57.538 CVE seguite
782 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.538 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2019-1282 | MED 5.5 | microsoft windows_10 An information disclosure exists in the Windows Common Log File System (CLFS) driver when it fails to properly handle sandbox checks, aka 'Windows Common Log File System Driver Information Disclosure Vulnerability'. | 1,3% | — |
| CVE-2019-1274 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel fails to properly initialize a memory address, aka 'Windows Kernel Information Disclosure Vulnerability'. | 1,3% | — |
| CVE-2017-14185 | MED 5.3 | fortinet fortios An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8 and 5.2 all versions allows SSL VPN web portal users to access internal FortiOS configuration information (eg:addresses) via specifically crafted URLs inside the SSL-VPN | 1,3% | — |
| CVE-2010-2826 | HIGH 9.0 | cisco wireless_control_system_software SQL injection vulnerability in Cisco Wireless Control System (WCS) 6.0.x before 6.0.196.0 allows remote authenticated users to execute arbitrary SQL commands via vectors related to the ORDER BY clause of the Client List screens, aka Bug ID CSCtf37019. | 1,3% | — |
| CVE-2025-29807 | HIGH 8.7 | microsoft dataverse Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network. | 1,3% | — |
| CVE-2023-30447 | MED 5.9 | ibm db2 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query on certain tables. IBM X-Force ID: 253436. | 1,3% | — |
| CVE-2023-30446 | MED 5.9 | ibm db2 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query on certain tables. IBM X-Force ID: 253361 . | 1,3% | — |
| CVE-2021-21196 | HIGH 8.8 | fedoraproject fedora Heap buffer overflow in TabStrip in Google Chrome on Windows prior to 89.0.4389.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | 1,3% | — |
| CVE-2020-17520 | MED 6.5 | apache pulsar_manager In the Pulsar manager 0.1.0 version, malicious users will be able to bypass pulsar-manager's admin, permission verification mechanism by constructing special URLs, thereby accessing any HTTP API. | 1,3% | — |
| CVE-2020-1999 | MED 5.3 | paloaltonetworks pan-os A vulnerability exists in the Palo Alto Network PAN-OS signature-based threat detection engine that allows an attacker to communicate with devices in the network in a way that is not analyzed for threats by sending data through specifically crafted TCP packets | 1,3% | — |
| CVE-2019-19769 | MED 6.7 | fedoraproject fedora In the Linux kernel 5.3.10, there is a use-after-free (read) in the perf_trace_lock_acquire function (related to include/trace/events/lock.h). | 1,3% | — |
| CVE-2018-4146 | MED 6.5 | apple icloud An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. | 1,3% | — |
| CVE-2016-1976 | MED 5.5 | mozilla firefox Use-after-free vulnerability in the DesktopDisplayDevice class in the WebRTC implementation in Mozilla Firefox before 45.0 on Windows might allow remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors. | 1,3% | — |
| CVE-2011-4022 | MED 5.0 | cisco intrusion_prevention_system The sensor in Cisco Intrusion Prevention System (IPS) 7.0 and 7.1 allows remote attackers to cause a denial of service (file-handle exhaustion and mainApp hang) by making authentication attempts that exceed the configured limit, aka Bug ID CSCto51204. | 1,3% | — |
| CVE-2022-24495 | HIGH 7.0 | microsoft windows_10 Windows Direct Show Remote Code Execution Vulnerability | 1,3% | — |
| CVE-2021-31379 | HIGH 7.5 | juniper junos An Incorrect Behavior Order vulnerability in the MAP-E automatic tunneling mechanism of Juniper Networks Junos OS allows an attacker to send certain malformed IPv4 or IPv6 packets to cause a Denial of Service (DoS) to the PFE on the device which is disabled as | 1,3% | — |
| CVE-2017-5058 | HIGH 8.8 | google chrome A use after free in PrintPreview in Google Chrome prior to 58.0.3029.81 for Windows allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. | 1,3% | — |
| CVE-2011-2839 | HIGH 7.5 | google chrome The PDF implementation in Google Chrome before 13.0.782.215 on Linux does not properly use the memset library function, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors. | 1,3% | — |
| CVE-2009-2056 | LOW 3.3 | cisco ios_xr Cisco IOS XR 3.8.1 and earlier allows remote authenticated users to cause a denial of service (process crash) via vectors involving a BGP UPDATE message with many AS numbers prepended to the AS path. | 1,3% | — |
| CVE-2009-1154 | LOW 3.3 | cisco ios_xr Cisco IOS XR 3.8.1 and earlier allows remote attackers to cause a denial of service (process crash) via a long BGP UPDATE message, as demonstrated by a message with many AS numbers in the AS Path Attribute. | 1,3% | — |
| CVE-2021-1464 | MED 5.0 | cisco catalyst_sd-wan_manager A vulnerability in Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization checking and gain restricted access to the configuration information of an affected system. This vulnerability exists because the affec | 1,3% | — |
| CVE-2024-20679 | MED 6.5 | microsoft azure_stack_hub Azure Stack Hub Spoofing Vulnerability | 1,3% | — |
| CVE-2023-40610 | MED 6.3 | apache superset Improper authorization check and possible privilege escalation on Apache Superset up to but excluding 2.1.2. Using the default examples database connection that allows access to both the examples schema and Apache Superset's metadata database, an attacker usin | 1,3% | — |
| CVE-2023-22665 | MED 5.4 | apache jena There is insufficient checking of user queries in Apache Jena versions 4.7.0 and earlier, when invoking custom scripts. It allows a remote user to execute arbitrary javascript via a SPARQL query. | 1,3% | — |
| CVE-2020-26076 | HIGH 7.5 | cisco iot_field_network_director A vulnerability in Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to view sensitive database information on an affected device. The vulnerability is due to the absence of authentication for sensitive information. An atta | 1,3% | — |