56.706 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.706 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più basso | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2025-54101 | MED 4.8 | microsoft windows_10_1507 Use after free in Windows SMBv3 Client allows an authorized attacker to execute code over a network. | 2,5% | — |
| CVE-2025-53608 | MED 4.8 | fortinet fortisandbox An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all ver | 0,3% | — |
| CVE-2025-29891 | MED 4.8 | apache camel Bypass/Injection vulnerability in Apache Camel. This issue affects Apache Camel: from 4.10.0 before 4.10.2, from 4.8.0 before 4.8.5, from 3.10.0 before 3.22.4. Users are recommended to upgrade to version 4.10.2 for 4.10.x LTS, 4.8.5 for 4.8.x LTS and 3.22.4 | 75,1% | — |
| CVE-2025-25252 | MED 4.8 | fortinet fortios An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL VPN 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, 6.4 all versions may allow a remote attacker (e.g. a former admin whose account was removed and | 0,3% | — |
| CVE-2025-21179 | MED 4.8 | microsoft windows_11_24h2 DHCP Client Service Denial of Service Vulnerability | 0,7% | — |
| CVE-2025-20307 | MED 4.8 | cisco broadworks_application_delivery_platform A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due t | 0,2% | — |
| CVE-2025-20289 | MED 4.8 | cisco identity_services_engine Multiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct a reflected XSS attack against a user of the interface. These vulnerabilities are due to insufficient vali | 0,2% | — |
| CVE-2025-20280 | MED 4.8 | cisco evolved_programmable_network_manager A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the i | 0,2% | — |
| CVE-2025-20279 | MED 4.8 | cisco unified_contact_center_express A vulnerability in the web-based management interface of Cisco Unified CCX could allow an authenticated, remote attacker to conduct a stored XSS attack on an affected system. To exploit this vulnerability, the attacker must have valid administrative credential | 0,2% | — |
| CVE-2025-20267 | MED 4.8 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insuffici | 0,3% | — |
| CVE-2025-20205 | MED 4.8 | cisco identity_services_engine Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) guest portals could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulnerab | 0,3% | — |
| CVE-2025-20204 | MED 4.8 | cisco identity_services_engine Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) guest portals could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulnerab | 0,3% | — |
| CVE-2025-20203 | MED 4.8 | cisco evolved_programmable_network_manager A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the i | 0,3% | — |
| CVE-2025-20180 | MED 4.8 | cisco asyncos A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Email Gateway could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user o | 0,3% | — |
| CVE-2025-20126 | MED 4.8 | cisco thousandeyes_endpoint_agent A vulnerability in certification validation routines of Cisco ThousandEyes Endpoint Agent for macOS and RoomOS could allow an unauthenticated, remote attacker to intercept or manipulate metrics information. This vulnerability exists because the affected sof | 0,2% | — |
| CVE-2025-20123 | MED 4.8 | cisco crosswork_network_controller Multiple vulnerabilities in the web-based management interface of Cisco Crosswork Network Controller could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against users of the interface of an affected system. These vuln | 0,3% | — |
| CVE-2025-20116 | MED 4.8 | cisco application_policy_infrastructure_controller A vulnerability in the web UI of Cisco APIC could allow an authenticated, remote attacker to perform a stored XSS attack on an affected system. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due | 0,3% | — |
| CVE-2024-5920 | MED 4.8 | paloaltonetworks pan-os A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write Panorama administrator to push a specially crafted configuration to a PAN-OS node. This enables impersonation of a legitimate PAN-OS administra | 0,3% | — |
| CVE-2024-5906 | MED 4.8 | paloaltonetworks prisma_cloud A cross-site scripting (XSS) vulnerability in Palo Alto Networks Prisma Cloud Compute software enables a malicious administrator with add/edit permissions for identity providers to store a JavaScript payload using the web interface on Prisma Cloud Compute. Thi | 0,2% | — |
| CVE-2024-54019 | MED 4.8 | fortinet forticlient A improper validation of certificate with host mismatch in Fortinet FortiClientWindows version 7.4.0, versions 7.2.0 through 7.2.6, and 7.0 all versions allow an unauthorized attacker to redirect VPN connections via DNS spoofing or another form of redirection. | 0,1% | — |
| CVE-2024-50562 | MED 4.8 | fortinet fortios An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version 7.4.6 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions may allow an attacker in possession of a cookie used to log in the SSL-VPN portal | 1,1% | — |
| CVE-2024-45478 | MED 4.8 | apache ranger Stored XSS vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0. Users are recommended to upgrade to version Apache Ranger 2.5.0, which fixes this issue. | 0,6% | — |
| CVE-2024-45073 | MED 4.8 | ibm websphere_application_server IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials | 0,2% | — |
| CVE-2024-43456 | MED 4.8 | microsoft windows_server_2008 Windows Remote Desktop Services Tampering Vulnerability | 0,7% | — |
| CVE-2024-40590 | MED 4.8 | fortinet fortiportal An improper certificate validation vulnerability [CWE-295] in FortiPortal version 7.4.0, version 7.2.4 and below, version 7.0.8 and below, version 6.0.15 and below when connecting to a FortiManager device, a FortiAnalyzer device, or an SMTP server may allow an | 0,2% | — |