57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.971 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2025-54917 | MED 4.3 | microsoft windows_10_1507 Protection mechanism failure in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network. | 0,9% | — |
| CVE-2023-45284 | MED 5.3 | golang go On Windows, The IsLocal function does not correctly detect reserved device names in some cases. Reserved names followed by spaces, such as "COM1 ", and reserved names "COM" and "LPT" followed by superscript 1, 2, or 3, are incorrectly reported as local. With f | 0,9% | — |
| CVE-2023-27871 | HIGH 7.5 | ibm aspera_faspex IBM Aspera Faspex 4.4.2 could allow a remote attacker to obtain sensitive credential information for an external user, using a specially crafted SQL query. IBM X-Force ID: 249613. | 0,9% | — |
| CVE-2022-20918 | HIGH 7.5 | cisco firepower_services_software_for_asa A vulnerability in the Simple Network Management Protocol (SNMP) access controls for Cisco FirePOWER Software for Adaptive Security Appliance (ASA) FirePOWER module, Cisco Firepower Management Center (FMC) Software, and Cisco Next-Generation Intrusion Preventi | 0,9% | — |
| CVE-2021-44226 | HIGH 7.3 | razer synapse Razer Synapse before 3.7.0228.022817 allows privilege escalation because it relies on %PROGRAMDATA%\Razer\Synapse3\Service\bin even if %PROGRAMDATA%\Razer has been created by any unprivileged user before Synapse is installed. The unprivileged user may have pla | 0,9% | — |
| CVE-2021-24010 | HIGH 8.1 | fortinet fortisandbox Improper limitation of a pathname to a restricted directory vulnerabilities in FortiSandbox 3.2.0 through 3.2.2, and 3.1.0 through 3.1.4 may allow an authenticated user to obtain unauthorized access to files and data via specifially crafted web requests. | 0,9% | — |
| CVE-2021-33767 | HIGH 8.2 | microsoft open_enclave_software_development_kit Open Enclave SDK Elevation of Privilege Vulnerability | 0,9% | — |
| CVE-2020-0697 | HIGH 7.8 | microsoft office_365_proplus An elevation of privilege vulnerability exists in Microsoft Office OLicenseHeartbeat task, where an attacker who successfully exploited this vulnerability could run this task as SYSTEM.To exploit the vulnerability, an authenticated attacker would need to place | 0,9% | — |
| CVE-2019-1018 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delet | 0,9% | — |
| CVE-2019-1017 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install pr | 0,9% | — |
| CVE-2019-1014 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install pr | 0,9% | — |
| CVE-2019-0984 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context. To exploit the vuln | 0,9% | — |
| CVE-2019-0960 | HIGH 7.0 | microsoft windows_7 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install pr | 0,9% | — |
| CVE-2018-0255 | HIGH 8.8 | cisco ios A vulnerability in the device manager web interface of Cisco Industrial Ethernet Switches could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of an affected system. The vulnerability is due to in | 0,9% | — |
| CVE-2017-3005 | HIGH 7.8 | adobe photoshop_cc Adobe Photoshop versions CC 2017 (18.0.1) and earlier, CC 2015.5.1 (17.0.1) and earlier have an unquoted search path vulnerability. | 0,9% | — |
| CVE-2013-1199 | MED 4.9 | cisco adaptive_security_appliance Race condition in the CIFS implementation in the rewriter module in the Clientless SSL VPN component on Cisco Adaptive Security Appliances (ASA) devices allows remote authenticated users to cause a denial of service (device reload) by accessing resources withi | 0,9% | — |
| CVE-2026-42779 | CRIT 9.8 | apache mina The fix for CVE-2026-41635 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: Apache MINA's AbstractIoBuffer.resolveClass() contains two branches, one of them (for static classes or primitive types) does not ch | 0,9% | — |
| CVE-2025-48824 | HIGH 8.8 | microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | 0,9% | — |
| CVE-2024-33868 | CRIT 9.8 | linqi linqi An issue was discovered in linqi before 1.4.0.1 on Windows. There is LDAP injection. | 0,9% | — |
| CVE-2024-21382 | MED 4.3 | microsoft edge_chromium Microsoft Edge for Android Information Disclosure Vulnerability | 0,9% | — |
| CVE-2023-20010 | HIGH 8.1 | cisco unified_communications_manager A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to conduct SQL injecti | 0,9% | — |
| CVE-2021-26619 | HIGH 7.1 | bigfile bigfileagent An path traversal vulnerability leading to delete arbitrary files was discovered in BigFileAgent. Remote attackers can use this vulnerability to delete arbitrary files of unspecified number of users. | 0,9% | — |
| CVE-2021-32591 | MED 5.3 | fortinet fortiadc A missing cryptographic steps vulnerability in the function that encrypts users' LDAP and RADIUS credentials in FortiSandbox before 4.0.1, FortiWeb before 6.3.12, FortiADC before 6.2.1, FortiMail 7.0.1 and earlier may allow an attacker in possession of the pas | 0,9% | — |
| CVE-2019-1577 | MED 6.3 | paloaltonetworks traps Code injection vulnerability in Palo Alto Networks Traps 5.0.5 and earlier may allow an authenticated attacker to inject arbitrary JavaScript or HTML. | 0,9% | — |
| CVE-2017-4930 | MED 5.4 | vmware airwatch VMware AirWatch Console 9.x prior to 9.2.0 contains a vulnerability that could allow an authenticated AWC user to add a malicious URL to an enrolled device's 'Links' page. Successful exploitation of this issue could result in an unsuspecting AWC user being red | 0,9% | — |