56.569 CVE seguite
773 Sfruttate ora
181 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.569 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più basso | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2000-0028 | LOW 2.6 | microsoft ie Internet Explorer 5.0 and 5.01 allows remote attackers to bypass the cross frame security policy and read files via the external.NavigateAndFind function. | 23,1% | — |
| CVE-2000-0006 | LOW 2.6 | linux linux_kernel strace allows local users to read arbitrary files via memory mapped file names. | 0,3% | — |
| CVE-1999-1453 | LOW 2.6 | microsoft internet_explorer Internet Explorer 4 allows remote attackers (malicious web site operators) to read the contents of the clipboard via the Internet WebBrowser ActiveX object. | 11,2% | — |
| CVE-1999-1001 | LOW 2.6 | cisco cache_engine Cisco Cache Engine allows a remote attacker to gain access via a null username and password. | 1,4% | — |
| CVE-1999-0871 | LOW 2.6 | microsoft internet_explorer Internet Explorer 4.0 and 4.01 allow a remote attacker to read files via IE's cross frame security, aka the "Cross Frame Navigate" vulnerability. | 12,2% | — |
| CVE-1999-0870 | LOW 2.6 | microsoft internet_explorer Internet Explorer 4.01 allows remote attackers to read arbitrary files by pasting a file name into the file upload control, aka untrusted scripted paste. | 12,5% | — |
| CVE-1999-0869 | LOW 2.6 | microsoft internet_explorer Internet Explorer 3.x to 4.01 allows a remote attacker to insert malicious content into a frame of another web site, aka frame spoofing. | 17,3% | — |
| CVE-1999-0861 | LOW 2.6 | microsoft commercial_internet_system Race condition in the SSL ISAPI filter in IIS and other servers may leak information in plaintext. | 3,2% | — |
| CVE-1999-0827 | LOW 2.6 | microsoft ie By default, Internet Explorer 5.0 and other versions enables the "Navigate sub-frames across different domains" option, which allows frame spoofing. | 4,7% | — |
| CVE-1999-0793 | LOW 2.6 | microsoft internet_explorer Internet Explorer allows remote attackers to read files by redirecting data to a Javascript applet. | 13,3% | — |
| CVE-1999-0749 | LOW 2.6 | microsoft windows_95 Buffer overflow in Microsoft Telnet client in Windows 95 and Windows 98 via a malformed Telnet argument. | 8,0% | — |
| CVE-1999-0717 | LOW 2.6 | microsoft excel A remote attacker can disable the virus warning mechanism in Microsoft Excel 97. | 5,8% | — |
| CVE-1999-0487 | LOW 2.6 | microsoft internet_explorer The DHTML Edit ActiveX control in Internet Explorer allows remote attackers to read arbitrary files. | 13,3% | — |
| CVE-1999-0031 | LOW 2.6 | microsoft internet_explorer JavaScript in Internet Explorer 3.x and 4.x, and Netscape 2.x, 3.x and 4.x, allows remote attackers to monitor a user's web activities, aka the Bell Labs vulnerability. | 18,3% | — |
| CVE-2026-27316 | LOW 2.7 | fortinet fortisandbox A insufficiently protected credentials vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4 all versions, FortiSandbox PaaS 5.0.1 through 5.0.5 may allow an authenticathed administrator to read LDAP server credentials via client-side in | 0,3% | — |
| CVE-2026-24641 | LOW 2.7 | fortinet fortiweb A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow an authenticated attacker to cras | 0,4% | — |
| CVE-2025-64299 | LOW 2.7 | secuavail logstare_collector LogStare Collector improperly handles the password hash data. An administrative user may obtain the other users' password hashes. | 0,3% | — |
| CVE-2025-59923 | LOW 2.7 | fortinet fortiauthenticator An improper access control vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may allow an authenticated attacker with at least read-on | 0,2% | — |
| CVE-2025-58903 | LOW 2.7 | fortinet fortios An Unchecked Return Value vulnerability [CWE-252] in Fortinet FortiOS version 7.6.0 through 7.6.3 and before 7.4.8 API allows an authenticated user to cause a Null Pointer Dereference, crashing the http daemon via a specialy crafted request. | 0,6% | — |
| CVE-2025-57823 | LOW 2.7 | fortinet fortiauthenticator A direct request ('forced browsing') vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may allow an authenticated attacker with at lea | 0,2% | — |
| CVE-2025-4614 | LOW 2.7 | paloaltonetworks pan-os An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to view session tokens of users authenticated to the firewall web UI. This may allow impersonation of users whose session tokens are leaked. | 0,2% | — |
| CVE-2025-31514 | LOW 2.7 | fortinet fortios A insertion of sensitive information into log file vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 t | 0,3% | — |
| CVE-2025-24474 | LOW 2.7 | fortinet fortianalyzer An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiManager 7.6.0 through 7.6.1, 7.4.0 through 7.4.6, 7.2 all versions, 7.0 all versions, 6.4 all versions; FortiManager Cloud 7.4.1 through 7.4. | 0,3% | — |
| CVE-2025-22855 | LOW 2.7 | fortinet forticlientems An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Fortinet FortiClient before 7.4.1 may allow the EMS administrator to send messages containing javascript code. | 0,3% | — |
| CVE-2025-13459 | LOW 2.7 | ibm aspera_console IBM Aspera Console 3.3.0 through 3.4.8 could allow a privileged user to cause a denial of service due to improper enforcement of behavioral workflow. | 0,4% | — |