57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.971 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2022-21855 | CRIT 9.0 | microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 0,9% | — |
| CVE-2020-16976 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations.</p> <p>To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specia | 0,9% | — |
| CVE-2017-6649 | HIGH 7.8 | cisco nx-os A vulnerability in the CLI of Cisco NX-OS System Software 7.1 through 7.3 running on Cisco Nexus Series Switches could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation of co | 0,9% | — |
| CVE-2016-6442 | HIGH 8.8 | cisco finesse A vulnerability in Cisco Finesse Agent and Supervisor Desktop Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against the user of the web interface. More Information: CSCvb57213. Known Affected Rel | 0,9% | — |
| CVE-2016-6376 | MED 6.5 | cisco wireless_lan_controller The Adaptive Wireless Intrusion Prevention System (wIPS) feature on Cisco Wireless LAN Controller (WLC) devices before 8.0.140.0, 8.1.x and 8.2.x before 8.2.121.0, and 8.3.x before 8.3.102.0 allows remote attackers to cause a denial of service (device restart) | 0,9% | — |
| CVE-2026-43867 | CRIT 9.8 | apache camel Deserialization of Untrusted Data vulnerability in Apache Camel PQC Component. The camel-pqc component persists post-quantum key metadata (KeyMetadata) through pluggable KeyLifecycleManager implementations. AwsSecretsManagerKeyLifecycleManager.deserializeMeta | 0,9% | — |
| CVE-2024-41817 | HIGH 7.0 | imagemagick imagemagick ImageMagick is a free and open-source software suite, used for editing and manipulating digital images. The `AppImage` version `ImageMagick` might use an empty path when setting `MAGICK_CONFIGURE_PATH` and `LD_LIBRARY_PATH` environment variables while executin | 0,9% | — |
| CVE-2024-26232 | HIGH 7.3 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 0,9% | — |
| CVE-2024-20267 | HIGH 8.6 | cisco nx-os A vulnerability with the handling of MPLS traffic for Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause the netstack process to unexpectedly restart, which could cause the device to stop processing network traffic or to reload. | 0,9% | — |
| CVE-2023-21568 | HIGH 7.3 | microsoft sql_server_2019_integration_services Microsoft SQL Server Integration Service (VS extension) Remote Code Execution Vulnerability | 0,9% | — |
| CVE-2022-20848 | HIGH 8.6 | cisco ios_xe A vulnerability in the UDP processing functionality of Cisco IOS XE Software for Embedded Wireless Controllers on Catalyst 9100 Series Access Points could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerabilit | 0,9% | — |
| CVE-2021-41026 | MED 6.5 | fortinet fortiweb A relative path traversal in FortiWeb versions 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allow an authenticated attacker to retrieve arbitrary files from the underlying filesystem via specially crafted web requests. | 0,9% | — |
| CVE-2022-23774 | MED 5.3 | docker docker_desktop Docker Desktop before 4.4.4 on Windows allows attackers to move arbitrary files. | 0,9% | — |
| CVE-2020-7852 | HIGH 7.8 | hmtalk daviewindy DaviewIndy has a Heap-based overflow vulnerability, triggered when the user opens a malformed ex.j2c format file that is mishandled by Daview.exe. Attackers could exploit this and arbitrary code execution. | 0,9% | — |
| CVE-2019-1314 | MED 6.8 | microsoft windows_10_mobile A security feature bypass vulnerability exists in Windows 10 Mobile when Cortana allows a user to access files and folders through the locked screen, aka 'Windows 10 Mobile Security Feature Bypass Vulnerability'. | 0,9% | — |
| CVE-2019-0016 | MED 6.5 | juniper junos_space A malicious authenticated user may be able to delete a device from the Junos Space database without the necessary privileges through crafted Ajax interactions obtained from another legitimate delete action performed by another administrative user. Affected rel | 0,9% | — |
| CVE-2017-12344 | MED 6.1 | cisco data_center_network_manager Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) Software could allow a remote attacker to inject arbitrary values into DCNM configuration parameters, redirect a user to a malicious website, inject malicious content into a DCNM client inter | 0,9% | — |
| CVE-2016-3258 | MED 4.7 | microsoft windows_10 Race condition in the kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to bypass the Low Integrity protection mechanism and write to files by leveraging unspecified object-manager | 0,9% | — |
| CVE-2011-4014 | MED 4.0 | cisco wireless_control_system_software The TAC Case Attachment tool in Cisco Wireless Control System (WCS) 7.0 allows remote authenticated users to read arbitrary files under webnms/Temp/ via unspecified vectors, aka Bug ID CSCtq86807. | 0,9% | — |
| CVE-2024-38176 | HIGH 8.1 | microsoft groupme An improper restriction of excessive authentication attempts in GroupMe allows a unauthenticated attacker to elevate privileges over a network. | 0,9% | — |
| CVE-2024-38017 | MED 5.5 | microsoft windows_10_1507 Microsoft Message Queuing Information Disclosure Vulnerability | 0,9% | — |
| CVE-2024-25015 | HIGH 7.5 | ibm mq IBM MQ 9.2 LTS, 9.3 LTS, and 9.3 CD Internet Pass-Thru could allow a remote user to cause a denial of service by sending HTTP requests that would consume all available resources. IBM X-Force ID: 281278. | 0,9% | — |
| CVE-2022-24455 | HIGH 7.8 | microsoft windows_10 Windows CD-ROM Driver Elevation of Privilege Vulnerability | 0,9% | — |
| CVE-2021-22036 | MED 6.5 | vmware vrealize_automation VMware vRealize Orchestrator ((8.x prior to 8.6) contains an open redirect vulnerability due to improper path handling. A malicious actor may be able to redirect victim to an attacker controlled domain due to improper path handling in vRealize Orchestrator lea | 0,9% | — |
| CVE-2021-1420 | MED 4.7 | cisco webex_meetings A vulnerability in certain web pages of Cisco Webex Meetings could allow an unauthenticated, remote attacker to modify a web page in the context of a user's browser. The vulnerability is due to improper checks on parameter values in affected pages. An attacker | 0,9% | — |