57.479 CVE seguite
782 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.479 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2016-3346 | HIGH 7.8 | microsoft windows_10 Microsoft Windows 10 Gold, 1511, and 1607 does not properly enforce permissions, which allows local users to obtain Administrator access via a crafted DLL, aka "Windows Permissions Enforcement Elevation of Privilege Vulnerability." | 1,4% | — |
| CVE-2015-6387 | MED 4.3 | cisco unified_computing_system_central_software Cross-site scripting (XSS) vulnerability in Cisco Unified Computing System (UCS) Central Software 1.3(0.1) allows remote attackers to inject arbitrary web script or HTML via a crafted value in a URL, aka Bug ID CSCux33573. | 1,4% | — |
| CVE-2015-6390 | MED 4.3 | cisco unity_connection Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unity Connection 9.1(1.10) allows remote attackers to inject arbitrary web script or HTML via a crafted value in a URL, aka Bug ID CSCup92741. | 1,4% | — |
| CVE-2015-6349 | MED 4.3 | cisco secure_access_control_server Cross-site scripting (XSS) vulnerability in the web interface in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote attackers to inject arbitrary web script or HTML via a crafted URL. | 1,4% | — |
| CVE-2015-6346 | MED 4.3 | cisco secure_access_control_server Cross-site scripting (XSS) vulnerability in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote attackers to inject arbitrary web script or HTML via a crafted URL. | 1,4% | — |
| CVE-2015-6268 | HIGH 7.8 | cisco ios_xe Cisco IOS XE before 2.2.3 on ASR 1000 devices allows remote attackers to cause a denial of service (Embedded Services Processor crash) via a crafted IPv4 UDP packet, aka Bug ID CSCsw95482. | 1,4% | — |
| CVE-2015-4294 | MED 4.3 | cisco unified_communications_manager_im_and_presence_service Cross-site scripting (XSS) vulnerability in Cisco IM and Presence Service before 10.5 MR1 allows remote attackers to inject arbitrary web script or HTML by constructing a crafted URL that leverages incomplete filtering of HTML elements, aka Bug ID CSCut41766. | 1,4% | — |
| CVE-2015-4292 | MED 4.3 | cisco prime_central_for_hosted_collaboration_solution_assurance Cross-site scripting (XSS) vulnerability in the management interface in Cisco Prime Central for Hosted Collaboration Solution (PC4HCS) 10.6(2) allows remote attackers to inject arbitrary web script or HTML via an unspecified value, aka Bug ID CSCuv45818. | 1,4% | — |
| CVE-2015-4283 | HIGH 7.8 | cisco videoscape_policy_resource_manager Cisco Videoscape Policy Resource Manager (PRM) 3.5.4 allows remote attackers to cause a denial of service (CPU and memory consumption, and TCP service outage) via (1) a SYN flood or (2) another type of TCP traffic flood, aka Bug IDs CSCuu35104 and CSCuu35128. | 1,4% | — |
| CVE-2010-3941 | HIGH 8.4 | microsoft windows_2003_server Double free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold and SP2, and Windows 7 allows local users to gain privileges via a crafted appl | 1,4% | — |
| CVE-1999-0843 | MED 5.0 | cisco router Denial of service in Cisco routers running NAT via a PORT command from an FTP client to a Telnet port. | 1,4% | — |
| CVE-2024-29834 | MED 6.4 | apache pulsar This vulnerability allows authenticated users with produce or consume permissions to perform unauthorized operations on partitioned topics, such as unloading topics and triggering compaction. These management operations should be restricted to users with the t | 1,4% | — |
| CVE-2024-20667 | HIGH 7.5 | microsoft azure_devops_server Azure DevOps Server Remote Code Execution Vulnerability | 1,4% | — |
| CVE-2019-17183 | HIGH 7.5 | foxitsoftware reader Foxit Reader before 9.7 allows an Access Violation and crash if insufficient memory exists. | 1,4% | — |
| CVE-2014-3396 | HIGH 7.5 | cisco asr_9000_rsp440_router Cisco IOS XR on ASR 9000 devices does not properly use compression for port-range and address-range encoding, which allows remote attackers to bypass intended Typhoon line-card ACL restrictions via transit traffic, aka Bug ID CSCup30133. | 1,4% | — |
| CVE-1999-0222 | MED 5.0 | cisco router Denial of service in Cisco IOS web server allows attackers to reboot the router using a long URL. | 1,4% | — |
| CVE-2025-47856 | HIGH 7.2 | fortinet fortivoice Two improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiVoice version 7.2.0, 7.0.0 through 7.0.6 and before 6.4.10 allows a privileged attacker to execute arbitrary code or comman | 1,4% | — |
| CVE-2025-29954 | MED 5.9 | microsoft windows_10_1507 Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network. | 1,4% | — |
| CVE-2025-26628 | HIGH 7.3 | microsoft azure_local_cluster Insufficiently protected credentials in Azure Local Cluster allows an authorized attacker to disclose information locally. | 1,4% | — |
| CVE-2021-47548 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ethernet: hisilicon: hns: hns_dsaf_misc: fix a possible array overflow in hns_dsaf_ge_srst_by_port() The if statement: if (port >= DSAF_GE_NUM) return; limits the value of port le | 1,4% | — |
| CVE-2024-20287 | MED 6.5 | cisco wap371_firmware A vulnerability in the web-based management interface of the Cisco WAP371 Wireless-AC/N Dual Radio Access Point (AP) with Single Point Setup could allow an authenticated, remote attacker to perform command injection attacks against an affected device. This vul | 1,4% | — |
| CVE-2022-2170 | MED 4.8 | microsoft microsoft_advertising_universal_event_tracking The Microsoft Advertising Universal Event Tracking (UET) WordPress plugin before 1.0.4 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is di | 1,4% | — |
| CVE-2021-21982 | CRIT 9.1 | vmware carbon_black_cloud_workload VMware Carbon Black Cloud Workload appliance 1.0.0 and 1.01 has an authentication bypass vulnerability that may allow a malicious actor with network access to the administrative interface of the VMware Carbon Black Cloud Workload appliance to obtain a valid au | 1,4% | — |
| CVE-2020-1614 | CRIT 10.0 | juniper junos A Use of Hard-coded Credentials vulnerability exists in the NFX250 Series for the vSRX Virtual Network Function (VNF) instance, which allows an attacker to take control of the vSRX VNF instance if they have the ability to access an administrative service (e.g. | 1,4% | — |
| CVE-2018-13384 | MED 6.1 | fortinet fortios A Host Header Redirection vulnerability in Fortinet FortiOS all versions below 6.0.5 under SSL VPN web portal allows a remote attacker to potentially poison HTTP cache and subsequently redirect SSL VPN web portal users to arbitrary web domains. | 1,4% | — |