57.954 CVE seguite
784 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.954 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2020-17521 | MED 5.5 | apache atlas Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operating systems | 1,1% | — |
| CVE-2019-1571 | MED 4.8 | paloaltonetworks expedition The Expedition Migration tool 1.1.8 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the RADIUS server settings. | 1,1% | — |
| CVE-2019-1570 | MED 4.8 | paloaltonetworks expedition The Expedition Migration tool 1.1.8 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the LDAP server settings. | 1,1% | — |
| CVE-2019-1569 | MED 4.8 | paloaltonetworks expedition The Expedition Migration tool 1.1.8 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the User Mapping Settings for account name of admin user. | 1,1% | — |
| CVE-2024-32115 | MED 5.5 | fortinet fortimanager A relative path traversal vulnerability [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 allows a privileged attacker to delete files from the underlying filesystem via crafted HTTP or HTTPs requests. | 1,1% | — |
| CVE-2024-49090 | HIGH 7.8 | microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 1,1% | — |
| CVE-2024-38190 | HIGH 8.6 | microsoft power_platform Missing authorization in Power Platform allows an unauthenticated attacker to view sensitive information through a network attack vector. | 1,1% | — |
| CVE-2024-20738 | CRIT 9.8 | adobe framemaker_publishing_server Adobe FrameMaker Publishing Server versions 2022.1 and earlier are affected by an Improper Authentication vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass authentication mechanisms and gain u | 1,1% | — |
| CVE-2023-38140 | MED 5.5 | microsoft windows_10_1607 Windows Kernel Information Disclosure Vulnerability | 1,1% | — |
| CVE-2022-41044 | HIGH 8.1 | microsoft windows_7 Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | 1,1% | — |
| CVE-2020-5933 | HIGH 7.5 | f5 big-ip_access_policy_manager On versions 15.1.0-15.1.0.5, 14.1.0-14.1.2.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, when a BIG-IP system that has a virtual server configured with an HTTP compression profile processes compressed HTTP message payloads that require deflation, a | 1,1% | — |
| CVE-2020-3583 | MED 6.1 | cisco adaptive_security_appliance_software Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a | 1,1% | — |
| CVE-2020-1683 | HIGH 7.5 | juniper junos On Juniper Networks Junos OS devices, a specific SNMP OID poll causes a memory leak which over time leads to a kernel crash (vmcore). Prior to the kernel crash other processes might be impacted, such as failure to establish SSH connection to the device. The ad | 1,1% | — |
| CVE-2020-1632 | HIGH 8.6 | juniper junos In a certain condition, receipt of a specific BGP UPDATE message might cause Juniper Networks Junos OS and Junos OS Evolved devices to advertise an invalid BGP UPDATE message to other peers, causing the other peers to terminate the established BGP session, cre | 1,1% | — |
| CVE-2019-6681 | HIGH 7.5 | f5 big-ip_local_traffic_manager On BIG-IP versions 15.0.0-15.0.1.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, and 12.1.0-12.1.5, a memory leak in Multicast Forwarding Cache (MFC) handling in tmrouted. | 1,1% | — |
| CVE-2019-6680 | HIGH 7.5 | f5 big-ip_access_policy_manager On BIG-IP versions 15.0.0-15.0.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.2, 12.1.0-12.1.5, and 11.5.2-11.6.5, while processing traffic through a standard virtual server that targets a FastL4 virtual server (VIP on VIP), hardware appliances may stop respon | 1,1% | — |
| CVE-2019-11751 | HIGH 8.8 | mozilla firefox Logging-related command line parameters are not properly sanitized when Firefox is launched by another program, such as when a user clicks on malicious links in a chat application. This can be used to write a log file to an arbitrary location such as the Windo | 1,1% | — |
| CVE-2018-8566 | MED 4.6 | microsoft windows_10 A security feature bypass vulnerability exists when Windows improperly suspends BitLocker Device Encryption, aka "BitLocker Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows Server 2019, Windows 10 Servers. | 1,1% | — |
| CVE-2018-6958 | MED 6.1 | vmware vrealize_automation VMware vRealize Automation (vRA) prior to 7.3.1 contains a vulnerability that may allow for a DOM-based cross-site scripting (XSS) attack. Exploitation of this issue may lead to the compromise of the vRA user's workstation. | 1,1% | — |
| CVE-2017-6167 | HIGH 7.5 | f5 big-ip_access_policy_manager In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM and WebSafe software version 13.0.0 and 12.1.0 - 12.1.2, race conditions in iControl REST may lead to commands being executed with different privilege levels than expected. | 1,1% | — |
| CVE-2017-7737 | MED 4.9 | fortinet fortiweb An information disclosure vulnerability in Fortinet FortiWeb 5.8.2 and below versions allows logged-in admin user to view SNMPv3 user password in cleartext in webui via the HTML source code. | 1,1% | — |
| CVE-2017-7337 | CRIT 9.1 | fortinet fortiportal An improper Access Control vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to interact with unauthorized VDOMs or enumerate other ADOMs via another user's stolen session and CSRF tokens or the adomName parameter in the /fpc/se | 1,1% | — |
| CVE-2024-26240 | HIGH 8.0 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 1,1% | — |
| CVE-2024-24989 | HIGH 7.5 | f5 nginx_open_source When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note: The HTTP/3 QUIC module is not enabled by default and is considered experimental. For more information, refer t | 1,1% | — |
| CVE-2023-46120 | MED 4.9 | vmware rabbitmq_java_client The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. `maxBodyLebgth` was not used when receiving Message objects. Attackers could send a very large Message causing a memory overflow and trigge | 1,1% | — |