58.458 CVE seguite
793 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.458 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2024-20477 | MED 5.4 | cisco nexus_dashboard A vulnerability in a specific REST API endpoint of Cisco NDFC could allow an authenticated, low-privileged, remote attacker to upload or delete files on an affected device. This vulnerability exists because of missing authorization controls on the affected | 0,5% | — |
| CVE-2024-38103 | MED 5.9 | microsoft edge Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | 0,5% | — |
| CVE-2022-43889 | MED 5.3 | ibm security_verify_privilege_on-premises IBM Security Verify Privilege On-Premises 11.5 could disclose sensitive information through an HTTP request that could aid an attacker in further attacks against the system. IBM X-Force ID: 240452. | 0,5% | — |
| CVE-2023-20218 | MED 5.8 | cisco spa500ds_firmware A vulnerability in web-based management interface of Cisco SPA500 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to to modify a web page in the context of a user's browser. This vulnerability is due to insufficient val | 0,5% | — |
| CVE-2023-28228 | MED 5.5 | microsoft windows_10_1507 Windows Spoofing Vulnerability | 0,5% | — |
| CVE-2022-28878 | MED 4.3 | f-secure atlant A Denial-of-Service vulnerability was discovered in the F-Secure Atlant and in certain WithSecure products while scanning fuzzed APK file it is possible that can crash the scanning engine. | 0,5% | — |
| CVE-2021-26610 | HIGH 7.2 | nhn-commerce godomall5 The move_uploaded_file function in godomall5 does not perform an integrity check of extension or authority when user upload file. This vulnerability allows an attacker to execute an remote arbitrary code. | 0,5% | — |
| CVE-2021-21989 | MED 6.5 | vmware horizon_client VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read vulnerability in the Cortado ThinPrint component (TTC Parser). A malicious actor with access to a virtual machine or remote desktop may be | 0,5% | — |
| CVE-2021-21988 | MED 6.5 | vmware horizon_client VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read vulnerability in the Cortado ThinPrint component (JPEG2000 Parser). A malicious actor with access to a virtual machine or remote desktop ma | 0,5% | — |
| CVE-2020-5858 | HIGH 7.8 | f5 big-ip_access_policy_manager On BIG-IP 15.0.0-15.0.1.2, 14.1.0-14.1.2.2, 13.1.0-13.1.3.2, 12.1.0-12.1.5, and 11.5.2-11.6.5.1 and BIG-IQ 7.0.0, 6.0.0-6.1.0, and 5.2.0-5.4.0, users with non-administrator roles (for example, Guest or Resource Administrator) with tmsh shell access can execute | 0,5% | — |
| CVE-2018-5546 | HIGH 7.8 | f5 big-ip_access_policy_manager The svpn and policyserver components of the F5 BIG-IP APM client prior to version 7.1.7.1 for Linux and macOS runs as a privileged process and can allow an unprivileged user to get ownership of files owned by root on the local client host. A malicious local un | 0,5% | — |
| CVE-2018-0224 | MED 6.7 | cisco staros A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers could allow an authenticated, local attacker to execute arbitrary commands with root privileges on an affected operating system. The vulnerab | 0,5% | — |
| CVE-2017-9497 | MED 6.8 | cisco mx011anm_firmware The Comcast firmware on Motorola MX011ANM (firmware version MX011AN_2.9p6s1_PROD_sey) devices allows physically proximate attackers to execute arbitrary commands as root by pulling up the diagnostics menu on the set-top box, and then posting to a Web Inspector | 0,5% | — |
| CVE-2011-4097 | MED 5.5 | linux linux_kernel Integer overflow in the oom_badness function in mm/oom_kill.c in the Linux kernel before 3.1.8 on 64-bit platforms allows local users to cause a denial of service (memory consumption or process termination) by using a certain large amount of memory. | 0,5% | — |
| CVE-2009-1262 | HIGH 7.2 | fortinet forticlient Format string vulnerability in Fortinet FortiClient 3.0.614, and possibly earlier, allows local users to execute arbitrary code via format string specifiers in the VPN connection name. | 0,5% | — |
| CVE-2026-80097 | HIGH 8.6 | microsoft authenticator Improper authentication in Microsoft Authenticator allows an unauthorized attacker to elevate privileges locally. | 0,5% | — |
| CVE-2026-65613 | MED 4.3 | apache cloudstack Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's Webhook module while listing and deleting deliveries. This issue affects Apache CloudStack: from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Use | 0,5% | — |
| CVE-2026-14973 | CRIT 9.3 | ibm aspera IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination. | 0,5% | — |
| CVE-2025-64679 | HIGH 7.8 | microsoft windows_10_1507 Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | 0,5% | — |
| CVE-2025-27478 | HIGH 7.0 | microsoft windows_10_1507 Heap-based buffer overflow in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally. | 0,5% | — |
| CVE-2025-21091 | HIGH 7.5 | f5 big-ip_access_policy_manager When SNMP v1 or v2c are disabled on the BIG-IP, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | 0,5% | — |
| CVE-2024-57932 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: gve: guard XDP xmit NDO on existence of xdp queues In GVE, dedicated XDP queues only exist when an XDP program is installed and the interface is up. As such, the NDO XDP XMIT callback should | 0,5% | — |
| CVE-2025-21340 | MED 5.5 | microsoft windows_10_1809 Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability | 0,5% | — |
| CVE-2024-20513 | MED 5.8 | cisco meraki_mx100_firmware A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a DoS condition for targeted users of the AnyConnect service on an affected devi | 0,5% | — |
| CVE-2023-33855 | LOW 3.7 | ibm common_cryptographic_architecture Under certain conditions, RSA operations performed by IBM Common Cryptographic Architecture (CCA) 7.0.0 through 7.5.36 may exhibit non-constant-time behavior. This could allow a remote attacker to obtain sensitive information using a timing-based attack. IBM | 0,5% | — |