56.571 CVE seguite
773 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.571 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più basso | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2015-4000 | LOW 3.7 | apple iphone_os The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello wi | 99,9% | — |
| CVE-2013-1959 | LOW 3.7 | linux linux_kernel kernel/user_namespace.c in the Linux kernel before 3.8.9 does not have appropriate capability requirements for the uid_map and gid_map files, which allows local users to gain privileges by opening a file within an unprivileged process and then modifying the fi | 1,2% | — |
| CVE-2007-1742 | LOW 3.7 | apache http_server suexec in Apache HTTP Server (httpd) 2.2.3 uses a partial comparison for verifying whether the current directory is within the document root, which might allow local users to perform unauthorized operations on incorrect directories, as demonstrated using "html | 0,7% | — |
| CVE-2005-1768 | LOW 3.7 | linux linux_kernel Race condition in the ia32 compatibility code for the execve system call in Linux kernel 2.4 before 2.4.31 and 2.6 before 2.6.6 allows local users to cause a denial of service (kernel panic) and possibly execute arbitrary code via a concurrent thread that incr | 0,5% | — |
| CVE-2004-2643 | LOW 3.7 | microsoft cabarc Directory traversal vulnerability in Microsoft cabarc allows remote attackers to overwrite files via "../" sequences in file names in a CAB archive. | 7,0% | — |
| CVE-2003-0480 | LOW 3.7 | vmware workstation VMware Workstation 4.0 for Linux allows local users to overwrite arbitrary files and gain privileges via "symlink manipulation." | 0,3% | — |
| CVE-2001-0317 | LOW 3.7 | linux linux_kernel Race condition in ptrace in Linux kernel 2.4 and 2.2 allows local users to gain privileges by using ptrace to track and modify a running setuid process. | 0,7% | — |
| CVE-1999-0401 | LOW 3.7 | linux linux_kernel A race condition in Linux 2.2.1 allows local users to read arbitrary memory from /proc files. | 0,3% | — |
| CVE-2025-67685 | LOW 3.8 | fortinet fortisandbox A Server-Side Request Forgery (SSRF) vulnerability [CWE-918] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.4, FortiSandbox 4.4 all versions, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions may allow an authenticated attacker to proxy in | 0,4% | — |
| CVE-2025-20276 | LOW 3.8 | cisco unified_contact_center_express A vulnerability in the web-based management interface of Cisco Unified CCX could allow an authenticated, remote attacker to execute arbitrary code on an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials.&nb | 0,4% | — |
| CVE-2025-0124 | LOW 3.8 | paloaltonetworks pan-os An authenticated file deletion vulnerability in the Palo Alto Networks PAN-OS® software enables an authenticated attacker with network access to the management web interface to delete certain files as the “nobody” user; this includes limited logs and configura | 0,3% | — |
| CVE-2024-55592 | LOW 3.8 | fortinet fortisiem An incorrect authorization vulnerability [CWE-863] in FortiSIEM 7.2 all versions, 7.1 all versions, 7.0 all versions, 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 all versions, 6.2 all versions, 6.1 all versions, 5.4 all versions | 0,2% | — |
| CVE-2024-23603 | LOW 3.8 | f5 big-ip_advanced_web_application_firewall An SQL injection vulnerability exists in an undisclosed page of the BIG-IP Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | 0,3% | — |
| CVE-2024-20528 | LOW 3.8 | cisco identity_services_engine A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to upload files to arbitrary locations on the underlying operating system of an affected device. To exploit this vulnerability, an attacker would need valid Super Admin | 0,6% | — |
| CVE-2023-52584 | LOW 3.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: spmi: mediatek: Fix UAF on device remove The pmif driver data that contains the clocks is allocated along with spmi_controller. On device remove, spmi_controller will be freed first, and the | 0,6% | — |
| CVE-2023-39265 | LOW 3.8 | apache superset Apache Superset would allow for SQLite database connections to be incorrectly registered when an attacker uses alternative driver names like sqlite+pysqlite or by using database imports. This could allow for unexpected file creation on Superset webservers. Add | 83,7% | — |
| CVE-2023-28404 | LOW 3.8 | intel arc_a_graphics Out-of-bounds read in the Intel(R) Arc(TM) & Iris(R) Xe Graphics - WHQL - Windows drivers before version 31.0.101.4255 may allow an authenticated user to potentially enable information disclosure via local access. | 0,2% | — |
| CVE-2022-22450 | LOW 3.8 | ibm security_verify_governance IBM Security Verify Identity Manager 10.0 could allow a privileged user to upload a malicious file by bypassing extension security in an HTTP request. IBM X-Force ID: 224916. | 0,6% | — |
| CVE-2022-20962 | LOW 3.8 | cisco identity_services_engine A vulnerability in the Localdisk Management feature of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to make unauthorized changes to the file system of an affected device. This vulnerability is due to insufficient input | 1,0% | — |
| CVE-2021-3039 | LOW 3.8 | paloaltonetworks prisma_cloud An information exposure through log file vulnerability exists in the Palo Alto Networks Prisma Cloud Compute Console where a secret used to authorize the role of the authenticated user is logged to a debug log file. Authenticated Operator role and Auditor role | 0,5% | — |
| CVE-2020-3970 | LOW 3.8 | vmware cloud_foundation VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain an out-of-bounds read vulnerability in the Shader functionality. A | 0,4% | — |
| CVE-2020-3951 | LOW 3.8 | vmware horizon_client VMware Workstation (15.x before 15.5.2) and Horizon Client for Windows (5.x and prior before 5.4.0) contain a denial-of-service vulnerability due to a heap-overflow issue in Cortado Thinprint. Attackers with non-administrative access to a guest VM with virtual | 0,3% | — |
| CVE-2017-4896 | LOW 3.8 | vmware airwatch_agent Airwatch Inbox for Android contains a vulnerability that may allow a rooted device to decrypt the local data used by the application. Successful exploitation of this issue may result in an unauthorized disclosure of confidential data. | 0,3% | — |
| CVE-2013-2140 | LOW 3.8 | linux linux_kernel The dispatch_discard_io function in drivers/block/xen-blkback/blkback.c in the Xen blkback implementation in the Linux kernel before 3.10.5 allows guest OS users to cause a denial of service (data loss) via filesystem write operations on a read-only disk that | 1,0% | — |
| CVE-2002-2202 | LOW 3.8 | microsoft outlook_express Outlook Express 6.0 does not delete messages from dbx files, even when a user empties the Deleted items folder, which allows local users to read other users email. | 1,3% | — |