56.635 CVE seguite
776 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.635 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più basso | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2003-1025 | MED 4.3 | microsoft internet_explorer Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the "Impro | 26,9% | — |
| CVE-2003-0712 | MED 4.3 | microsoft exchange_server Cross-site scripting (XSS) vulnerability in the HTML encoding for the Compose New Message form in Microsoft Exchange Server 5.5 Outlook Web Access (OWA) allows remote attackers to execute arbitrary web script. | 17,4% | — |
| CVE-2003-0446 | MED 4.3 | microsoft internet_explorer Cross-site scripting (XSS) in Internet Explorer 5.5 and 6.0, possibly in a component that is also used by other Microsoft products, allows remote attackers to insert arbitrary web script via an XML file that contains a parse error, which inserts the script in | 23,0% | — |
| CVE-2002-2435 | MED 4.3 | microsoft ie The Cascading Style Sheets (CSS) implementation in Microsoft Internet Explorer 8.0 and earlier does not properly handle the :visited pseudo-class, which allows remote attackers to obtain sensitive information about visited web pages via a crafted HTML document | 13,7% | — |
| CVE-2002-2426 | MED 4.3 | citrix access_essentials Cross-site request forgery (CSRF) vulnerability in Citrix Presentation Server 4.0 and 4.5, MetaFrame Presentation Server 3.0, and Access Essentials 1.0 through 2.0 allows remote attackers to execute arbitrary published applications, and possibly other programs | 0,7% | — |
| CVE-2002-2073 | MED 4.3 | microsoft site_server Cross-site scripting (XSS) vulnerability in the default ASP pages on Microsoft Site Server 3.0 on Windows NT 4.0 allows remote attackers to inject arbitrary web script or HTML via the (1) ctr parameter in Default.asp and (2) the query string to formslogin.asp. | 12,9% | — |
| CVE-2002-2062 | MED 4.3 | microsoft internet_explorer Cross-site scripting (XSS) vulnerability in ftp.htt in Internet Explorer 5.5 and 6.0, when running on Windows 2000 with "Enable folder view for FTP sites" and "Enable Web content in folders" selected, allows remote attackers to inject arbitrary web script or H | 13,3% | — |
| CVE-2002-1795 | MED 4.3 | microsoft tsac_activex_control Cross-site scripting (XSS) vulnerability in connect.asp in Microsoft Terminal Services Advanced Client (TSAC) ActiveX control allows remote attackers to inject arbitrary web script or HTML via unknown vectors. | 16,8% | — |
| CVE-2002-1700 | MED 4.3 | macromedia coldfusion Cross-site scripting vulnerability (XSS) in the missing template handler in Macromedia ColdFusion MX allows remote attackers to execute arbitrary script as other users by injecting script into the HTTP request for the name of a template, which is not filtered | 24,3% | — |
| CVE-2000-1205 | MED 4.3 | apache http_server Cross site scripting vulnerabilities in Apache 1.3.0 through 1.3.11 allow remote attackers to execute script as other web site visitors via (1) the printenv CGI (printenv.pl), which does not encode its output, (2) pages generated by the ap_send_error_response | 23,6% | — |
| CVE-2000-1105 | MED 4.3 | microsoft indexing_service The ixsso.query ActiveX Object is marked as safe for scripting, which allows malicious web site operators to embed a script that remotely determines the existence of files on visiting Windows 2000 systems that have Indexing Services enabled. | 10,8% | — |
| CVE-1999-0999 | MED 4.3 | microsoft sql_server Microsoft SQL 7.0 server allows a remote attacker to cause a denial of service via a malformed TDS packet. | 21,7% | — |
| CVE-1999-0877 | MED 4.3 | microsoft internet_explorer Internet Explorer 5 allows remote attackers to read files via an ExecCommand method called on an IFRAME. | 17,7% | — |
| CVE-2026-7932 | MED 4.4 | google chrome Insufficient policy enforcement in Downloads in Google Chrome prior to 148.0.7778.96 allowed a local attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium) | 0,1% | — |
| CVE-2026-7572 | MED 4.4 | rapid7 velociraptor An off-by-one error (CWE-193) in the ConsumeUnit16Array and ConsumeUnit64Array functions in Velocidex Velociraptor before version 0.76.5 on Windows and Linux allows a local attacker to cause a Denial of Service (DoS) via a process crash by providing a speciall | 0,1% | — |
| CVE-2026-7431 | MED 4.4 | ivanti secure_access_client An incorrect permission assignment for critical resource of Ivanti Secure Access Client before 22.8R6 allows a local authenticated user to read or modify sensitive log data via write access to a shared memory section. | 0,2% | — |
| CVE-2026-47487 | MED 4.4 | nvidia triton_inference_server NVIDIA Triton Inference Server for Linux contains a vulnerability where a user could cause files outside the model repository to be read, written to, or modified by providing a path in the model name to the Triton MLflow plugin. A successful exploit of this vu | 0,2% | — |
| CVE-2026-42408 | MED 4.4 | f5 big-ip_access_policy_manager When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed TMOS Shell (tmsh) command that may allow a highly privileged authenticated attacker to view sensitive information. Note: Software versions which have reached End of Technical Support (Eo | 0,1% | — |
| CVE-2026-41100 | MED 4.4 | microsoft 365_copilot Improper access control in M365 Copilot allows an authorized attacker to perform spoofing locally. | 0,2% | — |
| CVE-2026-41004 | MED 4.4 | vmware spring_cloud_config When enabling trace logging in Spring Cloud Config Server sensitive information was placed in plain text in the logs. Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). Spring Clou | 0,2% | — |
| CVE-2026-40949 | MED 4.4 | absolute secure_access CVE-2026-40949 is a buffer overflow vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windows client can use it to trigger a denial of service. | 0,1% | — |
| CVE-2026-32220 | MED 4.4 | microsoft windows_11_24h2 Improper access control in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally. | 0,3% | — |
| CVE-2026-32209 | MED 4.4 | microsoft windows_10_1607 Improper access control in Windows Filtering Platform (WFP) allows an authorized attacker to bypass a security feature locally. | 0,2% | — |
| CVE-2026-28758 | MED 4.4 | f5 big-ip_domain_name_system When BIG-IP DNS is provisioned, a vulnerability exists in the gtm_add and bigip_add iControl REST commands that return the ssh-password parameter in cleartext in the iControl REST response and is also logged in the audit log. This may allow a highly privileged | 0,1% | — |
| CVE-2026-28716 | MED 4.4 | acronis cyber_protect Information disclosure and manipulation due to improper authorization checks. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186. | 0,1% | — |