57.148 CVE seguite
779 Sfruttate ora
184 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.148 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2018-0103 | HIGH 7.8 | cisco webex_business_suite A Buffer Overflow vulnerability in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) files could allow a local attacker to execute arbitrary code on the system of a user. The attacker could exploit this vulnerability by sending the user | 1,7% | — |
| CVE-2023-20066 | MED 6.5 | cisco ios_xe A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to perform a directory traversal and access resources that are outside the filesystem mountpoint of the web UI. This vulnerability is due to an insufficient se | 1,7% | — |
| CVE-2021-1495 | MED 5.8 | cisco ios_xe Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due to incorrect handling of specific HTTP header param | 1,7% | — |
| CVE-2020-27730 | CRIT 9.8 | f5 nginx_controller In versions 3.0.0-3.9.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller Agent does not use absolute paths when calling system utilities. | 1,7% | — |
| CVE-2018-0223 | MED 6.1 | cisco security_manager A vulnerability in DesktopServlet in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based interface. The vulnerabil | 1,7% | — |
| CVE-2018-0219 | MED 6.1 | cisco unified_computing_system_director A vulnerability in the web-based management interface of Cisco Unified Computing System (UCS) Director could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an aff | 1,7% | — |
| CVE-2018-0212 | MED 6.1 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected dev | 1,7% | — |
| CVE-2018-0144 | MED 6.1 | cisco prime_data_center_network_manager A vulnerability in the web-based management interface of Cisco Prime Data Center Network Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected | 1,7% | — |
| CVE-2017-10614 | MED 5.3 | juniper junos A vulnerability in telnetd service on Junos OS allows a remote attacker to cause a limited memory and/or CPU consumption denial of service attack. This issue was found during internal product security testing. Affected releases are Juniper Networks Junos OS 12 | 1,7% | — |
| CVE-2017-12248 | MED 6.1 | cisco unified_intelligence_center A vulnerability in the web framework code of Cisco Unified Intelligence Center Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system. The vulnerability | 1,7% | — |
| CVE-2023-44981 | CRIT 9.1 | apache zookeeper Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper. If SASL Quorum Peer authentication is enabled in ZooKeeper (quorum.auth.enableSasl=true), the authorization is done by verifying that the instance part in SASL authentication I | 1,7% | — |
| CVE-2022-0400 | HIGH 7.5 | linux linux_kernel An out-of-bounds read vulnerability was discovered in linux kernel in the smc protocol stack, causing remote dos. | 1,7% | — |
| CVE-2019-1773 | HIGH 7.8 | cisco webex_business_suite A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software im | 1,7% | — |
| CVE-2019-1772 | HIGH 7.8 | cisco webex_business_suite A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software im | 1,7% | — |
| CVE-2010-1796 | LOW 2.6 | apple safari The AutoFill feature in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4, allows remote attackers to obtain sensitive Address Book Card information via JavaScript code that forces keystroke events for input | 1,7% | — |
| CVE-2020-1101 | MED 5.4 | microsoft sharepoint_enterprise_server A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially cra | 1,7% | — |
| CVE-2020-1100 | MED 5.4 | microsoft sharepoint_enterprise_server A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially cra | 1,7% | — |
| CVE-2020-1099 | MED 5.4 | microsoft sharepoint_enterprise_server A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially cra | 1,7% | — |
| CVE-2012-1104 | MED 5.3 | apereo phpcas A Security Bypass vulnerability exists in the phpCAS 1.2.2 library from the jasig project due to the way proxying of services are managed. | 1,7% | — |
| CVE-2019-1399 | MED 6.2 | microsoft windows_10 A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-071 | 1,7% | — |
| CVE-2019-1715 | MED 5.3 | cisco adaptive_security_appliance_device_manager A vulnerability in the Deterministic Random Bit Generator (DRBG), also known as Pseudorandom Number Generator (PRNG), used in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, rem | 1,7% | — |
| CVE-2024-30076 | MED 6.8 | microsoft windows_10_1607 Windows Container Manager Service Elevation of Privilege Vulnerability | 1,7% | — |
| CVE-2022-0020 | MED 6.8 | paloaltonetworks cortex_xsoar A stored cross-site scripting (XSS) vulnerability in Palo Alto Network Cortex XSOAR web interface enables an authenticated network-based attacker to store a persistent javascript payload that will perform arbitrary actions in the Cortex XSOAR web interface on | 1,7% | — |
| CVE-2020-10713 | HIGH 8.2 | debian debian_linux A flaw was found in grub2, prior to version 2.06. An attacker may use the GRUB 2 flaw to hijack and tamper the GRUB verification process. This flaw also allows the bypass of Secure Boot protections. In order to load an untrusted or modified kernel, an attacker | 1,7% | — |
| CVE-2019-16919 | HIGH 7.5 | linuxfoundation harbor Harbor API has a Broken Access Control vulnerability. The vulnerability allows project administrators to use the Harbor API to create a robot account with unauthorized push and/or pull access permissions to a project they don't have access or control for. The | 1,7% | — |