58.127 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.127 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2023-28982 | HIGH 7.5 | juniper junos A Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network based attacker to cause a Denial of Service (DoS). In a BGP rib sharding scen | 0,6% | — |
| CVE-2023-28964 | HIGH 7.5 | juniper junos An Improper Handling of Length Parameter Inconsistency vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a network based, unauthenticated attacker to cause an RPD crash leading to a Denial of Service (D | 0,6% | — |
| CVE-2022-41096 | HIGH 7.8 | microsoft windows_10 Microsoft DWM Core Library Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2022-38032 | MED 6.6 | microsoft windows_10 Windows Portable Device Enumerator Service Security Feature Bypass Vulnerability | 0,6% | — |
| CVE-2020-3590 | MED 6.4 | cisco catalyst_sd-wan_manager A vulnerability in the web-based management interface of the Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user. The vulnerability exists because the web-based management in | 0,6% | — |
| CVE-2020-3587 | MED 6.4 | cisco catalyst_sd-wan_manager A vulnerability in the web-based management interface of the Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user. The vulnerability exists because the web-based management in | 0,6% | — |
| CVE-2019-6663 | MED 5.5 | f5 big-ip_access_policy_manager The BIG-IP 15.0.0-15.0.1, 14.0.0-14.1.2.2, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.1-11.6.5.1, BIG-IQ 7.0.0, 6.0.0-6.1.0, and 5.2.0-5.4.0, iWorkflow 2.3.0, and Enterprise Manager 3.1.1 configuration utility is vulnerable to Anti DNS Pinning (DNS Rebinding) at | 0,6% | — |
| CVE-2014-3321 | MED 5.7 | cisco asr_9000_rsp440_router Cisco IOS XR 4.3.4 and earlier on ASR 9000 devices, when bridge-group virtual interface (BVI) routing is enabled, allows remote attackers to cause a denial of service (chip and card hangs) via a series of crafted MPLS packets, aka Bug ID CSCuo91149. | 0,6% | — |
| CVE-2014-3145 | MED 4.9 | canonical ubuntu_linux The BPF_S_ANC_NLATTR_NEST extension implementation in the sk_run_filter function in net/core/filter.c in the Linux kernel through 3.14.3 uses the reverse order in a certain subtraction, which allows local users to cause a denial of service (over-read and syste | 0,6% | — |
| CVE-2014-2115 | MED 6.8 | cisco emergency_responder Multiple cross-site request forgery (CSRF) vulnerabilities in CERUserServlet pages in Cisco Emergency Responder (ER) 8.6 and earlier allow remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCun24250. | 0,6% | — |
| CVE-2014-1446 | LOW 1.9 | linux linux_kernel The yam_ioctl function in drivers/net/hamradio/yam.c in the Linux kernel before 3.12.8 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability for an | 0,6% | — |
| CVE-2026-72987 | HIGH 8.1 | microsoft windows_10_1607 Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. | 0,6% | — |
| CVE-2026-57983 | HIGH 8.7 | microsoft edge_chromium Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network. | 0,6% | — |
| CVE-2025-53378 | HIGH 7.6 | trendmicro worry-free_business_security_services A missing authentication vulnerability in Trend Micro Worry-Free Business Security Services (WFBSS) agent could have allowed an unauthenticated attacker to remotely take control of the agent on affected installations. Also note: this vulnerability only affe | 0,6% | — |
| CVE-2025-26521 | HIGH 8.1 | apache cloudstack When an Apache CloudStack user-account creates a CKS-based Kubernetes cluster in a project, the API key and the secret key of the 'kubeadmin' user of the caller account are used to create the secret config in the CKS-based Kubernetes cluster. A member of the p | 0,6% | — |
| CVE-2025-32720 | MED 5.5 | microsoft windows_10_1507 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | 0,6% | — |
| CVE-2025-21375 | HIGH 7.8 | microsoft windows_10_1507 Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2025-21367 | HIGH 7.8 | microsoft windows_10_1809 Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2022-48743 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: amd-xgbe: Fix skb data length underflow There will be BUG_ON() triggered in include/linux/skbuff.h leading to intermittent kernel panic, when the skb length underflow is detected. Fix | 0,6% | — |
| CVE-2024-38618 | MED 5.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ALSA: timer: Set lower bound of start tick time Currently ALSA timer doesn't have the lower limit of the start tick time, and it allows a very small size, e.g. 1 tick with 1ns resolution for | 0,6% | — |
| CVE-2024-20405 | MED 4.8 | cisco finesse A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct a stored XSS attack by exploiting an RFI vulnerability. This vulnerability is due to insufficient validation of user-supplied | 0,6% | — |
| CVE-2023-20862 | MED 6.3 | netapp active_iq_unified_manager In Spring Security, versions 5.7.x prior to 5.7.8, versions 5.8.x prior to 5.8.3, and versions 6.0.x prior to 6.0.3, the logout support does not properly clean the security context if using serialized versions. Additionally, it is not possible to explicitly sa | 0,6% | — |
| CVE-2023-23391 | MED 5.5 | microsoft 365_copilot Office for Android Spoofing Vulnerability | 0,6% | — |
| CVE-2021-31185 | MED 5.5 | microsoft windows_10 Windows Desktop Bridge Denial of Service Vulnerability | 0,6% | — |
| CVE-2021-28443 | MED 5.5 | microsoft windows_10 Windows Console Driver Denial of Service Vulnerability | 0,6% | — |