EN
57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

57.971 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2021-26618 HIGH 7.1 tmax tooffice An improper input validation leading to arbitrary file creation was discovered in ToWord of ToOffice. Remote attackers use this vulnerability to execute arbitrary file included malicious code. 1,0%
CVE-2022-21847 MED 6.5 microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability 1,0%
CVE-2018-18966 MED 4.9 oscommerce online_merchant osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. The .htaccess file in catalog/images/ bans the html extension, but Internet Explorer render HTML elements in a .eml file. 1,0%
CVE-2017-12228 MED 5.9 cisco ios A vulnerability in the Cisco Network Plug and Play application of Cisco IOS 12.4 through 15.6 and Cisco IOS XE 3.3 through 16.4 could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data by using an invalid certificate. The v 1,0%
CVE-2015-7997 MED 4.3 citrix netscaler_application_delivery_controller_firmware Multiple cross-site scripting (XSS) vulnerabilities in the Nitro API in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 133.9, 10.5 before Build 58.11, and 10.5.e before Build 56.1505.e on NetScaler Service Delive 1,0%
CVE-2013-1245 MED 4.0 cisco webex_social The user-management page in Cisco WebEx Social relies on client-side validation of values in the Screen Name, First Name, Middle Name, Last Name, Email Address, and Job Title fields, which allows remote authenticated users to bypass intended access restriction 1,0%
CVE-2026-69910 CRIT 9.8 microsoft windows_10_1607 Stack-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code over a network. 1,0%
CVE-2026-69496 CRIT 9.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Compressed Folder allows an unauthorized attacker to execute code over a network. 1,0%
CVE-2024-52055 MED 4.9 wowza streaming_engine Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to read any file on the file system if the target directory contains an XML definition file. 1,0%
CVE-2024-39863 MED 5.4 apache airflow Apache Airflow versions before 2.9.3 have a vulnerability that allows an authenticated attacker to inject a malicious link when installing a provider. Users are recommended to upgrade to version 2.9.3, which fixes this issue. 1,0%
CVE-2023-35635 MED 5.5 microsoft windows_11_22h2 Windows Kernel Denial of Service Vulnerability 1,0%
CVE-2022-40747 CRIT 9.1 ibm infosphere_information_server "IBM InfoSphere Information Server 11.7 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 236 1,0%
CVE-2021-34774 MED 4.9 cisco common_services_platform_collector A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to access sensitive data on an affected system. This vulnerability exists because the application does not su 1,0%
CVE-2020-17038 HIGH 7.8 microsoft windows_10 Win32k Elevation of Privilege Vulnerability 1,0%
CVE-2020-0998 HIGH 7.8 microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context.</p> <p>In a local attack scenario, 1,0%
CVE-2020-0870 HIGH 7.8 microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Shell infrastructure component improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context.</p> <p>To exploit this vulnera 1,0%
CVE-2020-0838 HIGH 7.8 microsoft windows_10 <p>An elevation of privilege vulnerability exists when NTFS improperly checks access. An attacker who successfully exploited this vulnerability could run processes in an elevated context.</p> <p>To exploit the vulnerability, an attacker would first have to log 1,0%
CVE-2020-0782 HIGH 7.8 microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Cryptographic Catalog Services improperly handle objects in memory. An attacker who successfully exploited this vulnerability could modify the cryptographic catalog.</p> <p>To exploit this vuln 1,0%
CVE-2019-15703 HIGH 7.5 fortinet fortios An Insufficient Entropy in PRNG vulnerability in Fortinet FortiOS 6.2.1, 6.2.0, 6.0.8 and below for device not enable hardware TRNG token and models not support builtin TRNG seed allows attacker to theoretically recover the long term ECDSA secret in a TLS clie 1,0%
CVE-2018-0189 MED 5.3 cisco ios_xe A vulnerability in the Forwarding Information Base (FIB) code of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, network attacker to cause a denial of service (DoS) condition. The vulnerability is due to a limitation in the way the 1,0%
CVE-2015-6304 MED 6.8 cisco telepresence_server_software Cross-site request forgery (CSRF) vulnerability in Cisco TelePresence Server software 3.0(2.24) allows remote attackers to hijack the authentication of arbitrary users, aka Bug IDs CSCut63718, CSCut63724, and CSCut63760. 1,0%
CVE-2015-6262 MED 6.8 cisco prime_infrastructure Cross-site request forgery (CSRF) vulnerability in Cisco Prime Infrastructure 1.2(0.103) and 2.0(0.0) allows remote attackers to hijack the authentication of arbitrary users, aka Bug IDs CSCum49054 and CSCum49059. 1,0%
CVE-2015-4267 MED 6.8 cisco identity_services_engine_software Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco Identity Services Engine (ISE) 1.2(0.793), 1.3(0.876), 1.4(0.109), 2.0(0.147), and 2.0(0.169) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCu 1,0%
CVE-2015-4258 MED 6.8 cisco telepresence_mse_8000_series Cross-site request forgery (CSRF) vulnerability on Cisco TelePresence MSE 8000 devices allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuu90444. 1,0%
CVE-2015-4257 MED 6.8 cisco telepresence_mcu_software Cross-site request forgery (CSRF) vulnerability on Cisco TelePresence MCU 4500 devices with software 4.5(1.55) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuu90710. 1,0%