EN
57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

57.971 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2024-26193 MED 6.4 microsoft azure_migrate Azure Migrate Remote Code Execution Vulnerability 0,9%
CVE-2023-2984 HIGH 8.8 pimcore pimcore Path Traversal: '\..\filename' in GitHub repository pimcore/pimcore prior to 10.5.22. 0,9%
CVE-2023-23459 CRIT 9.1 priority-software priority Priority Windows may allow Command Execution via SQL Injection using an unspecified method. 0,9%
CVE-2022-20920 HIGH 7.7 cisco ios A vulnerability in the SSH implementation of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload. This vulnerability is due to improper handling of resources during an exceptional sit 0,9%
CVE-2019-1802 MED 4.8 cisco secure_firewall_management_center A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected sy 0,9%
CVE-2026-70328 MED 6.5 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. 0,9%
CVE-2026-70327 MED 6.5 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. 0,9%
CVE-2024-56202 MED 4.3 apache traffic_server Expected Behavior Violation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.8, from 10.0.0 through 10.0.3. Users are recommended to upgrade to versions 9.2.9 or 10.0.4 or newer, which fixes the issue. 0,9%
CVE-2023-31036 HIGH 7.5 nvidia triton_inference_server NVIDIA Triton Inference Server for Linux and Windows contains a vulnerability where, when it is launched with the non-default command line option --model-control explicit, an attacker may use the model load API to cause a relative path traversal. A successful 0,9%
CVE-2021-44172 MED 4.3 fortinet forticlient_endpoint_management_server An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClientEMS versions 7.0.0 through 7.0.4, 7.0.6 through 7.0.7, in all 6.4 and 6.2 version management interface may allow an unauthenticated attacker to gain information 0,9%
CVE-2023-28308 MED 6.6 microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability 0,9%
CVE-2023-28307 MED 6.6 microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability 0,9%
CVE-2023-28306 MED 6.6 microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability 0,9%
CVE-2023-28305 MED 6.6 microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability 0,9%
CVE-2023-28278 MED 6.6 microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability 0,9%
CVE-2022-23767 HIGH 8.8 hanssak securegate This vulnerability of SecureGate is SQL-Injection using login without password. A path traversal vulnerability is also identified during file transfer. An attacker can take advantage of these vulnerabilities to perform various attacks such as obtaining privile 0,9%
CVE-2022-35831 MED 5.5 microsoft windows_10 Windows Remote Access Connection Manager Information Disclosure Vulnerability 0,9%
CVE-2021-20292 MED 6.7 debian debian_linux There is a flaw reported in the Linux kernel in versions before 5.9 in drivers/gpu/drm/nouveau/nouveau_sgdma.c in nouveau_sgdma_create_ttm in Nouveau DRM subsystem. The issue results from the lack of validating the existence of an object prior to performing op 0,9%
CVE-2021-0268 HIGH 8.8 juniper junos An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') weakness in J-web of Juniper Networks Junos OS leads to buffer overflows, segment faults, or other impacts, which allows an attacker to modify the integrity of the device 0,9%
CVE-2020-1402 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows ActiveX Installer Service improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows ActiveX Installer Service Eleva 0,9%
CVE-2020-0799 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in Microsoft Windows when the Windows kernel fails to properly handle parsing of certain symbolic links, aka 'Windows Kernel Elevation of Privilege Vulnerability'. 0,9%
CVE-2019-0931 HIGH 7.0 microsoft windows_10 An elevation of privilege vulnerability exists when the Storage Service improperly handles file operations, aka 'Windows Storage Service Elevation of Privilege Vulnerability'. 0,9%
CVE-2016-8961 MED 6.1 ibm bigfix_inventory IBM BigFix Inventory v9 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to red 0,9%
CVE-2016-6418 MED 6.1 cisco videoscape_distribution_suite_service_manager Cross-site scripting (XSS) vulnerability in Cisco Videoscape Distribution Suite Service Manager (VDS-SM) 3.0 through 3.4.0 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCva14552. 0,9%
CVE-2026-71336 HIGH 8.8 microsoft windows_10_1607 Integer overflow or wraparound in Windows Work Folder Service allows an authorized attacker to execute code over a network. 0,9%