57.056 CVE seguite
777 Sfruttate ora
184 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.056 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2024-29054 | HIGH 7.2 | microsoft defender_for_iot Microsoft Defender for IoT Elevation of Privilege Vulnerability | 2,3% | — |
| CVE-2024-21324 | HIGH 7.2 | microsoft defender_for_iot Microsoft Defender for IoT Elevation of Privilege Vulnerability | 2,3% | — |
| CVE-2013-5530 | HIGH 9.0 | cisco identity_services_engine_software The web framework in Cisco Identity Services Engine (ISE) 1.0 and 1.1.0 before 1.1.0.665-5, 1.1.1 before 1.1.1.268-7, 1.1.2 before 1.1.2.145-10, 1.1.3 before 1.1.3.124-7, 1.1.4 before 1.1.4.218-7, and 1.2 before 1.2.0.899-2 allows remote authenticated users to | 2,3% | — |
| CVE-2010-2665 | MED 4.3 | opera opera_browser Cross-site scripting (XSS) vulnerability in Opera before 10.54 on Windows and Mac OS X, and before 10.11 on UNIX platforms, allows remote attackers to inject arbitrary web script or HTML via a data: URI, related to incorrect detection of the "opening site." | 2,3% | — |
| CVE-2014-2721 | HIGH 8.8 | fortinet fortibalancer_1000_firmware In FortiBalancer 400, 1000, 2000 and 3000, a platform-specific remote access vulnerability has been discovered that may allow a remote user to gain privileged access to affected systems using SSH. The vulnerability is caused by a configuration error, and is no | 2,3% | — |
| CVE-2019-0817 | MED 5.4 | microsoft exchange_server A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web Access (OWA) fails to properly handle web requests, aka 'Microsoft Exchange Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0858. | 2,3% | — |
| CVE-2018-0022 | HIGH 7.5 | juniper junos A Junos device with VPLS routing-instances configured on one or more interfaces may be susceptible to an mbuf leak when processing a specific MPLS packet. Approximately 1 mbuf is leaked per each packet processed. The number of mbufs is platform dependent. The | 2,3% | — |
| CVE-2011-2395 | MED 5.0 | cisco ios The Neighbor Discovery (ND) protocol implementation in Cisco IOS on unspecified switches allows remote attackers to bypass the Router Advertisement Guarding functionality via a fragmented IPv6 packet in which the Router Advertisement (RA) message is contained | 2,3% | — |
| CVE-2009-4027 | HIGH 7.1 | linux linux_kernel Race condition in the mac80211 subsystem in the Linux kernel before 2.6.32-rc8-next-20091201 allows remote attackers to cause a denial of service (system crash) via a Delete Block ACK (aka DELBA) packet that triggers a certain state change in the absence of an | 2,3% | — |
| CVE-2024-30036 | MED 6.5 | microsoft windows_server_2008 Windows Deployment Services Information Disclosure Vulnerability | 2,3% | — |
| CVE-2015-5241 | MED 6.1 | apache juddi After logging into the portal, the logout jsp page redirects the browser back to the login page after. It is feasible for malicious users to redirect the browser to an unintended web page in Apache jUDDI 3.1.2, 3.1.3, 3.1.4, and 3.1.5 when utilizing the portle | 2,3% | — |
| CVE-2013-3172 | MED 4.9 | microsoft windows_7 Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to cause a denial of service (system hang) via a | 2,3% | — |
| CVE-2009-3759 | HIGH 8.8 | citrix xencenterweb Multiple cross-site request forgery (CSRF) vulnerabilities in sample code in the XenServer Resource Kit in Citrix XenCenterWeb allow remote attackers to hijack the authentication of administrators for (1) requests that change the password via the username para | 2,3% | — |
| CVE-2021-23025 | HIGH 8.8 | f5 big-ip_access_policy_manager On version 15.1.x before 15.1.0.5, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.5, and all versions of 12.1.x and 11.6.x, an authenticated remote command execution vulnerability exists in the BIG-IP Configuration utility. Note: Software versions which have rea | 2,3% | — |
| CVE-2020-3809 | MED 5.5 | adobe after_effects Adobe After Effects versions 17.0.1 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure . | 2,3% | — |
| CVE-2017-8628 | MED 6.8 | microsoft windows_10 Microsoft Bluetooth Driver in Windows Server 2008 SP2, Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703 allows a spoofing vulnerability due to Microsoft's implementation of the Bluetooth stack, aka "Microsoft Bluetooth Driver Spoof | 2,3% | — |
| CVE-2011-2339 | HIGH 7.6 | apple itunes WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other | 2,3% | — |
| CVE-2019-1357 | MED 4.3 | microsoft edge A spoofing vulnerability exists when Microsoft Browsers improperly handle browser cookies, aka 'Microsoft Browser Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0608. | 2,3% | — |
| CVE-2019-0608 | MED 4.3 | microsoft edge A spoofing vulnerability exists when Microsoft Browsers does not properly parse HTTP content, aka 'Microsoft Browser Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-1357. | 2,3% | — |
| CVE-2018-15453 | HIGH 8.6 | cisco email_security_appliance_firmware A vulnerability in the Secure/Multipurpose Internet Mail Extensions (S/MIME) Decryption and Verification or S/MIME Public Key Harvesting features of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker | 2,3% | — |
| CVE-2005-1891 | HIGH 7.5 | aol aim The GIF parser in ateimg32.dll in AOL Instant Messenger (AIM) 5.9.3797 and earlier allows remote attackers to cause a denial of service (crash) via a malformed buddy icon that causes an integer underflow in a loop counter variable. | 2,3% | — |
| CVE-2021-34503 | HIGH 7.8 | microsoft windows_10 Microsoft Windows Media Foundation Remote Code Execution Vulnerability | 2,3% | — |
| CVE-2018-8506 | MED 5.5 | microsoft windows_10 An Information Disclosure vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory, aka "Microsoft Windows Codecs Library Information Disclosure Vulnerability." This affects Windows 10 Servers, Windows 10, Windows Server | 2,3% | — |
| CVE-2015-4329 | MED 6.5 | cisco telepresence_video_communication_server_software The administrator web interface in Cisco TelePresence Video Communication Server (VCS) X8.5.2 allows remote authenticated users to execute arbitrary OS commands via crafted HTTP requests, aka Bug ID CSCuv11796. | 2,3% | — |
| CVE-2013-1414 | MED 5.1 | fortinet fortigate-1000c Multiple cross-site request forgery (CSRF) vulnerabilities in Fortinet FortiOS on FortiGate firewall devices before 4.3.13 and 5.x before 5.0.2 allow remote attackers to hijack the authentication of administrators for requests that modify (1) settings or (2) p | 2,3% | — |