58.046 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.046 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2025-32713 | HIGH 7.8 | microsoft windows_10_1507 Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | 0,7% | — |
| CVE-2024-43456 | MED 4.8 | microsoft windows_server_2008 Windows Remote Desktop Services Tampering Vulnerability | 0,7% | — |
| CVE-2024-20375 | HIGH 8.6 | cisco unified_communications_manager A vulnerability in the SIP call processing function of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to cause a denial of s | 0,7% | — |
| CVE-2019-25160 | CRIT 9.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netlabel: fix out-of-bounds memory accesses There are two array out-of-bounds memory accesses, one in cipso_v4_map_lvl_valid(), the other in netlbl_bitmap_walk(). Both errors are embarassin | 0,7% | — |
| CVE-2023-20055 | HIGH 8.0 | cisco catalyst_center A vulnerability in the management API of Cisco DNA Center could allow an authenticated, remote attacker to elevate privileges in the context of the web-based management interface on an affected device. This vulnerability is due to the unintended exposure of se | 0,7% | — |
| CVE-2021-1467 | MED 4.3 | cisco webex_meetings A vulnerability in Cisco Webex Meetings for Android could allow an authenticated, remote attacker to modify the avatar of another user. This vulnerability is due to improper authorization checks. An attacker could exploit this vulnerability by sending a crafte | 0,7% | — |
| CVE-2017-3873 | HIGH 7.5 | cisco aironet_access_point_firmware A vulnerability in the Plug-and-Play (PnP) subsystem of the Cisco Aironet 1800, 2800, and 3800 Series Access Points running a Lightweight Access Point (AP) or Mobility Express image could allow an unauthenticated, adjacent attacker to execute arbitrary code wi | 0,7% | — |
| CVE-2014-3812 | MED 5.0 | juniper fips_infranet_controller_6500 The Juniper Junos Pulse Secure Access Service (SSL VPN) devices with IVE OS before 7.4r5 and 8.x before 8.0r1 and Junos Pulse Access Control Service (UAC) before 4.4r5 and 5.x before 5.0r1 enable cipher suites with weak encryption algorithms, which make it eas | 0,7% | — |
| CVE-2014-2144 | MED 6.1 | cisco ios_xr Cisco IOS XR does not properly throttle ICMPv6 redirect packets, which allows remote attackers to cause a denial of service (IPv4 and IPv6 transit outage) via crafted redirect messages, aka Bug ID CSCum14266. | 0,7% | — |
| CVE-2005-3807 | MED 4.9 | linux linux_kernel Memory leak in the VFS file lease handling in locks.c in Linux kernels 2.6.10 to 2.6.15 allows local users to cause a denial of service (memory exhaustion) via certain Samba activities that cause an fasync entry to be re-allocated by the fcntl_setlease functio | 0,7% | — |
| CVE-2024-6236 | HIGH 7.5 | citrix netscaler_agent Denial of Service in NetScaler Console (formerly NetScaler ADM), NetScaler Agent, and NetScaler SDX | 0,7% | — |
| CVE-2024-36265 | CRIT 9.8 | apache submarine ** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Submarine Server Core. This issue affects Apache Submarine Server Core: from 0.8.0. An attacker can bypass authentication by sending specially crafted REST requests. As this pro | 0,7% | — |
| CVE-2024-35253 | MED 4.4 | microsoft azure_file_sync Microsoft Azure File Sync Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2021-47131 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/tls: Fix use-after-free after the TLS device goes down and up When a netdev with active TLS offload goes down, tls_device_down is called to stop the offload and tear down the TLS context | 0,7% | — |
| CVE-2023-46712 | HIGH 7.2 | fortinet fortiportal A improper access control in Fortinet FortiPortal version 7.0.0 through 7.0.6, Fortinet FortiPortal version 7.2.0 through 7.2.1 allows attacker to escalate its privilege via specifically crafted HTTP requests. | 0,7% | — |
| CVE-2023-20262 | MED 5.3 | cisco catalyst_sd-wan_manager A vulnerability in the SSH service of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to cause a process crash, resulting in a DoS condition for SSH access only. This vulnerability does not prevent the system from continuing to fu | 0,7% | — |
| CVE-2022-34479 | MED 6.5 | mozilla firefox A malicious website that could create a popup could have resized the popup to overlay the address bar with its own content, resulting in potential user confusion or spoofing attacks. <br>*This bug only affects Thunderbird for Linux. Other operating systems are | 0,7% | — |
| CVE-2022-20949 | MED 6.5 | cisco secure_firewall_threat_defense A vulnerability in the management web server of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker with high privileges to execute configuration commands on an affected system. This vulnerability exists because acces | 0,7% | — |
| CVE-2022-33684 | HIGH 8.1 | apache pulsar The Apache Pulsar C++ Client does not verify peer TLS certificates when making HTTPS calls for the OAuth2.0 Client Credential Flow, even when tlsAllowInsecureConnection is disabled via configuration. This vulnerability allows an attacker to perform a man in th | 0,7% | — |
| CVE-2021-29754 | HIGH 8.8 | ibm websphere_application_server IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a privilege escalation vulnerability when using the SAML Web Inbound Trust Association Interceptor (TAI). IBM X-Force ID: 202006. | 0,7% | — |
| CVE-2019-19692 | MED 6.1 | trendmicro apex_one Trend Micro Apex One (2019) is affected by a cross-site scripting (XSS) vulnerability on the product console. Note that the Japanese version of the product is NOT affected. | 0,7% | — |
| CVE-2019-1797 | HIGH 8.8 | cisco wireless_lan_controller_software A vulnerability in the web-based management interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on the device with the pri | 0,7% | — |
| CVE-2026-57821 | HIGH 8.1 | apache fineract A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in versions up to and including 1.14.0. The orderBy request parameter is concatenated into a SQL query without sufficient validation, allowing an authenticated us | 0,7% | — |
| CVE-2025-62550 | HIGH 8.8 | microsoft azure_monitor_agent Out-of-bounds write in Azure Monitor Agent allows an authorized attacker to execute code over a network. | 0,7% | — |
| CVE-2024-43643 | MED 6.8 | microsoft windows_10_1507 Windows USB Video Class System Driver Elevation of Privilege Vulnerability | 0,7% | — |