EN
57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

57.971 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2017-8574 HIGH 7.0 microsoft windows_10 Graphics in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability when it fails to properly handle objects in memory, aka "Microsoft Graphics Component Elevation of Privilege Vulnerability". This CVE ID is uniq 1,0%
CVE-2017-6617 MED 5.4 cisco integrated_management_controller_supervisor A vulnerability in the session identification management functionality of the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an unauthenticated, remote attacker to hijack a valid user session on an affected system. The vulner 1,0%
CVE-2012-6029 MED 4.3 cisco nac_appliance Multiple cross-site scripting (XSS) vulnerabilities in the web-authentication function on the Cisco NAC Appliance 4.9.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) cm or (2) uri parameters to (a) perfigo_weblogin.jsp, 1,0%
CVE-2025-49677 HIGH 7.0 microsoft windows_11_22h2 Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. 1,0%
CVE-2024-39547 HIGH 7.5 juniper junos_containerized_routing_protocol_daemon An Improper Handling of Exceptional Conditions vulnerability in the rpd-server of Juniper Networks Junos OS and Junos OS Evolved within cRPD allows an unauthenticated network-based attacker sending crafted TCP traffic to the routing engine (RE) to cause a CPU- 1,0%
CVE-2024-29217 MED 4.6 apache answer Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Answer.This issue affects Apache Answer: before 1.3.0. XSS attack when user changes personal website. A logged-in user, when modifying their personal 1,0%
CVE-2020-7804 MED 6.4 handysoft groupware ActiveX Control(HShell.dll) in Handy Groupware 1.7.3.1 for Windows 7, 8, and 10 allows an attacker to execute arbitrary command via the ShellExec method. 1,0%
CVE-2020-0695 MED 5.4 microsoft office_online_server A spoofing vulnerability exists when Office Online Server does not validate origin in cross-origin communications correctly, aka 'Microsoft Office Online Server Spoofing Vulnerability'. 1,0%
CVE-2019-0048 MED 5.8 juniper junos On EX4300 Series switches with TCAM optimization enabled, incoming multicast traffic matches an implicit loopback filter rule first, since it has high priority. This rule is meant for reserved multicast addresses 224.0.0.x, but incorrectly matches on 224.x.x.x 1,0%
CVE-2018-15437 MED 5.5 cisco advanced_malware_protection_for_endpoints A vulnerability in the system scanning component of Cisco Immunet and Cisco Advanced Malware Protection (AMP) for Endpoints running on Microsoft Windows could allow a local attacker to disable the scanning functionality of the product. This could allow executa 1,0%
CVE-2015-6371 MED 4.0 cisco firepower_extensible_operating_system Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote authenticated users to read arbitrary files via crafted parameters to unspecified scripts, aka Bug ID CSCux10621. 1,0%
CVE-2025-59284 LOW 3.3 microsoft windows_11_22h2 Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing locally. 1,0%
CVE-2023-36598 HIGH 7.8 microsoft windows_10_1507 Microsoft WDAC ODBC Driver Remote Code Execution Vulnerability 1,0%
CVE-2023-36908 MED 6.5 microsoft windows_10 Windows Hyper-V Information Disclosure Vulnerability 1,0%
CVE-2023-24935 MED 6.1 microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability 1,0%
CVE-2022-21995 HIGH 7.9 microsoft windows_10 Windows Hyper-V Remote Code Execution Vulnerability 1,0%
CVE-2021-38975 MED 6.5 ibm security_guardium_key_lifecycle_manager IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow an authenticated user to to obtain sensitive information from a specially crafted HTTP request. IBM X-Force ID: 212780. 1,0%
CVE-2021-28954 HIGH 7.8 bit_project bit In Chris Walz bit before 1.0.5 on Windows, attackers can run arbitrary code via a .exe file in a crafted repository. 1,0%
CVE-2021-26899 HIGH 7.8 microsoft windows_10 Windows UPnP Device Host Elevation of Privilege Vulnerability 1,0%
CVE-2020-0648 HIGH 7.8 microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows RSoP Service Application improperly handles memory.</p> <p>To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a speci 1,0%
CVE-2020-14356 HIGH 7.8 canonical ubuntu_linux A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versions before 5.7.10 was found in the way when reboot the system. A local user could use this flaw to crash the system or escalate their privileges on the system. 1,0%
CVE-2019-5590 MED 6.1 fortinet fortiweb The URL part of the report message is not encoded in Fortinet FortiWeb 6.0.2 and below which may allow an attacker to execute unauthorized code or commands (Cross Site Scripting) via attack reports generated in HTML form. 1,0%
CVE-2026-47301 HIGH 8.8 microsoft configuration_manager_2503 Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network. 1,0%
CVE-2023-44794 CRIT 9.8 dromara sa-token An issue in Dromara SaToken version 1.36.0 and before allows a remote attacker to escalate privileges via a crafted payload to the URL. 1,0%
CVE-2023-20045 MED 4.9 cisco rv160_vpn_router_firmware A vulnerability in the web-based management interface of Cisco Small Business RV160 and RV260 Series VPN Routers could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. This vulne 1,0%