EN
57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

57.971 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2024-37358 HIGH 8.6 apache james_server Similarly to CVE-2024-34055, Apache James is vulnerable to denial of service through the abuse of IMAP literals from both authenticated and unauthenticated users, which could be used to cause unbounded memory allocation and very long computations Version 3.7. 0,9%
CVE-2024-31079 MED 4.8 f5 nginx_open_source When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate or cause other potential impact. This attack requires that a request be specifically timed during the connectio 0,9%
CVE-2024-28917 MED 6.2 microsoft azure_arc_extension_microsoft.azstackhci.operator Azure Arc-enabled Kubernetes Extension Cluster-Scope Elevation of Privilege Vulnerability 0,9%
CVE-2024-20338 HIGH 7.3 cisco secure_client A vulnerability in the ISE Posture (System Scan) module of Cisco Secure Client for Linux could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to the use of an uncontrolled search path element. A 0,9%
CVE-2023-34324 MED 4.9 linux linux_kernel Closing of an event channel in the Linux kernel can result in a deadlock. This happens when the close is being performed in parallel to an unrelated Xen console action and the handling of a Xen console interrupt in an unprivileged guest. The closing of an eve 0,9%
CVE-2023-20272 MED 6.7 cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to upload malicious files to the web root of the application. This vulnerability is due to insufficient file input validation. 0,9%
CVE-2021-24106 MED 5.5 microsoft windows_10 Windows DirectX Information Disclosure Vulnerability 0,9%
CVE-2021-24079 MED 5.5 microsoft windows_10 Windows Backup Engine Information Disclosure Vulnerability 0,9%
CVE-2021-24076 MED 5.5 microsoft windows_10 Microsoft Windows VMSwitch Information Disclosure Vulnerability 0,9%
CVE-2017-0430 HIGH 7.8 google android An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compr 0,9%
CVE-2010-4249 MED 4.9 fedoraproject fedora The wait_for_unix_gc function in net/unix/garbage.c in the Linux kernel before 2.6.37-rc3-next-20101125 does not properly select times for garbage collection of inflight sockets, which allows local users to cause a denial of service (system hang) via crafted u 0,9%
CVE-2024-20694 MED 5.5 microsoft windows_10_1607 Windows CoreMessaging Information Disclosure Vulnerability 0,9%
CVE-2022-20917 MED 4.3 cisco jabber A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) message processing feature of Cisco Jabber could allow an authenticated, remote attacker to manipulate the content of XMPP messages that are used by the affected application. This vulne 0,9%
CVE-2023-21564 HIGH 7.1 microsoft azure_devops_server Azure DevOps Server Cross-Site Scripting Vulnerability 0,9%
CVE-2021-43081 MED 6.1 fortinet fortios An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS version 7.0.3 and below, 6.4.8 and below, 6.2.10 and below, 6.0.14 to 6.0.0. and in FortiProxy version 7.0.1 and below, 2.0.7 to 2.0.0 web filter override form may 0,9%
CVE-2021-36081 HIGH 7.8 tesseract-ocr tesseract_ocr Tesseract OCR 5.0.0-alpha-20201231 has a one_ell_conflict use-after-free during a strpbrk call. 0,9%
CVE-2021-25248 MED 5.5 trendmicro apex_one An out-of-bounds read information disclosure vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security (10.0 SP1 and Services) could allow an attacker to disclose sensitive information about a named pipe. Ple 0,9%
CVE-2020-27724 MED 6.5 f5 big-ip_access_policy_manager In BIG-IP APM versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, on systems running more than one TMM instance, authenticated VPN users may consume excessive resources by sending sp 0,9%
CVE-2020-1676 HIGH 7.2 juniper mist_cloud_ui When SAML authentication is enabled, Juniper Networks Mist Cloud UI might incorrectly handle SAML responses, allowing a remote attacker to modify a valid SAML response without invalidating its cryptographic signature to bypass SAML authentication security cont 0,9%
CVE-2008-1113 HIGH 7.8 vocera_communications vocera_communications_badge Cisco Unified Wireless IP Phone 7921, when using Protected Extensible Authentication Protocol (PEAP), does not validate server certificates, which allows remote wireless access points to steal hashed passwords and conduct man-in-the-middle (MITM) attacks. 0,9%
CVE-2006-1095 HIGH 7.2 apache mod_python Directory traversal vulnerability in the FileSession object in Mod_python module 3.2.7 for Apache allows local users to execute arbitrary code via a crafted session cookie. 0,9%
CVE-2026-65681 HIGH 7.5 microsoft windows_10_1607 Null pointer dereference in Windows iSCSI Target Service allows an unauthorized attacker to deny service over a network. 0,9%
CVE-2026-40859 HIGH 8.1 apache camel Deserialization of Untrusted Data vulnerability in Apache Camel. The camel-vertx-http component deserializes HTTP response bodies carrying the Content-Type application/x-java-serialized-object using a raw java.io.ObjectInputStream, without applying any Object 0,9%
CVE-2026-42780 MED 4.9 f5 big-ip_ssl_orchestrator A directory traversal vulnerability exists in BIG-IP SSL Orchestrator that allows an authenticated attacker with high privilege to overwrite, delete or corrupt arbitrary local files.  Note: Software versions which have reached End of Technical Support (EoTS) a 0,9%
CVE-2026-24464 MED 6.8 f5 big-ip_access_policy_manager When running in Appliance mode, a directory traversal vulnerability exists in an undisclosed iControl REST endpoint that may allow an authenticated attacker with administrator role privileges to cross a security boundary and delete files.  Note: Software versi 0,9%