57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.971 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2018-0482 | MED 5.4 | cisco prime_infrastructure A vulnerability in the web-based management interface of Cisco Prime Network Control System could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web interface of the affected system. The vuln | 0,9% | — |
| CVE-2018-14608 | HIGH 7.5 | thomsonreuters ultratax_cs Thomson Reuters UltraTax CS 2017 on Windows has a password protection option; however, the level of protection might be inconsistent with some customers' expectations because the data is directly accessible in cleartext. Specifically, it stores customer data i | 0,9% | — |
| CVE-2017-8420 | MED 6.5 | swftools swftools SWFTools 2013-04-09-1007 on Windows has a "Data from Faulting Address controls Branch Selection starting at image00000000_00400000+0x0000000000003e71" issue. This issue can be triggered by a malformed TTF file that is mishandled by font2swf. Attackers could ex | 0,9% | — |
| CVE-2017-0634 | MED 4.7 | linux linux_kernel An information disclosure vulnerability in the Synaptics touchscreen driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. | 0,9% | — |
| CVE-2017-0633 | MED 4.7 | linux linux_kernel An information disclosure vulnerability in the Broadcom Wi-Fi driver could enable a local malicious component to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: | 0,9% | — |
| CVE-2017-0632 | MED 4.7 | linux linux_kernel An information disclosure vulnerability in the Qualcomm sound codec driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. | 0,9% | — |
| CVE-2017-0631 | MED 4.7 | linux linux_kernel An information disclosure vulnerability in the Qualcomm camera driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Produ | 0,9% | — |
| CVE-2017-0629 | MED 4.7 | linux linux_kernel An information disclosure vulnerability in the Qualcomm camera driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Produ | 0,9% | — |
| CVE-2017-0628 | MED 4.7 | linux linux_kernel An information disclosure vulnerability in the Qualcomm camera driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Produ | 0,9% | — |
| CVE-2013-6942 | MED 6.8 | citrix netscaler_application_delivery_controller_firmware Cross-site request forgery (CSRF) vulnerability in Citrix NetScaler Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 allows remote attackers to hijack the authentication of unspecified victims via u | 0,9% | — |
| CVE-2005-2695 | MED 5.0 | cisco ciscoworks_management_center_for_ids_sensors Unspecified vulnerability in the SSL certificate checking functionality in Cisco CiscoWorks Management Center for IDS Sensors (IDSMC) 2.0 and 2.1, and Monitoring Center for Security (Security Monitor or Secmon) 1.1 through 2.0 and 2.1, allows remote attackers | 0,9% | — |
| CVE-2023-35624 | HIGH 7.3 | microsoft azure_connected_machine_agent Azure Connected Machine Agent Elevation of Privilege Vulnerability | 0,9% | — |
| CVE-2022-38012 | HIGH 7.7 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 0,9% | — |
| CVE-2022-27182 | MED 5.3 | f5 big-ip_access_policy_manager On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, and 14.1.x versions prior to 14.1.4.6, when BIG-IP packet filters are enabled and a virtual server is configured with the type set to Reject, undisclosed requests can cause an i | 0,9% | — |
| CVE-2021-23029 | HIGH 8.8 | f5 big-ip_advanced_web_application_firewall On version 16.0.x before 16.0.1.2, insufficient permission checks may allow authenticated users with guest privileges to perform Server-Side Request Forgery (SSRF) attacks through F5 Advanced Web Application Firewall (WAF) and the BIG-IP ASM Configuration util | 0,9% | — |
| CVE-2020-3547 | MED 4.3 | cisco asyncos A vulnerability in the web-based management interface of Cisco AsyncOS software for Cisco Email Security Appliance (ESA), Cisco Content Security Management Appliance (SMA), and Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to | 0,9% | — |
| CVE-2015-6434 | MED 6.1 | cisco prime_infrastructure Cisco Prime Infrastructure does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "cross-frame scripting (XFS)" issue, aka | 0,9% | — |
| CVE-2026-70342 | HIGH 8.1 | microsoft windows_10_1607 Use after free in Windows Ancillary Function Driver for WinSock allows an unauthorized attacker to elevate privileges over a network. | 0,9% | — |
| CVE-2026-47282 | MED 6.5 | microsoft visual_studio_code Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network. | 0,9% | — |
| CVE-2026-57987 | MED 6.5 | microsoft edge_chromium Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | 0,9% | — |
| CVE-2026-21532 | HIGH 8.2 | microsoft azure_functions Azure Function Information Disclosure Vulnerability | 0,9% | — |
| CVE-2022-49058 | CRIT 9.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: cifs: potential buffer overflow in handling symlinks Smatch printed a warning: arch/x86/crypto/poly1305_glue.c:198 poly1305_update_arch() error: __memcpy() 'dctx->buf' too small (16 vs u32 | 0,9% | — |
| CVE-2024-38245 | HIGH 7.8 | microsoft windows_10_1507 Kernel Streaming Service Driver Elevation of Privilege Vulnerability | 0,9% | — |
| CVE-2024-29006 | CRIT 9.8 | apache cloudstack By default the CloudStack management server honours the x-forwarded-for HTTP header and logs it as the source IP of an API request. This could lead to authentication bypass and other operational problems should an attacker decide to spoof their IP address this | 0,9% | — |
| CVE-2022-0803 | MED 6.5 | google chrome Inappropriate implementation in Permissions in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to tamper with the contents of the Omnibox (URL bar) via a crafted HTML page. | 0,9% | — |