EN
57.918 CVE seguite
783 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

57.918 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2026-45648 HIGH 8.8 microsoft windows_server_2022 Stack-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network. 1,1%
CVE-2024-49069 HIGH 7.8 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 1,1%
CVE-2023-21743 MED 5.3 microsoft sharepoint_server Microsoft SharePoint Server Security Feature Bypass Vulnerability 1,1%
CVE-2020-14999 HIGH 7.5 acronis agent A logic bug in system monitoring driver of Acronis Agent after 12.5.21540 and before 12.5.23094 allowed to bypass Windows memory protection and access sensitive data. 1,1%
CVE-2021-26886 MED 6.1 microsoft windows_10 User Profile Service Denial of Service Vulnerability 1,1%
CVE-2018-9192 MED 5.9 fortinet fortios A plaintext recovery of encrypted messages or a Man-in-the-middle (MiTM) attack on RSA PKCS #1 v1.5 encryption may be possible without knowledge of the server's private key. Fortinet FortiOS 5.4.6 to 5.4.9, 6.0.0 and 6.0.1 are vulnerable by such attack under S 1,1%
CVE-2015-7829 LOW 1.9 adobe acrobat Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows mishandle junctions in the Synchronizer directory, 1,1%
CVE-2015-0676 HIGH 7.1 cisco adaptive_security_appliance_software The DNS implementation in Cisco Adaptive Security Appliance (ASA) Software 7.2 before 7.2(5.16), 8.2 before 8.2(5.57), 8.3 before 8.3(2.44), 8.4 before 8.4(7.28), 8.5 before 8.5(1.24), 8.6 before 8.6(1.17), 8.7 before 8.7(1.16), 9.0 before 9.0(4.33), 9.1 befor 1,1%
CVE-2022-41057 HIGH 7.8 microsoft windows_10 Windows HTTP.sys Elevation of Privilege Vulnerability 1,1%
CVE-2012-0903 MED 4.3 vmware zimbra_desktop Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Desktop 7.1.2 b10978 allow remote attackers to inject arbitrary web script or HTML via the (1) Username or (2) MailBox Name. 1,1%
CVE-2024-43467 HIGH 7.5 microsoft windows_server_2008 Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability 1,1%
CVE-2023-20873 CRIT 9.8 vmware spring_boot In Spring Boot versions 3.0.0 - 3.0.5, 2.7.0 - 2.7.10, and older unsupported versions, an application that is deployed to Cloud Foundry could be susceptible to a security bypass. Users of affected versions should apply the following mitigation: 3.0.x users sho 1,1%
CVE-2023-20863 MED 6.5 vmware spring_framework In spring framework versions prior to 5.2.24 release+ ,5.3.27+ and 6.0.8+ , it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition. 1,1%
CVE-2022-35283 MED 6.5 ibm security_verify_information_queue IBM Security Verify Information Queue 10.0.2 could allow an authenticated user to cause a denial of service with a specially crafted HTTP request. 1,1%
CVE-2019-1413 MED 4.3 microsoft edge A security feature bypass vulnerability exists when Microsoft Edge improperly handles extension requests and fails to request host permission for all_urls, aka 'Microsoft Edge Security Feature Bypass Vulnerability'. 1,1%
CVE-2017-16878 MED 6.1 paloaltonetworks pan-os Cross-site scripting (XSS) vulnerability in the Captive Portal function in Palo Alto Networks PAN-OS before 8.0.7 allows remote attackers to inject arbitrary web script or HTML by leveraging an unspecified configuration. 1,1%
CVE-2017-5083 MED 4.3 google chrome Inappropriate implementation in Blink in Google Chrome prior to 59.0.3071.86 for Mac, Windows, and Linux, and 59.0.3071.92 for Android, allowed a remote attacker to display UI on a non attacker controlled tab via a crafted HTML page. 1,1%
CVE-2016-1298 MED 6.1 cisco unified_contact_center_express Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified Contact Center Express 10.0(1), 10.5(1), 10.6(1), and 11.0(1) allow remote attackers to inject arbitrary web script or HTML via vectors related to permalinks, aka Bug ID CSCux92033. 1,1%
CVE-2016-1294 MED 6.1 cisco firesight_system_software Cross-site scripting (XSS) vulnerability in the Management Center in Cisco FireSIGHT System Software 6.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted cookie, aka Bug ID CSCuw89094. 1,1%
CVE-2016-1293 MED 6.1 cisco firesight_system_software Multiple cross-site scripting (XSS) vulnerabilities in the Management Center in Cisco FireSIGHT System Software 6.0.0 and 6.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCux40414. 1,1%
CVE-2024-38051 HIGH 7.8 microsoft windows_10_1507 Windows Graphics Component Remote Code Execution Vulnerability 1,1%
CVE-2023-36027 HIGH 7.1 microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 1,1%
CVE-2022-45064 HIGH 8.0 apache apache_sling_engine The SlingRequestDispatcher doesn't correctly implement the RequestDispatcher API resulting in a generic type of include-based cross-site scripting issues on the Apache Sling level. The vulnerability is exploitable by an attacker that is able to include a resou 1,1%
CVE-2022-21155 HIGH 7.5 fernhillsoftware scada_server A specially crafted packet sent to the Fernhill SCADA Server Version 3.77 and earlier may cause an exception, causing the server process (FHSvrService.exe) to exit. 1,1%
CVE-2020-8145 MED 6.5 ui unifi_video The UniFi Video Server (Windows) web interface configuration restore functionality at the “backup” and “wizard” endpoints does not implement sufficient privilege checks. Low privileged users, belonging to the PUBLIC_GROUP or CUSTOM_GROUP groups, can access the 1,1%