58.015 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.015 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2016-1439 | MED 6.1 | cisco unified_contact_center_enterprise Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unified Contact Center Enterprise through 10.5(2) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCux59650. | 0,8% | — |
| CVE-2016-1355 | MED 6.1 | cisco firesight_system_software Cross-site scripting (XSS) vulnerability in the Device Management UI in the management interface in Cisco FireSIGHT System Software 6.1.0 allows remote attackers to inject arbitrary web script or HTML via a crafted value, aka Bug ID CSCuy41687. | 0,8% | — |
| CVE-2026-24217 | HIGH 8.8 | nvidia bionemo_framework NVIDIA BioNeMo Core for Linux contains a vulnerability where a user could cause a path traversal by loading a malicious file. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering | 0,8% | — |
| CVE-2026-24017 | HIGH 8.1 | fortinet fortiweb An Improper Control of Interaction Frequency vulnerability [CWE-799] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow a r | 0,8% | — |
| CVE-2025-59244 | MED 6.5 | microsoft windows_10_1507 External control of file name or path in Windows Core Shell allows an unauthorized attacker to perform spoofing over a network. | 0,8% | — |
| CVE-2025-58739 | MED 6.5 | microsoft windows_10_1507 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network. | 0,8% | — |
| CVE-2025-53762 | HIGH 8.7 | microsoft purview Permissive list of allowed inputs in Microsoft Purview allows an authorized attacker to elevate privileges over a network. | 0,8% | — |
| CVE-2025-20176 | HIGH 7.7 | cisco ios A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper error handling when parsing SNMP reques | 0,8% | — |
| CVE-2025-20175 | HIGH 7.7 | cisco ios A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper error handling when parsing SNMP reques | 0,8% | — |
| CVE-2025-20174 | HIGH 7.7 | cisco ios A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper error handling when parsing SNMP reques | 0,8% | — |
| CVE-2025-20173 | HIGH 7.7 | cisco ios A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper error handling when parsing SNMP reques | 0,8% | — |
| CVE-2025-20172 | HIGH 7.7 | cisco ios A vulnerability in the SNMP subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper error handling | 0,8% | — |
| CVE-2024-52963 | LOW 3.7 | fortinet fortios A out-of-bounds write in Fortinet FortiOS versions 7.6.0, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, 6.4.0 through 6.4.15 allows attacker to trigger a denial of service via specially crafted packets. | 0,8% | — |
| CVE-2024-39747 | HIGH 8.1 | ibm sterling_connect_direct_web_services IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 uses default credentials for potentially critical functionality. | 0,8% | — |
| CVE-2024-5491 | HIGH 7.5 | citrix netscaler_application_delivery_controller Denial of Service in NetScaler ADC and NetScaler Gateway in NetScaler | 0,8% | — |
| CVE-2024-30357 | HIGH 7.8 | foxit pdf_editor Foxit PDF Reader AcroForm Annotation Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerabil | 0,8% | — |
| CVE-2024-30355 | HIGH 7.8 | foxit pdf_editor Foxit PDF Reader AcroForm Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in | 0,8% | — |
| CVE-2024-30353 | HIGH 7.8 | foxit pdf_editor Foxit PDF Reader AcroForm Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in | 0,8% | — |
| CVE-2024-30348 | HIGH 7.8 | foxit pdf_editor Foxit PDF Reader U3D File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerab | 0,8% | — |
| CVE-2023-21822 | HIGH 7.8 | microsoft windows_10 Windows Graphics Component Elevation of Privilege Vulnerability | 0,8% | — |
| CVE-2022-41098 | MED 5.5 | microsoft windows_10 Windows GDI+ Information Disclosure Vulnerability | 0,8% | — |
| CVE-2014-3181 | MED 6.9 | linux linux_kernel Multiple stack-based buffer overflows in the magicmouse_raw_event function in drivers/hid/hid-magicmouse.c in the Magic Mouse HID driver in the Linux kernel through 3.16.3 allow physically proximate attackers to cause a denial of service (system crash) or poss | 0,8% | — |
| CVE-2014-2180 | MED 4.0 | cisco unified_contact_center_enterprise The Document Management component in Cisco Unified Contact Center Express does not properly validate a parameter, which allows remote authenticated users to upload files to arbitrary pathnames via a crafted HTTP request, aka Bug ID CSCun74133. | 0,8% | — |
| CVE-2026-42403 | HIGH 7.5 | apache neethi Apache Neethi does not properly detect circular references in policy definitions. When a WS-Policy document contains circular policy references (where Policy A references Policy B which references Policy A), the policy normalization process can enter an infini | 0,8% | — |
| CVE-2026-3843 | CRIT 9.8 | bukts buk_ts-g_gas_station_automation_system Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 on Linux contains a SQL Injection vulnerability (CWE-89) in the system configuration module. A remote attacker can send specially crafted HTTP POST requests to the /php/request.php endpoint via | 0,8% | — |