57.808 CVE seguite
783 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.808 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2016-8636 | HIGH 7.8 | linux linux_kernel Integer overflow in the mem_check_range function in drivers/infiniband/sw/rxe/rxe_mr.c in the Linux kernel before 4.9.10 allows local users to cause a denial of service (memory corruption), obtain sensitive information from kernel memory, or possibly have unsp | 1,2% | — |
| CVE-2016-0754 | MED 5.3 | haxx curl cURL before 7.47.0 on Windows allows attackers to write to arbitrary files in the current working directory on a different drive via a colon in a remote file name. | 1,2% | — |
| CVE-2024-49576 | HIGH 8.8 | foxit pdf_editor A use-after-free vulnerability exists in the way Foxit Reader 2024.3.0.26795 handles a checkbox CBF_Widget object. A specially crafted Javascript code inside a malicious PDF document can trigger this vulnerability, which can lead to memory corruption and resul | 1,2% | — |
| CVE-2024-20329 | CRIT 9.9 | cisco adaptive_security_appliance_software A vulnerability in the SSH subsystem of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker to execute operating system commands as root. This vulnerability is due to insufficient validation of user input. An attac | 1,2% | — |
| CVE-2024-26007 | MED 5.3 | fortinet fortios An improper check or handling of exceptional conditions vulnerability [CWE-703] in Fortinet FortiOS version 7.4.1 allows an unauthenticated attacker to provoke a denial of service on the administrative interface via crafted HTTP requests. | 1,2% | — |
| CVE-2020-7814 | HIGH 7.8 | raonwiz raon_k_upload RAONWIZ v2018.0.2.50 and eariler versions contains a vulnerability that could allow remote files to be downloaded and excuted by lack of validation to file extension, witch can used as remote-code-excution attacks by hackers File download & execution vulnerabi | 1,2% | — |
| CVE-2020-5863 | HIGH 8.6 | f5 nginx_controller In NGINX Controller versions prior to 3.2.0, an unauthenticated attacker with network access to the Controller API can create unprivileged user accounts. The user which is created is only able to upload a new license to the system but cannot view or modify any | 1,2% | — |
| CVE-2019-0976 | MED 5.5 | microsoft nuget A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify contents of the intermediate build folder (by default "obj"), aka 'NuGet Package Manager Tampering Vulnerability'. | 1,2% | — |
| CVE-2013-0883 | MED 5.0 | google chrome Skia, as used in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service (incorrect read operation) via unspecified vectors. | 1,2% | — |
| CVE-2013-0881 | MED 5.0 | google chrome Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service (incorrect read operation) via crafted data in the Matroska container format. | 1,2% | — |
| CVE-2025-53781 | HIGH 7.7 | microsoft dcadsv5-series_azure_vm_firmware Exposure of sensitive information to an unauthorized actor in Azure Virtual Machines allows an authorized attacker to disclose information over a network. | 1,1% | — |
| CVE-2024-50562 | MED 4.8 | fortinet fortios An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version 7.4.6 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions may allow an attacker in possession of a cookie used to log in the SSL-VPN portal | 1,1% | — |
| CVE-2025-21349 | MED 6.8 | microsoft windows_10_1507 Windows Remote Desktop Configuration Service Tampering Vulnerability | 1,1% | — |
| CVE-2024-2362 | CRIT 9.1 | lollms lollms_web_ui A path traversal vulnerability exists in the parisneo/lollms-webui version 9.3 on the Windows platform. Due to improper validation of file paths between Windows and Linux environments, an attacker can exploit this vulnerability to delete any file on the system | 1,1% | — |
| CVE-2023-21686 | HIGH 8.8 | microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 1,1% | — |
| CVE-2022-41118 | HIGH 7.5 | microsoft windows_10 Windows Scripting Languages Remote Code Execution Vulnerability | 1,1% | — |
| CVE-2019-16153 | CRIT 9.8 | fortinet fortisiem A hard-coded password vulnerability in the Fortinet FortiSIEM database component version 5.2.5 and below may allow attackers to access the device database via the use of static credentials. | 1,1% | — |
| CVE-2019-15995 | MED 6.5 | cisco dna_spaces\ A vulnerability in the web UI of Cisco DNA Spaces: Connector could allow an authenticated, remote attacker to execute arbitrary SQL queries. The vulnerability exists because the web UI does not properly validate user-supplied input. An attacker could exploit t | 1,1% | — |
| CVE-2019-0656 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. | 1,1% | — |
| CVE-2015-6419 | MED 6.8 | cisco firesight_system_software Cisco FireSIGHT Management Center with software 4.10.3, 5.2.0, 5.3.0, 5.3.1, and 5.4.0 allows remote authenticated users to read arbitrary files via a crafted GET request, aka Bug ID CSCur25410. | 1,1% | — |
| CVE-2026-77895 | HIGH 7.5 | microsoft windows_10_1607 Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | 1,1% | — |
| CVE-2026-69342 | HIGH 7.5 | microsoft windows_10_1607 Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | 1,1% | — |
| CVE-2024-41890 | MED 5.3 | apache answer Missing Release of Resource after Effective Lifetime vulnerability in Apache Answer. This issue affects Apache Answer: through 1.3.5. User sends multiple password reset emails, each containing a valid link. Within the link's validity period, this could poten | 1,1% | — |
| CVE-2023-29055 | HIGH 7.5 | apache kylin In Apache Kylin version 2.0.0 to 4.0.3, there is a Server Config web interface that displays the content of file 'kylin.properties', that may contain serverside credentials. When the kylin service runs over HTTP (or other plain text protocol), it is possible f | 1,1% | — |
| CVE-2023-42504 | MED 5.8 | apache superset An authenticated malicious user could initiate multiple concurrent requests, each requesting multiple dashboard exports, leading to a possible denial of service. This issue affects Apache Superset: before 3.0.0 | 1,1% | — |