58.535 CVE seguite
797 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.535 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più basso | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2025-11219 | LOW 3.1 | google chrome Use after free in V8 in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Low) | 0,3% | — |
| CVE-2024-50565 | LOW 3.1 | fortinet fortianalyzer A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0.0 through 7.0.14, 6.4.0 through 6.4.15 and 6.2.0 through 6.2.16, Fortinet FortiProxy version | 0,4% | — |
| CVE-2024-46901 | LOW 3.1 | apache subversion Insufficient validation of filenames against control characters in Apache Subversion repositories served via mod_dav_svn allows authenticated users with commit access to commit a corrupted revision, leading to disruption for users of the repository. All versi | 1,9% | — |
| CVE-2024-45099 | LOW 3.1 | ibm security_qradar_edr IBM Security ReaQta 3.12 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted | 0,2% | — |
| CVE-2024-38820 | LOW 3.1 | vmware spring_framework The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions that could potentially result in fields not protected as expected. | 0,6% | — |
| CVE-2024-32152 | LOW 3.1 | ankitects anki A blocklist bypass vulnerability exists in the LaTeX functionality of Ankitects Anki 24.04. A specially crafted malicious flashcard can lead to an arbitrary file creation at a fixed path. An attacker can share a malicious flashcard to trigger this vulnerabilit | 12,7% | — |
| CVE-2024-1221 | LOW 3.1 | papercut papercut_mf This vulnerability potentially allows files on a PaperCut NG/MF server to be exposed using a specifically formed payload against the impacted API endpoint. The attacker must carry out some reconnaissance to gain knowledge of a system token. This CVE only affec | 0,5% | — |
| CVE-2023-49619 | LOW 3.1 | apache answer Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Answer. This issue affects Apache Answer: through 1.2.0. Under normal circumstances, a user can only bookmark a question once, and will only i | 0,9% | — |
| CVE-2023-47536 | LOW 3.1 | fortinet fortios An improper access control vulnerability [CWE-284] in FortiOS version 7.2.0, version 7.0.13 and below, version 6.4.14 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below may allow a remote unauthenticated attacke | 0,6% | — |
| CVE-2023-38158 | LOW 3.1 | microsoft edge_chromium Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | 1,3% | — |
| CVE-2023-34047 | LOW 3.1 | vmware spring_for_graphql A batch loader function in Spring for GraphQL versions 1.1.0 - 1.1.5 and 1.2.0 - 1.2.2 may be exposed to GraphQL context with values, including security context values, from a different session. An application is vulnerable if it provides a DataLoaderOptions i | 0,4% | — |
| CVE-2023-27525 | LOW 3.1 | apache superset An authenticated user with Gamma role authorization could have access to metadata information using non trivial methods in Apache Superset up to and including 2.0.1 | 0,8% | — |
| CVE-2023-27272 | LOW 3.1 | ibm aspera_console IBM Aspera Console 3.4.0 through 3.4.4 allows passwords to be reused when a new user logs into the system. | 0,3% | — |
| CVE-2023-23472 | LOW 3.1 | ibm infosphere_information_server IBM InfoSphere DataStage Flow Designer (InfoSphere Information Server 11.7) could allow an authenticated user to obtain sensitive information that could aid in further attacks against the system. | 0,3% | — |
| CVE-2023-23395 | LOW 3.1 | microsoft sharepoint_foundation Microsoft SharePoint Server Spoofing Vulnerability | 0,6% | — |
| CVE-2022-43906 | LOW 3.1 | ibm security_guardium IBM Security Guardium 11.5 could disclose sensitive information due to a missing or insecure SameSite attribute for a sensitive cookie. IBM X-Force ID: 240897. | 0,5% | — |
| CVE-2022-43573 | LOW 3.1 | ibm robotic_process_automation IBM Robotic Process Automation 20.12 through 21.0.6 is vulnerable to exposure of the name and email for the creator/modifier of platform level objects. IBM X-Force ID: 238678. | 0,5% | — |
| CVE-2022-3649 | LOW 3.1 | debian debian_linux A vulnerability was found in Linux Kernel. It has been classified as problematic. Affected is the function nilfs_new_inode of the file fs/nilfs2/inode.c of the component BPF. The manipulation leads to use after free. It is possible to launch the attack remotel | 0,9% | — |
| CVE-2022-3646 | LOW 3.1 | debian debian_linux A vulnerability, which was classified as problematic, has been found in Linux Kernel. This issue affects the function nilfs_attach_log_writer of the file fs/nilfs2/segment.c of the component BPF. The manipulation leads to memory leak. The attack may be initiat | 0,9% | — |
| CVE-2022-3630 | LOW 3.1 | linux linux_kernel A vulnerability was found in Linux Kernel. It has been rated as problematic. This issue affects some unknown processing of the file fs/fscache/cookie.c of the component IPsec. The manipulation leads to memory leak. It is recommended to apply a patch to fix thi | 0,3% | — |
| CVE-2022-29147 | LOW 3.1 | microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability | 0,6% | — |
| CVE-2022-1389 | LOW 3.1 | f5 big-ip_access_policy_manager On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP (fixed in 17.0.0), a cross-site request forgery (CSRF) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility. This vulnerability allows an attacker to | 0,3% | — |
| CVE-2021-43220 | LOW 3.1 | microsoft edge_ios Microsoft Edge for iOS Spoofing Vulnerability | 1,3% | — |
| CVE-2021-42308 | LOW 3.1 | microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability | 1,3% | — |
| CVE-2021-36181 | LOW 3.1 | fortinet fortiportal A concurrent execution using shared resource with improper Synchronization vulnerability ('Race Condition') in the customer database interface of FortiPortal before 6.0.6 may allow an authenticated, low-privilege user to bring the underlying database data into | 0,4% | — |