58.089 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.089 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2024-20331 | MED 6.8 | cisco adaptive_security_appliance_software A vulnerability in the session authentication functionality of the Remote Access SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to prevent us | 0,7% | — |
| CVE-2024-20686 | HIGH 7.8 | microsoft windows_server_2022_23h2 Win32k Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2023-35343 | HIGH 7.8 | microsoft windows_10_1809 Windows Geolocation Service Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2023-28226 | MED 5.3 | microsoft windows_10_1507 Windows Enroll Engine Security Feature Bypass Vulnerability | 0,7% | — |
| CVE-2022-42439 | MED 6.8 | ibm app_connect_enterprise IBM App Connect Enterprise 11.0.0.17 through 11.0.0.19 and 12.0.4.0 and 12.0.5.0 contains an unspecified vulnerability in the Discovery Connector nodes which may cause a 3rd party system’s credentials to be exposed to a privileged attacker. IBM X-Force ID: 23 | 0,7% | — |
| CVE-2022-21973 | MED 5.5 | microsoft windows_7 Windows Media Center Update Denial of Service Vulnerability | 0,7% | — |
| CVE-2020-5018 | HIGH 7.5 | ibm spectrum_protect_plus IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may include sensitive information in its URLs increasing the risk of such information being caputured by an attacker. IBM X-Force ID: 193654. | 0,7% | — |
| CVE-2019-16002 | MED 6.5 | cisco sd-wan_firmware A vulnerability in the vManage web-based UI (web UI) of the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protect | 0,7% | — |
| CVE-2019-1915 | MED 6.5 | cisco unified_communications_manager A vulnerability in the web-based interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition (SME), Cisco Unified Communications Manager IM and Presence (Unified CM IM&P) Service, and Cisco Unity Conne | 0,7% | — |
| CVE-2016-9218 | HIGH 8.8 | cisco hybrid_meeting_server A vulnerability in Cisco Hybrid Meeting Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against the user of the web interface. More Information: CSCvc28662. Known Affected Releases: 1.0. | 0,7% | — |
| CVE-2009-2073 | MED 6.8 | cisco wrt160n Cross-site request forgery (CSRF) vulnerability in Linksys WRT160N wireless router hardware 1 and firmware 1.02.2 allows remote attackers to hijack the authentication of other users for unspecified requests via unknown vectors, as demonstrated using administra | 0,7% | — |
| CVE-2026-70091 | MED 5.9 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to deny service over a network. | 0,7% | — |
| CVE-2026-59837 | MED 6.6 | fortinet fortios A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2 all versions, FortiPAM 1.8.0 through 1.8.2, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1. | 0,7% | — |
| CVE-2025-58693 | MED 6.5 | fortinet fortivoice An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7 allows a privileged attacker to delete files from the underlying filesystem via crafted H | 0,7% | — |
| CVE-2022-49094 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/tls: fix slab-out-of-bounds bug in decrypt_internal The memory size of tls_ctx->rx.iv for AES128-CCM is 12 setting in tls_set_sw_offload(). The return value of crypto_aead_ivsize() for " | 0,7% | — |
| CVE-2024-50286 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slab-use-after-free in ksmbd_smb2_session_create There is a race condition between ksmbd_smb2_session_create and ksmbd_expire_session. This patch add missing sessions_table_lock w | 0,7% | — |
| CVE-2024-9467 | MED 6.1 | paloaltonetworks expedition A reflected XSS vulnerability in Palo Alto Networks Expedition enables execution of malicious JavaScript in the context of an authenticated Expedition user's browser if that user clicks on a malicious link, allowing phishing attacks that could lead to Expediti | 0,7% | — |
| CVE-2023-52887 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: can: j1939: enhanced error handling for tightly received RTS messages in xtp_rx_rts_session_new This patch enhances error handling in scenarios with RTS (Request to Send) messages arriv | 0,7% | — |
| CVE-2021-47179 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: NFSv4: Fix a NULL pointer dereference in pnfs_mark_matching_lsegs_return() Commit de144ff4234f changes _pnfs_return_layout() to call pnfs_mark_matching_lsegs_return() passing NULL as the str | 0,7% | — |
| CVE-2023-22290 | MED 6.5 | intel unison_software Uncaught exception for some Intel Unison software may allow an authenticated user to potentially enable denial of service via network access. | 0,7% | — |
| CVE-2022-22167 | HIGH 7.2 | juniper junos A traffic classification vulnerability in Juniper Networks Junos OS on the SRX Series Services Gateways may allow an attacker to bypass Juniper Deep Packet Inspection (JDPI) rules and access unauthorized networks or resources, when 'no-syn-check' is enabled on | 0,7% | — |
| CVE-2021-1566 | HIGH 7.4 | cisco asyncos A vulnerability in the Cisco Advanced Malware Protection (AMP) for Endpoints integration of Cisco AsyncOS for Cisco Email Security Appliance (ESA) and Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to intercept traffic betwe | 0,7% | — |
| CVE-2020-3997 | MED 5.4 | vmware horizon VMware Horizon Server (7.x prior to 7.10.3 or 7.13.0) contains a Cross Site Scripting (XSS) vulnerability. Successful exploitation of this issue may allow an attacker to inject malicious script which will be executed. | 0,7% | — |
| CVE-2018-10840 | MED 6.6 | canonical ubuntu_linux Linux kernel is vulnerable to a heap-based buffer overflow in the fs/ext4/xattr.c:ext4_xattr_set_entry() function. An attacker could exploit this by operating on a mounted crafted ext4 image. | 0,7% | — |
| CVE-2018-7755 | MED 5.5 | canonical ubuntu_linux An issue was discovered in the fd_locked_ioctl function in drivers/block/floppy.c in the Linux kernel through 4.15.7. The floppy driver will copy a kernel pointer to user memory in response to the FDGETPRM ioctl. An attacker can send the FDGETPRM ioctl and use | 0,7% | — |