57.961 CVE seguite
784 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.961 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-32071 | HIGH 7.5 | microsoft windows_10_1607 Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network. | 1,1% | — |
| CVE-2025-20374 | MED 4.9 | cisco unified_contact_center_express A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to perform a directory traversal and access arbitrary resources. This vulnerability is due to an insufficient input validation associated to specific UI feature | 1,1% | — |
| CVE-2023-36639 | HIGH 7.2 | fortinet fortios A use of externally-controlled format string in Fortinet FortiProxy versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.10, FortiOS versions 7.4.0, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiPA | 1,1% | — |
| CVE-2022-34719 | HIGH 7.8 | microsoft windows_10 Windows Distributed File System (DFS) Elevation of Privilege Vulnerability | 1,1% | — |
| CVE-2022-21897 | HIGH 7.8 | microsoft windows_10 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 1,1% | — |
| CVE-2020-5864 | HIGH 7.4 | f5 nginx_controller In versions of NGINX Controller prior to 3.2.0, communication between NGINX Controller and NGINX Plus instances skip TLS verification by default. | 1,1% | — |
| CVE-2017-10887 | HIGH 7.8 | bookwalker book_walker Untrusted search path vulnerability in BOOK WALKER for Windows Ver.1.2.9 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | 1,1% | — |
| CVE-2017-10855 | HIGH 7.8 | fujitsu fence-explorer Untrusted search path vulnerability in FENCE-Explorer for Windows V8.4.1 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | 1,1% | — |
| CVE-2017-10851 | HIGH 7.8 | fujixerox contentsbridge_utility Untrusted search path vulnerability in Installer for ContentsBridge Utility for Windows 7.4.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | 1,1% | — |
| CVE-2024-49065 | MED 5.5 | microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability | 1,1% | — |
| CVE-2024-31869 | MED 4.3 | apache airflow Airflow versions 2.7.0 through 2.8.4 have a vulnerability that allows an authenticated user to see sensitive provider configuration via the "configuration" UI page when "non-sensitive-only" was set as "webserver.expose_config" configuration (The celery provide | 1,1% | — |
| CVE-2023-24895 | HIGH 7.8 | microsoft .net .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability | 1,1% | — |
| CVE-2019-6610 | HIGH 8.6 | f5 big-ip_access_policy_manager On BIG-IP versions 14.0.0-14.0.0.4, 13.0.0-13.1.1.1, 12.1.0-12.1.4, 11.6.0-11.6.3.4, and 11.5.1-11.5.8, the system is vulnerable to a denial of service attack when performing URL classification. | 1,1% | — |
| CVE-2018-16968 | LOW 3.1 | citrix sharefile_storagezones_controller Citrix ShareFile StorageZones Controller before 5.4.2 allows Directory Traversal. | 1,1% | — |
| CVE-2005-3257 | MED 4.6 | linux linux_kernel The VT implementation (vt_ioctl.c) in Linux kernel 2.6.12, and possibly other versions including 2.6.14.4, allows local users to use the KDSKBSENT ioctl on terminals of other users and gain privileges, as demonstrated by modifying key bindings using loadkeys. | 1,1% | — |
| CVE-2026-62901 | HIGH 7.5 | microsoft .net Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network. | 1,1% | — |
| CVE-2023-21800 | HIGH 7.8 | microsoft windows_server_2008 Windows Installer Elevation of Privilege Vulnerability | 1,1% | — |
| CVE-2022-22203 | MED 6.5 | juniper junos An Incorrect Comparison vulnerability in PFE of Juniper Networks Junos OS allows an adjacent unauthenticated attacker to cause a Denial of Service (DoS). On QFX5000 Series, and EX4600 and EX4650 platforms, the fxpc process will crash followed by the FPC reboot | 1,1% | — |
| CVE-2022-26071 | HIGH 7.4 | f5 big-ip_access_policy_manager On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, a flaw in the way reply ICMP packets are limited in the Traffic Manage | 1,1% | — |
| CVE-2021-1725 | MED 5.5 | microsoft bot_framework_software_development_kit Bot Framework SDK Information Disclosure Vulnerability | 1,1% | — |
| CVE-2020-3449 | MED 4.3 | cisco ios_xr A vulnerability in the Border Gateway Protocol (BGP) additional paths feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to prevent authorized users from monitoring the BGP status and cause the BGP process to stop processing new u | 1,1% | — |
| CVE-2020-0983 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Delivery Optimization service improperly handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0934, CVE-2020-1009, CVE-2020-1011, CVE- | 1,1% | — |
| CVE-2019-15259 | MED 6.1 | cisco unified_contact_center_express A vulnerability in Cisco Unified Contact Center Express (UCCX) Software could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack. The vulnerability is due to insufficient input validation of some parameters that are passed t | 1,1% | — |
| CVE-2019-12716 | MED 6.1 | cisco unified_communications_manager A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified Communications Manager Session Management Edition (SME) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against | 1,1% | — |
| CVE-2019-12715 | MED 6.1 | cisco unified_communications_manager A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified Communications Manager Session Management Edition (SME) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against | 1,1% | — |