57.056 CVE seguite
777 Sfruttate ora
184 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.056 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2017-12259 | HIGH 7.5 | cisco small_business_ip_phone_firmware A vulnerability in the implementation of Session Initiation Protocol (SIP) functionality in Cisco Small Business SPA51x Series IP Phones could allow an unauthenticated, remote attacker to cause an affected device to become unresponsive, resulting in a denial o | 2,3% | — |
| CVE-2017-12270 | HIGH 7.5 | cisco ios_xr A vulnerability in the gRPC code of Cisco IOS XR Software for Cisco Network Convergence System (NCS) 5500 Series Routers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition when the emsd service stops. The vulnerability | 2,3% | — |
| CVE-2017-6729 | HIGH 7.5 | cisco asr_5000_software A vulnerability in the Border Gateway Protocol (BGP) processing functionality of the Cisco StarOS operating system for Cisco ASR 5000 Series Routers and Cisco Virtualized Packet Core (VPC) Software could allow an unauthenticated, remote attacker to cause the B | 2,3% | — |
| CVE-2013-5511 | HIGH 10.0 | cisco adaptive_security_appliance_software The Adaptive Security Device Management (ASDM) remote-management feature in Cisco Adaptive Security Appliance (ASA) Software 8.2.x before 8.2(5.46), 8.3.x before 8.3(2.39), 8.4.x before 8.4(6), 8.5.x before 8.5(1.18), 8.6.x before 8.6(1.12), 8.7.x before 8.7(1 | 2,3% | — |
| CVE-2022-31780 | HIGH 7.5 | apache traffic_server Improper Input Validation vulnerability in HTTP/2 frame handling of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 9.1.2. | 2,3% | — |
| CVE-2022-29139 | HIGH 8.8 | microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 2,3% | — |
| CVE-2022-23294 | HIGH 8.8 | microsoft windows_10 Windows Event Tracing Remote Code Execution Vulnerability | 2,3% | — |
| CVE-2021-39233 | CRIT 9.1 | apache ozone In Apache Ozone versions prior to 1.2.0, Container related Datanode requests of Ozone Datanode were not properly authorized and can be called by any client. | 2,3% | — |
| CVE-2021-39231 | CRIT 9.1 | apache ozone In Apache Ozone versions prior to 1.2.0, Various internal server-to-server RPC endpoints are available for connections, making it possible for an attacker to download raw data from Datanode and Ozone manager and modify Ratis replication configuration. | 2,3% | — |
| CVE-2020-3382 | CRIT 9.8 | cisco data_center_network_manager A vulnerability in the REST API of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. The vulnerability exists be | 2,3% | — |
| CVE-2021-28477 | HIGH 7.0 | microsoft visual_studio_code Visual Studio Code Remote Code Execution Vulnerability | 2,3% | — |
| CVE-2018-4161 | HIGH 8.8 | apple icloud An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. | 2,3% | — |
| CVE-2018-5224 | HIGH 8.8 | atlassian bamboo Bamboo did not correctly check if a configured Mercurial repository URI contained values that the Windows operating system may consider argument parameters. An attacker who has permission to create a repository in Bamboo, edit an existing plan in Bamboo that h | 2,3% | — |
| CVE-2016-1265 | CRIT 9.8 | juniper junos_space A remote unauthenticated network based attacker with access to Junos Space may execute arbitrary code on Junos Space or gain access to devices managed by Junos Space using cross site request forgery (CSRF), default authentication credentials, information leak | 2,3% | — |
| CVE-2024-28913 | HIGH 8.8 | microsoft ole_db_driver_for_sql_server Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | 2,3% | — |
| CVE-2020-35931 | HIGH 7.8 | foxitsoftware foxit_reader An issue was discovered in Foxit Reader before 10.1.1 (and before 4.1.1 on macOS) and PhantomPDF before 9.7.5 and 10.x before 10.1.1 (and before 4.1.1 on macOS). An attacker can spoof a certified PDF document via an Evil Annotation Attack because the products | 2,3% | — |
| CVE-2018-0396 | MED 6.1 | cisco unified_communications_manager_im_and_presence_service A vulnerability in the web framework of the Cisco Unified Communications Manager IM and Presence Service software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of an affected | 2,3% | — |
| CVE-2013-5664 | MED 4.3 | paloaltonetworks pan-os Cross-site scripting (XSS) vulnerability in the web-based device-management API browser in Palo Alto Networks PAN-OS before 4.1.13 and 5.0.x before 5.0.6 allows remote attackers to inject arbitrary web script or HTML via crafted data, aka Ref ID 50908. | 2,3% | — |
| CVE-2022-31665 | HIGH 7.2 | vmware identity_manager VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a remote code execution vulnerability. A malicious actor with administrator and network access can trigger a remote code execution. | 2,3% | — |
| CVE-2016-6801 | HIGH 8.8 | apache jackrabbit Cross-site request forgery (CSRF) vulnerability in the CSRF content-type check in Jackrabbit-Webdav in Apache Jackrabbit 2.4.x before 2.4.6, 2.6.x before 2.6.6, 2.8.x before 2.8.3, 2.10.x before 2.10.4, 2.12.x before 2.12.4, and 2.13.x before 2.13.3 allows rem | 2,3% | — |
| CVE-2010-1138 | MED 5.0 | vmware ace The virtual networking stack in VMware Workstation 7.0 before 7.0.1 build 227600, VMware Workstation 6.5.x before 6.5.4 build 246459 on Windows, VMware Player 3.0 before 3.0.1 build 227600, VMware Player 2.5.x before 2.5.4 build 246459 on Windows, VMware ACE 2 | 2,3% | — |
| CVE-2013-1137 | HIGH 7.8 | cisco unified_presence_server Cisco Unified Presence Server (CUPS) 8.6, 9.0, and 9.1 before 9.1.1 allows remote attackers to cause a denial of service (CPU consumption) via crafted packets to the SIP TCP port, aka Bug ID CSCua89930. | 2,3% | — |
| CVE-2007-0959 | HIGH 7.8 | cisco asa_5500 Cisco PIX 500 and ASA 5500 Series Security Appliances 7.2.2, when configured to inspect certain TCP-based protocols, allows remote attackers to cause a denial of service (device reboot) via malformed TCP packets. | 2,3% | — |
| CVE-2025-54916 | HIGH 7.8 | microsoft windows_10_1507 Stack-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | 2,3% | — |
| CVE-2024-29055 | HIGH 7.2 | microsoft defender_for_iot Microsoft Defender for IoT Elevation of Privilege Vulnerability | 2,3% | — |