57.971 CVE seguite
784 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.971 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2024-36264 | CRIT 9.8 | apache submarine ** UNSUPPORTED WHEN ASSIGNED ** Improper Authentication vulnerability in Apache Submarine Commons Utils. If the user doesn't explicitly set `submarine.auth.default.secret`, a default value will be used. This issue affects Apache Submarine Commons Utils: fro | 1,0% | — |
| CVE-2023-36788 | HIGH 7.8 | microsoft .net_framework .NET Framework Remote Code Execution Vulnerability | 1,0% | — |
| CVE-2022-31685 | CRIT 9.8 | vmware workspace_one_assist VMware Workspace ONE Assist prior to 22.10 contains an Authentication Bypass vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application. | 1,0% | — |
| CVE-2020-11583 | MED 6.1 | plesk obsidian A GET-based XSS reflected vulnerability in Plesk Obsidian 18.0.17 allows remote unauthenticated users to inject arbitrary JavaScript, HTML, or CSS via a GET parameter. | 1,0% | — |
| CVE-2019-6604 | MED 6.8 | f5 big-ip_access_policy_manager On BIG-IP 11.5.1-11.5.8, 11.6.1-11.6.3, 12.1.0-12.1.3.6, 13.0.0-13.1.1.1, and 14.0.0-14.0.0.2, under certain conditions, hardware systems with a High-Speed Bridge and using non-default Layer 2 forwarding configurations may experience a lockup of the High-Speed | 1,0% | — |
| CVE-2019-6594 | MED 5.9 | f5 big-ip_access_policy_manager On BIG-IP 11.5.1-11.6.3.2, 12.1.3.4-12.1.3.7, 13.0.0 HF1-13.1.1.1, and 14.0.0-14.0.0.2, Multi-Path TCP (MPTCP) does not protect against multiple zero length DATA_FINs in the reassembly queue, which can lead to an infinite loop in some circumstances. | 1,0% | — |
| CVE-2017-0626 | MED 5.5 | linux linux_kernel An information disclosure vulnerability in the Qualcomm crypto engine driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without expli | 1,0% | — |
| CVE-2017-0624 | MED 5.5 | linux linux_kernel An information disclosure vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user | 1,0% | — |
| CVE-2014-9870 | HIGH 7.8 | google android The Linux kernel before 3.11 on ARM platforms, as used in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices, does not properly consider user-space access to the TPIDRURW register, which allows local users to gain privileges via a crafted application, a | 1,0% | — |
| CVE-2012-3375 | MED 4.9 | linux linux_kernel The epoll_ctl system call in fs/eventpoll.c in the Linux kernel before 3.2.24 does not properly handle ELOOP errors in EPOLL_CTL_ADD operations, which allows local users to cause a denial of service (file-descriptor consumption and system crash) via a crafted | 1,0% | — |
| CVE-2026-26122 | MED 6.5 | microsoft aci_confidential_containers Initialization of a resource with an insecure default in Azure Compute Gallery allows an authorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2025-21383 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Information Disclosure Vulnerability | 1,0% | — |
| CVE-2023-0394 | MED 5.5 | linux linux_kernel A NULL pointer dereference flaw was found in rawv6_push_pending_frames in net/ipv6/raw.c in the network subcomponent in the Linux kernel. This flaw causes the system to crash. | 1,0% | — |
| CVE-2019-1041 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, | 1,0% | — |
| CVE-2018-20245 | HIGH 7.5 | apache airflow The LDAP auth backend (airflow.contrib.auth.backends.ldap_auth) prior to Apache Airflow 1.10.1 was misconfigured and contained improper checking of exceptions which disabled server certificate checking. | 1,0% | — |
| CVE-2017-3815 | MED 5.3 | cisco telepresence_server_software An API Privilege vulnerability in Cisco TelePresence Server Software could allow an unauthenticated, remote attacker to emulate Cisco TelePresence Server endpoints. Affected Products: This vulnerability affects Cisco TelePresence Server MSE 8710 Processors tha | 1,0% | — |
| CVE-2012-3063 | HIGH 7.1 | cisco application_control_engine_software Cisco Application Control Engine (ACE) before A4(2.3) and A5 before A5(1.1), when multicontext mode is enabled, does not properly share a management IP address among multiple contexts, which allows remote authenticated administrators to bypass intended access | 1,0% | — |
| CVE-2006-1863 | LOW 2.1 | linux linux_kernel Directory traversal vulnerability in CIFS in Linux 2.6.16 and earlier allows local users to escape chroot restrictions for an SMB-mounted filesystem via "..\\" sequences, a similar vulnerability to CVE-2006-1864. | 1,0% | — |
| CVE-2026-48579 | CRIT 9.1 | microsoft exchange_online Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2022-20962 | LOW 3.8 | cisco identity_services_engine A vulnerability in the Localdisk Management feature of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to make unauthorized changes to the file system of an affected device. This vulnerability is due to insufficient input | 1,0% | — |
| CVE-2022-22319 | MED 5.4 | ibm robotic_process_automation IBM Robotic Process Automation 21.0.1 could allow a register user on the system to physically delete a queue that could cause disruption for any scripts dependent on the queue. IBM X-Force ID: 218366. | 1,0% | — |
| CVE-2022-20764 | MED 6.5 | cisco roomos Multiple vulnerabilities in the web engine of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow a remote attacker to cause a denial of service (DoS) condition, view sensitive data on an affected device, or redirect u | 1,0% | — |
| CVE-2021-40125 | MED 5.3 | cisco adaptive_security_appliance_software A vulnerability in the Internet Key Exchange Version 2 (IKEv2) implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to trigger a denial of service (Do | 1,0% | — |
| CVE-2021-1478 | MED 5.3 | cisco hosted_collaboration_mediation_fulfillment A vulnerability in the Java Management Extensions (JMX) component of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to cause a | 1,0% | — |
| CVE-2018-0388 | MED 4.8 | cisco wireless_lan_controller_software A vulnerability in the web-based interface of Cisco Wireless LAN Controller (WLC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web-based interface of an affected system. The vulne | 1,0% | — |