EN
56.635 CVE seguite
776 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia

CVE Tracker

56.635 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordinato dal più basso Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2003-1025 MED 4.3 microsoft internet_explorer Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the "Impro 26,9%
CVE-2003-0712 MED 4.3 microsoft exchange_server Cross-site scripting (XSS) vulnerability in the HTML encoding for the Compose New Message form in Microsoft Exchange Server 5.5 Outlook Web Access (OWA) allows remote attackers to execute arbitrary web script. 17,4%
CVE-2003-0446 MED 4.3 microsoft internet_explorer Cross-site scripting (XSS) in Internet Explorer 5.5 and 6.0, possibly in a component that is also used by other Microsoft products, allows remote attackers to insert arbitrary web script via an XML file that contains a parse error, which inserts the script in 23,0%
CVE-2002-2435 MED 4.3 microsoft ie The Cascading Style Sheets (CSS) implementation in Microsoft Internet Explorer 8.0 and earlier does not properly handle the :visited pseudo-class, which allows remote attackers to obtain sensitive information about visited web pages via a crafted HTML document 13,7%
CVE-2002-2426 MED 4.3 citrix access_essentials Cross-site request forgery (CSRF) vulnerability in Citrix Presentation Server 4.0 and 4.5, MetaFrame Presentation Server 3.0, and Access Essentials 1.0 through 2.0 allows remote attackers to execute arbitrary published applications, and possibly other programs 0,7%
CVE-2002-2073 MED 4.3 microsoft site_server Cross-site scripting (XSS) vulnerability in the default ASP pages on Microsoft Site Server 3.0 on Windows NT 4.0 allows remote attackers to inject arbitrary web script or HTML via the (1) ctr parameter in Default.asp and (2) the query string to formslogin.asp. 12,9%
CVE-2002-2062 MED 4.3 microsoft internet_explorer Cross-site scripting (XSS) vulnerability in ftp.htt in Internet Explorer 5.5 and 6.0, when running on Windows 2000 with "Enable folder view for FTP sites" and "Enable Web content in folders" selected, allows remote attackers to inject arbitrary web script or H 13,3%
CVE-2002-1795 MED 4.3 microsoft tsac_activex_control Cross-site scripting (XSS) vulnerability in connect.asp in Microsoft Terminal Services Advanced Client (TSAC) ActiveX control allows remote attackers to inject arbitrary web script or HTML via unknown vectors. 16,8%
CVE-2002-1700 MED 4.3 macromedia coldfusion Cross-site scripting vulnerability (XSS) in the missing template handler in Macromedia ColdFusion MX allows remote attackers to execute arbitrary script as other users by injecting script into the HTTP request for the name of a template, which is not filtered 24,3%
CVE-2000-1205 MED 4.3 apache http_server Cross site scripting vulnerabilities in Apache 1.3.0 through 1.3.11 allow remote attackers to execute script as other web site visitors via (1) the printenv CGI (printenv.pl), which does not encode its output, (2) pages generated by the ap_send_error_response 23,6%
CVE-2000-1105 MED 4.3 microsoft indexing_service The ixsso.query ActiveX Object is marked as safe for scripting, which allows malicious web site operators to embed a script that remotely determines the existence of files on visiting Windows 2000 systems that have Indexing Services enabled. 10,8%
CVE-1999-0999 MED 4.3 microsoft sql_server Microsoft SQL 7.0 server allows a remote attacker to cause a denial of service via a malformed TDS packet. 21,7%
CVE-1999-0877 MED 4.3 microsoft internet_explorer Internet Explorer 5 allows remote attackers to read files via an ExecCommand method called on an IFRAME. 17,7%
CVE-2026-7932 MED 4.4 google chrome Insufficient policy enforcement in Downloads in Google Chrome prior to 148.0.7778.96 allowed a local attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium) 0,1%
CVE-2026-7572 MED 4.4 rapid7 velociraptor An off-by-one error (CWE-193) in the ConsumeUnit16Array and ConsumeUnit64Array functions in Velocidex Velociraptor before version 0.76.5 on Windows and Linux allows a local attacker to cause a Denial of Service (DoS) via a process crash by providing a speciall 0,1%
CVE-2026-7431 MED 4.4 ivanti secure_access_client An incorrect permission assignment for critical resource of Ivanti Secure Access Client   before 22.8R6 allows a local authenticated user to read or modify sensitive log data via write access to a shared memory section. 0,2%
CVE-2026-47487 MED 4.4 nvidia triton_inference_server NVIDIA Triton Inference Server for Linux contains a vulnerability where a user could cause files outside the model repository to be read, written to, or modified by providing a path in the model name to the Triton MLflow plugin. A successful exploit of this vu 0,2%
CVE-2026-42408 MED 4.4 f5 big-ip_access_policy_manager When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed TMOS Shell (tmsh) command that may allow a highly privileged authenticated attacker to view sensitive information.  Note: Software versions which have reached End of Technical Support (Eo 0,1%
CVE-2026-41100 MED 4.4 microsoft 365_copilot Improper access control in M365 Copilot allows an authorized attacker to perform spoofing locally. 0,2%
CVE-2026-41004 MED 4.4 vmware spring_cloud_config When enabling trace logging in Spring Cloud Config Server sensitive information was placed in plain text in the logs. Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). Spring Clou 0,2%
CVE-2026-40949 MED 4.4 absolute secure_access CVE-2026-40949 is a buffer overflow vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windows client can use it to trigger a denial of service. 0,1%
CVE-2026-32220 MED 4.4 microsoft windows_11_24h2 Improper access control in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally. 0,3%
CVE-2026-32209 MED 4.4 microsoft windows_10_1607 Improper access control in Windows Filtering Platform (WFP) allows an authorized attacker to bypass a security feature locally. 0,2%
CVE-2026-28758 MED 4.4 f5 big-ip_domain_name_system When BIG-IP DNS is provisioned, a vulnerability exists in the gtm_add and bigip_add iControl REST commands that return the ssh-password parameter in cleartext in the iControl REST response and is also logged in the audit log. This may allow a highly privileged 0,1%
CVE-2026-28716 MED 4.4 acronis cyber_protect Information disclosure and manipulation due to improper authorization checks. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186. 0,1%