57.859 CVE seguite
783 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.859 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2022-20883 | MED 4.7 | cisco application_extension_platform Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpe | 1,1% | — |
| CVE-2022-20880 | MED 4.7 | cisco application_extension_platform Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpe | 1,1% | — |
| CVE-2022-20879 | MED 4.7 | cisco application_extension_platform Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpe | 1,1% | — |
| CVE-2022-20873 | MED 4.7 | cisco application_extension_platform Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpe | 1,1% | — |
| CVE-2021-26623 | HIGH 7.8 | bandisoft bandizip A remote code execution vulnerability due to incomplete check for 'xheader_decode_path_record' function's parameter length value in the ark library. Remote attackers can induce exploit malicious code using this function. | 1,1% | — |
| CVE-2022-23281 | MED 5.5 | microsoft windows_10 Windows Common Log File System Driver Information Disclosure Vulnerability | 1,1% | — |
| CVE-2021-1677 | MED 5.5 | microsoft azure_kubernetes_service Azure Active Directory Pod Identity Spoofing Vulnerability | 1,1% | — |
| CVE-2018-18688 | MED 5.3 | code-industry master_pdf_editor The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, an Incremental Saving vulnerability exists in multiple products. When an attacker uses the Increment | 1,1% | — |
| CVE-2020-3472 | MED 5.0 | cisco webex_meetings_online A vulnerability in the contacts feature of Cisco Webex Meetings could allow an authenticated, remote attacker with a legitimate user account to access sensitive information. The vulnerability is due to improper access restrictions on users who are added within | 1,1% | — |
| CVE-2018-15380 | HIGH 8.8 | cisco hyperflex_hx_data_platform A vulnerability in the cluster service manager of Cisco HyperFlex Software could allow an unauthenticated, adjacent attacker to execute commands as the root user. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnera | 1,1% | — |
| CVE-2017-5118 | MED 4.3 | debian debian_linux Blink in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3163.81 for Android, failed to correctly propagate CSP restrictions to javascript scheme pages, which allowed a remote attacker to bypass content security policy via a crafted H | 1,1% | — |
| CVE-2002-1097 | HIGH 7.5 | cisco vpn_3000_concentrator_series_software Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.2, allows restricted administrators to obtain certificate passwords that are stored in plaintext in the HTML source code for Certificate Management pages. | 1,1% | — |
| CVE-2023-49620 | MED 6.5 | apache dolphinscheduler Before DolphinScheduler version 3.1.0, the login user could delete UDF function in the resource center unauthorized (which almost used in sql task), with unauthorized access vulnerability (IDOR), but after version 3.1.0 we fixed this issue. We mark this cve as | 1,1% | — |
| CVE-2023-33165 | MED 4.3 | microsoft sharepoint_server Microsoft SharePoint Server Security Feature Bypass Vulnerability | 1,1% | — |
| CVE-2021-21057 | MED 6.6 | adobe acrobat Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a null pointer dereference vulnerability when parsing a specially crafted PDF file. An unauthenticated attacker coul | 1,1% | — |
| CVE-2019-1340 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows AppX Deployment Server that allows file creation in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Elevation of Privilege | 1,1% | — |
| CVE-2017-3798 | MED 6.1 | cisco unified_communications_manager A cross-site scripting (XSS) filter bypass vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to mount XSS attacks against a user of an affected device. More Information: | 1,1% | — |
| CVE-2014-7822 | HIGH 7.2 | linux linux_kernel The implementation of certain splice_write file operations in the Linux kernel before 3.16 does not enforce a restriction on the maximum size of a single file, which allows local users to cause a denial of service (system crash) or possibly have unspecified ot | 1,1% | — |
| CVE-2025-26687 | HIGH 7.5 | microsoft 365_copilot Use after free in Windows Win32K - GRFX allows an unauthorized attacker to elevate privileges over a network. | 1,1% | — |
| CVE-2023-24911 | MED 4.3 | microsoft windows_10_1607 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | 1,1% | — |
| CVE-2018-8404 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows Server 2012, Windows 8.1, | 1,1% | — |
| CVE-2010-3050 | MED 6.5 | cisco ios Cisco IOS before 12.2(33)SXI allows remote authenticated users to cause a denial of service (device reboot). | 1,1% | — |
| CVE-2012-5030 | MED 6.5 | cisco ios Cisco IOS before 15.2(4)S6 does not initialize an unspecified variable, which might allow remote authenticated users to cause a denial of service (CPU consumption, watchdog timeout, crash) by walking specific SNMP objects. | 1,1% | — |
| CVE-2017-3810 | MED 5.4 | cisco prime_service_catalog A vulnerability in the web framework of Cisco Prime Service Catalog could allow an authenticated, remote attacker to conduct a web URL redirect attack against a user who is logged in to an affected system. More Information: CSCvb21745. Known Affected Releases: | 1,1% | — |
| CVE-2022-44688 | MED 4.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability | 1,1% | — |