1, is affected by a vulnerability that allows an authenticated user to retrieve sensitive configuration information when the "expose_config" option is set to "non-sensitive-only". The `expose_config` option is False by de | 1,2% | — |
| CVE-2023-24900 | MED 5.9 | microsoft windows_10_1507 Windows NTLM Security Support Provider Information Disclosure Vulnerability | 1,2% | — |
| CVE-2022-39243 | HIGH 8.4 | nuprocess_project nuprocess NuProcess is an external process execution implementation for Java. In all the versions of NuProcess where it forks processes by using the JVM's Java_java_lang_UNIXProcess_forkAndExec method (1.2.0+), attackers can use NUL characters in their strings to perfor | 1,2% | — |
| CVE-2021-0231 | MED 6.5 | juniper junos A path traversal vulnerability in the Juniper Networks SRX and vSRX Series may allow an authenticated J-web user to read sensitive system files. This issue affects Juniper Networks Junos OS on SRX and vSRX Series: 19.3 versions prior to 19.3R2-S6, 19.3R3-S1; 1 | 1,2% | — |
| CVE-2020-3578 | MED 5.3 | cisco adaptive_security_appliance_software A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access rule and access parts of the WebVP | 1,2% | — |
| CVE-2020-0634 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory, aka 'Windows Common Log File System Driver Elevation of Privilege Vulnerability'. | 1,2% | — |
| CVE-2019-5513 | MED 5.3 | vmware horizon VMware Horizon Connection Server (7.x before 7.8, 7.5.x before 7.5.2, 6.x before 6.2.8) contains an information disclosure vulnerability. Successful exploitation of this issue may allow disclosure of internal domain names, the Connection Server’s internal name | 1,2% | — |
| CVE-2018-15393 | MED 4.8 | cisco content_security_management_appliance A vulnerability in the web-based management interface of Cisco Content Security Management Appliance (SMA) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interf | 1,2% | — |
| CVE-2018-10654 | HIGH 8.1 | citrix xenmobile_server There is a Hazelcast Library Java Deserialization Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3. | 1,2% | — |
| CVE-2017-5086 | MED 6.5 | google chrome Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 59.0.3071.86 for Windows and Mac allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name. | 1,2% | — |