56.793 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.793 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più basso | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-1999-0154 | MED 5.0 | microsoft internet_information_server IIS 2.0 and 3.0 allows remote attackers to read the source code for ASP pages by appending a . (dot) to the end of the URL. | 40,0% | — |
| CVE-1999-0153 | MED 5.0 | microsoft windows_2000 Windows 95/NT out of band (OOB) data denial of service through NETBIOS port, aka WinNuke. | 21,1% | — |
| CVE-1999-0140 | MED 5.0 | microsoft windows_nt Denial of service in RAS/PPTP on NT systems. | 13,6% | — |
| CVE-1999-0128 | MED 5.0 | digital osf_1 Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death. | 74,7% | — |
| CVE-1999-0107 | MED 5.0 | apache http_server Buffer overflow in Apache 1.2.5 and earlier allows a remote attacker to cause a denial of service with a large number of GET requests containing a large number of / characters. | 19,9% | — |
| CVE-1999-0104 | MED 5.0 | caldera openlinux A later variation on the Teardrop IP denial of service attack, a.k.a. Teardrop-2. | 9,2% | — |
| CVE-1999-0077 | MED 5.0 | microsoft windows_nt Predictable TCP sequence numbers allow spoofing. | 30,9% | — |
| CVE-1999-0070 | MED 5.0 | apache http_server test-cgi program allows an attacker to list files on the server. | 29,6% | — |
| CVE-1999-0063 | MED 5.0 | cisco ios Cisco IOS 12.0 and other versions can be crashed by malicious UDP packets to the syslog port. | 8,2% | — |
| CVE-1999-0016 | MED 5.0 | cisco ios Land IP denial of service. | 95,7% | — |
| CVE-1999-0015 | MED 5.0 | hp hp-ux Teardrop IP denial of service. | 35,7% | — |
| CVE-1999-0007 | MED 5.0 | c2net stonghold_web_server Information from SSL-encrypted sessions via PKCS #1. | 7,6% | — |
| CVE-2026-8672 | MED 5.1 | avantra avantra Use of default password vulnerability in syslink software AG Avantra on Linux, Windows allows Try Common or Default Usernames and Passwords. This issue affects Avantra: before 25.3.0. | 0,1% | — |
| CVE-2026-50418 | MED 5.1 | microsoft windows_11_24h2 Improper access control in Windows System allows an unauthorized attacker to bypass a security feature locally. | 0,3% | — |
| CVE-2026-11276 | MED 5.1 | google chrome Inappropriate implementation in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to bypass discretionary access control via malicious network traffic. (Chromium security severity: Low) | 0,1% | — |
| CVE-2025-55679 | MED 5.1 | microsoft windows_10_1809 Improper input validation in Windows Kernel allows an unauthorized attacker to disclose information locally. | 0,4% | — |
| CVE-2025-52989 | MED 5.1 | juniper junos An Improper Neutralization of Delimiters vulnerability in the UI of Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with high privileges to modify the system configuration. A user with limited configuration and commit p | 0,1% | — |
| CVE-2025-33069 | MED 5.1 | microsoft windows_11_24h2 Improper verification of cryptographic signature in App Control for Business (WDAC) allows an unauthorized attacker to bypass a security feature locally. | 0,3% | — |
| CVE-2025-26644 | MED 5.1 | microsoft windows_10_1809 Automated recognition mechanism with inadequate detection or handling of adversarial input perturbations in Windows Hello allows an unauthorized attacker to perform spoofing locally. | 0,5% | — |
| CVE-2025-20117 | MED 5.1 | cisco application_policy_infrastructure_controller A vulnerability in the CLI of Cisco APIC could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrativ | 0,2% | — |
| CVE-2024-47566 | MED 5.1 | fortinet fortirecorder A improper limitation of a pathname to a restricted directory ('path traversal') [CWE-23] in Fortinet FortiRecorder version 7.2.0 through 7.2.1 and before 7.0.4 allows a privileged attacker to delete files from the underlying filesystem via crafted CLI request | 0,2% | — |
| CVE-2024-45772 | MED 5.1 | apache lucene_replicator Deserialization of Untrusted Data vulnerability in Apache Lucene Replicator. This issue affects Apache Lucene's replicator module: from 4.4.0 before 9.12.0. The deprecated org.apache.lucene.replicator.http package is affected. The org.apache.lucene.replicator | 0,6% | — |
| CVE-2024-36505 | MED 5.1 | fortinet fortios An improper access control vulnerability [CWE-284] in FortiOS 7.4.0 through 7.4.3, 7.2.5 through 7.2.7, 7.0.12 through 7.0.14 and 6.4.x may allow an attacker who has already successfully obtained write access to the underlying system (via another hypothetical | 0,2% | — |
| CVE-2024-32116 | MED 5.1 | fortinet fortianalyzer Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 and FortiAnalyzer-BigData version 7.4.0 and before 7.2.7 allows a privil | 0,2% | — |
| CVE-2024-26847 | MED 5.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: powerpc/rtas: use correct function name for resetting TCE tables The PAPR spec spells the function name as "ibm,reset-pe-dma-windows" but in practice firmware uses the singular form: | 0,2% | — |