57.588 CVE seguite
783 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.588 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2020-5875 | HIGH 7.5 | f5 big-ip_access_policy_manager On BIG-IP 15.0.0-15.0.1 and 14.1.0-14.1.2.3, under certain conditions, the Traffic Management Microkernel (TMM) may generate a core file and restart while processing SSL traffic with an HTTP/2 full proxy. | 1,3% | — |
| CVE-2020-5874 | HIGH 7.5 | f5 big-ip_access_policy_manager On BIG-IP APM 15.0.0-15.0.1.2, 14.1.0-14.1.2.3, and 14.0.0-14.0.1, in certain circumstances, an attacker sending specifically crafted requests to a BIG-IP APM virtual server may cause a disruption of service provided by the Traffic Management Microkernel(TMM). | 1,3% | — |
| CVE-2020-5872 | HIGH 7.5 | f5 big-ip_access_policy_manager On BIG-IP 14.1.0-14.1.2.3, 14.0.0-14.0.1, 13.1.0-13.1.3.1, and 12.1.0-12.1.4.1, when processing TLS traffic with hardware cryptographic acceleration enabled on platforms with Intel QAT hardware, the Traffic Management Microkernel (TMM) may stop responding and | 1,3% | — |
| CVE-2018-0340 | MED 5.4 | cisco unified_communications_manager A vulnerability in the web framework of the Cisco Unified Communications Manager (Unified CM) software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of the affected system. Th | 1,3% | — |
| CVE-2016-9952 | HIGH 8.1 | haxx curl The verify_certificate function in lib/vtls/schannel.c in libcurl 7.30.0 through 7.51.0, when built for Windows CE using the schannel TLS backend, makes it easier for remote attackers to conduct man-in-the-middle attacks via a crafted wildcard SAN in a server | 1,3% | — |
| CVE-2007-2041 | MED 4.0 | cisco 2100_wireless_lan_controller Cisco Wireless LAN Controller (WLC) before 4.0.206.0 saves the WLAN ACL configuration with an invalid checksum, which prevents WLAN ACLs from being loaded at boot time, and might allow remote attackers to bypass intended access restrictions, aka Bug ID CSCse58 | 1,3% | — |
| CVE-2025-30391 | HIGH 8.1 | microsoft dynamics_365_customer_service Improper input validation in Microsoft Dynamics allows an unauthorized attacker to disclose information over a network. | 1,3% | — |
| CVE-2022-41331 | CRIT 9.8 | fortinet fortiproxy A missing authentication for critical function vulnerability [CWE-306] in FortiPresence infrastructure server before version 1.2.1 allows a remote, unauthenticated attacker to access the Redis and MongoDB instances via crafted authentication requests. | 1,3% | — |
| CVE-2021-36962 | MED 5.5 | microsoft windows_10 Windows Installer Information Disclosure Vulnerability | 1,3% | — |
| CVE-2021-29767 | MED 5.3 | ibm i2_analysts_notebook IBM i2 Analyst's Notebook Premium 9.2.0, 9.2.1, and 9.2.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IB | 1,3% | — |
| CVE-2021-29766 | MED 5.3 | ibm i2_analyze IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks again | 1,3% | — |
| CVE-2021-20430 | MED 5.3 | ibm i2_analyze IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks again | 1,3% | — |
| CVE-2021-20428 | MED 5.3 | ibm security_guardium IBM Security Guardium 11.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 196315. | 1,3% | — |
| CVE-2021-29682 | MED 5.3 | ibm security_identity_manager IBM Security Identity Manager 7.0.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 199997 | 1,3% | — |
| CVE-2020-16987 | HIGH 7.3 | microsoft azure_sphere Azure Sphere Unsigned Code Execution Vulnerability | 1,3% | — |
| CVE-2020-3422 | HIGH 7.5 | cisco ios_xe A vulnerability in the IP Service Level Agreement (SLA) responder feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the IP SLA responder to reuse an existing port, resulting in a denial of service (DoS) condition. The vu | 1,3% | — |
| CVE-2019-0037 | HIGH 7.5 | juniper junos In a Dynamic Host Configuration Protocol version 6 (DHCPv6) environment, the jdhcpd daemon may crash and restart upon receipt of certain DHCPv6 solicit messages received from a DHCPv6 client. By continuously sending the same crafted packet, an attacker can rep | 1,3% | — |
| CVE-2016-6877 | MED 5.3 | citrix xenmobile_server Citrix XenMobile Server before 10.5.0.24 allows man-in-the-middle attackers to trigger HTTP 302 redirections via vectors involving the HTTP Host header and a cached page. NOTE: the vendor reports "our internal analysis of this issue concluded that this was no | 1,3% | — |
| CVE-2021-34736 | MED 5.3 | cisco unified_computing_system A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote attacker to cause the web-based management interface to unexpectedly restart. The vulnerability is due to insu | 1,3% | — |
| CVE-2021-1394 | MED 5.3 | cisco ios_xe A vulnerability in the ingress traffic manager of Cisco IOS XE Software for Cisco Network Convergence System (NCS) 520 Routers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition in the web management interface of an af | 1,3% | — |
| CVE-2021-1243 | MED 5.3 | cisco ios_xr A vulnerability in the Local Packet Transport Services (LPTS) programming of the SNMP with the management plane protection feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to allow connections despite the management plane protec | 1,3% | — |
| CVE-2020-1116 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows Client Server Run-Time Subsystem (CSRSS) fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the use | 1,3% | — |
| CVE-2020-1072 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit this vulnerabili | 1,3% | — |
| CVE-2020-3273 | HIGH 7.5 | cisco 5508_wireless_controller_firmware A vulnerability in the 802.11 Generic Advertisement Service (GAS) frame processing function of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service | 1,3% | — |
| CVE-2019-1906 | MED 6.5 | cisco prime_infrastructure A vulnerability in the Virtual Domain system of Cisco Prime Infrastructure (PI) could allow an authenticated, remote attacker to change the virtual domain configuration, which could lead to privilege escalation. The vulnerability is due to improper validation | 1,3% | — |