57.065 CVE seguite
777 Sfruttate ora
184 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.065 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2020-2009 | HIGH 7.2 | paloaltonetworks pan-os An external control of filename vulnerability in the SD WAN component of Palo Alto Networks PAN-OS Panorama allows an authenticated administrator to send a request that results in the creation and write of an arbitrary file on all firewalls managed by the Pano | 2,0% | — |
| CVE-2017-7090 | HIGH 7.5 | apple icloud An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. iTunes before 12.7 on Windows is affected. tvOS before 11 is affected. The issue involves the "WebKit" compone | 2,0% | — |
| CVE-2016-4760 | MED 6.5 | apple iphone_os WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 allows remote attackers to conduct DNS rebinding attacks against non-HTTP Safari sessions by leveraging HTTP/0.9 support. | 2,0% | — |
| CVE-2015-2454 | LOW 2.1 | microsoft windows_7 The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly constrain impersonation levels, which allows local | 2,0% | — |
| CVE-2014-3375 | MED 4.3 | cisco unified_communications_manager Multiple cross-site scripting (XSS) vulnerabilities in the CCM Service interface in the Server in Cisco Unified Communications Manager allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCuq90597. | 2,0% | — |
| CVE-2014-3374 | MED 4.3 | cisco unified_communications_manager Multiple cross-site scripting (XSS) vulnerabilities in the CCM admin interface in the Server in Cisco Unified Communications Manager allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCuq90582. | 2,0% | — |
| CVE-2014-3373 | MED 4.3 | cisco unified_communications_manager Multiple cross-site scripting (XSS) vulnerabilities in the CCM Dialed Number Analyzer interface in the Server in Cisco Unified Communications Manager allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCup9255 | 2,0% | — |
| CVE-2014-3372 | MED 4.3 | cisco unified_communications_manager Multiple cross-site scripting (XSS) vulnerabilities in the CCM reports interface in the Server in Cisco Unified Communications Manager allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCuq90589. | 2,0% | — |
| CVE-2014-3344 | MED 4.3 | cisco transport_gateway_installation_software Multiple cross-site scripting (XSS) vulnerabilities in the web framework in Cisco Transport Gateway for Smart Call Home (aka TG-SCH or Transport Gateway Installation Software) 4.0 allow remote attackers to inject arbitrary web script or HTML via unspecified pa | 2,0% | — |
| CVE-2014-3313 | MED 4.3 | cisco spa901_1-line_ip_phone Cross-site scripting (XSS) vulnerability in the web user interface on Cisco Small Business SPA300 and SPA500 phones allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuo52582. | 2,0% | — |
| CVE-2014-1735 | HIGH 7.5 | google chrome Multiple unspecified vulnerabilities in Google V8 before 3.24.35.33, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux, allow attackers to cause a denial of service or possibly have other impact via unknown vec | 2,0% | — |
| CVE-2014-0680 | MED 4.3 | cisco identity_services_engine Cross-site scripting (XSS) vulnerability in the HTTP control interface in the NAC Web Agent component in Cisco Identity Services Engine (ISE) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCui15038. | 2,0% | — |
| CVE-2013-6960 | MED 4.3 | cisco webex_meeting_center Multiple cross-site scripting (XSS) vulnerabilities in Cisco WebEx Meeting Center allow remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCul36248. | 2,0% | — |
| CVE-2012-5050 | MED 4.3 | vmware vcenter_operations Cross-site scripting (XSS) vulnerability in the server in VMware vCenter Operations (aka vCOps) before 5.0.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 2,0% | — |
| CVE-2007-4293 | HIGH 7.1 | cisco ios Cisco IOS 12.0 through 12.4 allows remote attackers to cause a denial of service (device crash) via (1) "abnormal" MGCP messages, aka CSCsd81407; and (2) a large facsimile packet, aka CSCej20505. | 2,0% | — |
| CVE-2026-62713 | HIGH 7.8 | microsoft windows_10_1809 Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. | 1,9% | — |
| CVE-2021-38161 | HIGH 8.1 | apache traffic_server Improper Authentication vulnerability in TLS origin verification of Apache Traffic Server allows for man in the middle attacks. This issue affects Apache Traffic Server 8.0.0 to 8.0.8. | 1,9% | — |
| CVE-2021-34517 | MED 5.3 | microsoft sharepoint_foundation Microsoft SharePoint Server Spoofing Vulnerability | 1,9% | — |
| CVE-2021-3339 | MED 4.3 | microsoft modernflow ModernFlow before 1.3.00.208 does not constrain web-page access to members of a security group, as demonstrated by the Search Screen and the Profile Screen. | 1,9% | — |
| CVE-2020-13926 | CRIT 9.8 | apache kylin Kylin concatenates and executes a Hive SQL in Hive CLI or beeline when building a new segment; some part of the HQL is from system configurations, while the configuration can be overwritten by certain rest api, which makes SQL injection attack is possible. Use | 1,9% | — |
| CVE-2023-23477 | HIGH 8.1 | ibm websphere_application_server IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence of serialized objects. IBM X-Force ID: 245513. | 1,9% | — |
| CVE-2022-44645 | HIGH 8.8 | apache linkis In Apache Linkis <=1.3.0 when used with the MySQL Connector/J, a deserialization vulnerability with possible remote code execution impact exists when an attacker has write access to a database and configures new datasource with a MySQL data source and maliciou | 1,9% | — |
| CVE-2021-4287 | MED 5.0 | microsoft binwalk A vulnerability, which was classified as problematic, was found in ReFirm Labs binwalk up to 2.3.2. Affected is an unknown function of the file src/binwalk/modules/extractor.py of the component Archive Extraction Handler. The manipulation leads to symlink foll | 1,9% | — |
| CVE-2022-37959 | MED 6.5 | microsoft windows_server_2012 Network Device Enrollment Service (NDES) Security Feature Bypass Vulnerability | 1,9% | — |
| CVE-2021-1259 | MED 6.5 | cisco sd-wan_vmanage A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct path traversal attacks and obtain write access to sensitive files on an affected system. The vulnerability is due to | 1,9% | — |