57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.971 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2020-1979 | HIGH 8.1 | paloaltonetworks pan-os A format string vulnerability in the PAN-OS log daemon (logd) on Panorama allows a network based attacker with knowledge of registered firewall devices and access to Panorama management interfaces to execute arbitrary code, bypassing the restricted shell and e | 1,0% | — |
| CVE-2019-13722 | MED 6.5 | google chrome Inappropriate implementation in WebRTC in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | 1,0% | — |
| CVE-2018-5519 | MED 4.9 | f5 big-ip_access_policy_manager On F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.3, or 11.2.1-11.6.3.1, administrative users by way of undisclosed methods can exploit the ssldump utility to write to arbitrary file paths. For users who do not have Advanced Shell access (for example, any user when | 1,0% | — |
| CVE-2016-3135 | HIGH 7.8 | canonical ubuntu_linux Integer overflow in the xt_alloc_table_info function in net/netfilter/x_tables.c in the Linux kernel through 4.5.2 on 32-bit platforms allows local users to gain privileges or cause a denial of service (heap memory corruption) via an IPT_SO_SET_REPLACE setsock | 1,0% | — |
| CVE-2004-1016 | LOW 2.1 | linux linux_kernel The scm_send function in the scm layer for Linux kernel 2.4.x up to 2.4.28, and 2.6.x up to 2.6.9, allows local users to cause a denial of service (system hang) via crafted auxiliary messages that are passed to the sendmsg function, which causes a deadlock con | 1,0% | — |
| CVE-2024-41040 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/sched: Fix UAF when resolving a clash KASAN reports the following UAF: BUG: KASAN: slab-use-after-free in tcf_ct_flow_table_process_conn+0x12b/0x380 [act_ct] Read of size 1 at addr ff | 1,0% | — |
| CVE-2021-22128 | HIGH 7.1 | fortinet fortiproxy An improper access control vulnerability in FortiProxy SSL VPN portal 2.0.0, 1.2.9 and below versions may allow an authenticated, remote attacker to access internal service such as the ZebOS Shell on the FortiProxy appliance through the Quick Connection functi | 1,0% | — |
| CVE-2020-16913 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could th | 1,0% | — |
| CVE-2020-16907 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could th | 1,0% | — |
| CVE-2020-16890 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; vi | 1,0% | — |
| CVE-2020-0703 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Backup Service Elevation of Privi | 1,0% | — |
| CVE-2017-0651 | MED 4.7 | linux linux_kernel An information disclosure vulnerability in the kernel ION subsystem could enable a local malicious application to access data outside of its permission levels. This issue is rated as Low because it first requires compromising a privileged process. Product: And | 1,0% | — |
| CVE-2025-67895 | CRIT 9.8 | apache apache-airflow-providers-edge3 Edge3 Worker RPC RCE on Airflow 2. This issue affects Apache Airflow Providers Edge3: before 2.0.0 - and only if you installed and configured it on Airflow 2. The Edge3 provider support in Airflow 2 has been always development-only and not officially relea | 1,0% | — |
| CVE-2022-20846 | MED 4.3 | cisco ios_xr A vulnerability in the Cisco Discovery Protocol implementation for Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause the Cisco Discovery Protocol process to reload on an affected device. This vulnerability is due | 1,0% | — |
| CVE-2023-33135 | HIGH 7.3 | microsoft .net .NET and Visual Studio Elevation of Privilege Vulnerability | 1,0% | — |
| CVE-2023-33128 | HIGH 7.3 | microsoft .net .NET and Visual Studio Remote Code Execution Vulnerability | 1,0% | — |
| CVE-2023-33126 | HIGH 7.3 | microsoft .net .NET and Visual Studio Remote Code Execution Vulnerability | 1,0% | — |
| CVE-2021-36184 | HIGH 8.8 | fortinet fortiwlm A improper neutralization of Special Elements used in an SQL Command ('SQL Injection') in Fortinet FortiWLM version 8.6.1 and below allows attacker to disclosure device, users and database information via crafted HTTP requests. | 1,0% | — |
| CVE-2021-34754 | MED 5.8 | cisco secure_firewall_management_center Multiple vulnerabilities in the payload inspection for Ethernet Industrial Protocol (ENIP) traffic for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured rules for ENIP traffic. These vulnerabilit | 1,0% | — |
| CVE-2021-21682 | MED 4.3 | jenkins jenkins Jenkins 2.314 and earlier, LTS 2.303.1 and earlier accepts names of jobs and other entities with a trailing dot character, potentially replacing the configuration and data of other entities on Windows. | 1,0% | — |
| CVE-2021-34696 | MED 5.8 | cisco ios_xe A vulnerability in the access control list (ACL) programming of Cisco ASR 900 and ASR 920 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to incorrect programming of hard | 1,0% | — |
| CVE-2021-22023 | HIGH 7.2 | vmware cloud_foundation The vRealize Operations Manager API (8.x prior to 8.5) has insecure object reference vulnerability. A malicious actor with administrative access to vRealize Operations Manager API may be able to modify other users information leading to an account takeover. | 1,0% | — |
| CVE-2021-1591 | MED 5.8 | cisco nx-os A vulnerability in the EtherChannel port subscription logic of Cisco Nexus 9500 Series Switches could allow an unauthenticated, remote attacker to bypass access control list (ACL) rules that are configured on an affected device. This vulnerability is due to ov | 1,0% | — |
| CVE-2020-5022 | MED 5.3 | ibm spectrum_protect_plus IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may allow unauthenticated and unauthorized access to VDAP proxy which can result in an attacker obtaining information they are not authorized to access. IBM X-Force ID: 193658. | 1,0% | — |
| CVE-2019-15712 | HIGH 7.2 | fortinet fortimail An improper access control vulnerability in FortiMail admin webUI 6.2.0, 6.0.0 to 6.0.6, 5.4.10 and below may allow administrators to access web console they should not be authorized for. | 1,0% | — |