57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.971 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2020-4688 | HIGH 7.8 | ibm security_guardium IBM Security Guardium 10.6 and 11.2 could allow a local attacker to execute arbitrary commands on the system as an unprivileged user, caused by command injection vulnerability. IBM X-Force ID: 186700. | 0,9% | — |
| CVE-2020-16941 | MED 4.1 | microsoft sharepoint_enterprise_server <p>An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web pages. An attacker who took advantage of this information disclosure could view the folder path of scripts | 0,9% | — |
| CVE-2020-0730 | HIGH 7.1 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks, aka 'Windows User Profile Service Elevation of Privilege Vulnerability'. | 0,9% | — |
| CVE-2016-4066 | HIGH 8.8 | fortinet fortiweb Cross-site request forgery (CSRF) vulnerability in Fortinet FortiWeb before 5.5.3 allows remote attackers to hijack the authentication of administrators for requests that change the password via unspecified vectors. | 0,9% | — |
| CVE-2003-1579 | MED 4.3 | sun one_web_server Sun ONE (aka iPlanet) Web Server 6 on Windows, when DNS resolution is enabled for client IP addresses, uses a logging format that does not identify whether a dotted quad represents an unresolved IP address, which allows remote attackers to spoof IP addresses v | 0,9% | — |
| CVE-2025-29817 | MED 5.7 | microsoft power_automate_for_desktop Uncontrolled search path element in Power Automate allows an authorized attacker to disclose information over a network. | 0,9% | — |
| CVE-2024-38172 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 0,9% | — |
| CVE-2023-20103 | MED 4.9 | cisco secure_network_analytics A vulnerability in Cisco Secure Network Analytics could allow an authenticated, remote attacker to execute arbitrary code as a root user on an affected device. This vulnerability is due to insufficient validation of user input to the web interface. An attacker | 0,9% | — |
| CVE-2023-28508 | HIGH 8.8 | rocketsoftware unidata Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a heap-based overflow vulnerability, where certain input can corrupt the heap and crash the forked process. | 0,9% | — |
| CVE-2022-30144 | HIGH 7.5 | microsoft windows_10 Windows Bluetooth Service Remote Code Execution Vulnerability | 0,9% | — |
| CVE-2021-26425 | HIGH 7.8 | microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability | 0,9% | — |
| CVE-2020-4840 | MED 6.1 | ibm security_secret_server IBM Security Secret Server 10.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displaye | 0,9% | — |
| CVE-2019-15278 | MED 6.1 | cisco finesse A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to bypass authorization and access sensitive information related to the device. The vulnerability exists because the software fails to saniti | 0,9% | — |
| CVE-2019-5542 | HIGH 7.7 | vmware fusion VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain a denial-of-service vulnerability in the RPC handler. Successful exploitation of this issue may allow attackers with normal user privileges to create a denial-of-service condition | 0,9% | — |
| CVE-2019-19063 | MED 4.6 | broadcom brocade_fabric_operating_system_firmware Two memory leaks in the rtl_usb_probe() function in drivers/net/wireless/realtek/rtlwifi/usb.c in the Linux kernel through 5.3.11 allow attackers to cause a denial of service (memory consumption), aka CID-3f9361695113. | 0,9% | — |
| CVE-2019-12699 | HIGH 7.8 | cisco firepower_9300_firmware Multiple vulnerabilities in the CLI of Cisco FXOS Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute commands on the underlying operating system (OS) with root privileges. These vulnerabilities ar | 0,9% | — |
| CVE-2019-1270 | MED 5.5 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows store installer where WindowsApps directory is vulnerable to symbolic link attack, aka 'Microsoft Windows Store Installer Elevation of Privilege Vulnerability'. | 0,9% | — |
| CVE-2013-1292 | HIGH 7.4 | microsoft windows_7 Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted applicat | 0,9% | — |
| CVE-2026-41607 | MED 6.5 | apache thrift Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. | 0,9% | — |
| CVE-2026-39304 | HIGH 7.5 | apache activemq Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ. ActiveMQ NIO SSL transports do not correctly handle TLSv1.3 handshake KeyUpdates triggered by clients. This makes it possible for a client to | 0,9% | — |
| CVE-2022-20870 | HIGH 8.6 | cisco ios_xe A vulnerability in the egress MPLS packet processing function of Cisco IOS XE Software for Cisco Catalyst 3650, Catalyst 3850, and Catalyst 9000 Family Switches could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, | 0,9% | — |
| CVE-2020-3155 | HIGH 7.4 | cisco intelligence_proximity A vulnerability in the SSL implementation of the Cisco Intelligent Proximity solution could allow an unauthenticated, remote attacker to view or alter information shared on Cisco Webex video devices and Cisco collaboration endpoints if the products meet the co | 0,9% | — |
| CVE-2019-1161 | HIGH 7.1 | microsoft forefront_endpoint_protection_2010 An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations. To exploit the vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted c | 0,9% | — |
| CVE-2018-15321 | MED 4.9 | f5 big-ip_access_policy_manager When BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.0.5, 12.1.0-12.1.3.5, 11.6.0-11.6.3.2, or 11.2.1-11.5.6, BIG-IQ Centralized Management 5.0.0-5.4.0 or 4.6.0, BIG-IQ Cloud and Orchestration 1.0.0, iWorkflow 2.1.0-2.3.0, or Enterprise Manager 3.1.1 is licensed for Appli | 0,9% | — |
| CVE-2009-0743 | LOW 3.5 | cisco unified_meetingplace Cross-site scripting (XSS) vulnerability in the edit account page in the Web Server in Cisco Unified MeetingPlace Web Conferencing 6.0 before 6.0(517.0) (aka 6.0 MR4) and 7.0 before 7.0(2) (aka 7.0 MR1) allows remote authenticated users to inject arbitrary web | 0,9% | — |