57.613 CVE seguite
783 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.613 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2023-33144 | MED 6.6 | microsoft visual_studio_code Visual Studio Code Spoofing Vulnerability | 1,3% | — |
| CVE-2018-0963 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka "Windows Kernel Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. | 1,3% | — |
| CVE-2017-3887 | MED 5.9 | cisco secure_firewall_threat_defense A vulnerability in the detection engine that handles Secure Sockets Layer (SSL) packets for Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition because the Snort process unexpectedly rest | 1,3% | — |
| CVE-2024-38129 | HIGH 7.5 | microsoft windows_server_2022_23h2 Windows Kerberos Elevation of Privilege Vulnerability | 1,3% | — |
| CVE-2024-25693 | CRIT 9.9 | esri portal_for_arcgis There is a path traversal in Esri Portal for ArcGIS versions <= 11.2. Successful exploitation may allow a remote, authenticated attacker to traverse the file system to access files or execute code outside of the intended directory. | 1,3% | — |
| CVE-2023-48791 | HIGH 8.8 | fortinet fortiportal An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in FortiPortal version 7.2.0, version 7.0.6 and below may allow a remote authenticated attacker with at least R/W permission to execute unauthorized c | 1,3% | — |
| CVE-2023-20855 | HIGH 8.8 | vmware vrealize_automation VMware vRealize Orchestrator contains an XML External Entity (XXE) vulnerability. A malicious actor, with non-administrative access to vRealize Orchestrator, may be able to use specially crafted input to bypass XML parsing restrictions leading to access to sen | 1,3% | — |
| CVE-2019-1053 | MED 6.3 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Shell fails to validate folder shortcuts. An attacker who successfully exploited the vulnerability could elevate privileges by escaping a sandbox. To exploit this vulnerability, an attacker would | 1,3% | — |
| CVE-2016-1324 | MED 5.3 | cisco spark The REST interface in Cisco Spark 2015-06 allows remote attackers to cause a denial of service (resource outage) by accessing an administrative page, aka Bug ID CSCuv84125. | 1,3% | — |
| CVE-2009-0623 | HIGH 7.8 | cisco ace_4710 Unspecified vulnerability in Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers before A2(1.3) and Cisco ACE 4710 Application Control Engine Appliance before A3(2.1) allows remote attackers to cause a denial of service (dev | 1,3% | — |
| CVE-2025-24064 | HIGH 8.1 | microsoft windows_server_2008 Use after free in DNS Server allows an unauthorized attacker to execute code over a network. | 1,3% | — |
| CVE-2022-22943 | MED 6.7 | vmware tools VMware Tools for Windows (11.x.y and 10.x.y prior to 12.0.0) contains an uncontrolled search path vulnerability. A malicious actor with local administrative privileges in the Windows guest OS, where VMware Tools is installed, may be able to execute code with s | 1,3% | — |
| CVE-2020-3360 | MED 5.3 | cisco unified_ip_phone_6901_firmware A vulnerability in the Web Access feature of Cisco IP Phones Series 7800 and Series 8800 could allow an unauthenticated, remote attacker to view sensitive information on an affected device. The vulnerability is due to improper access controls on the web-based | 1,3% | — |
| CVE-2015-0654 | HIGH 7.1 | cisco intrusion_prevention_system Race condition in the TLS implementation in MainApp in the management interface in Cisco Intrusion Prevention System (IPS) Software before 7.3(3)E4 allows remote attackers to cause a denial of service (process hang) by establishing many HTTPS sessions, aka Bug | 1,3% | — |
| CVE-2024-38011 | HIGH 8.0 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 1,3% | — |
| CVE-2024-37987 | HIGH 8.0 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 1,3% | — |
| CVE-2024-37975 | HIGH 8.0 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 1,3% | — |
| CVE-2023-52832 | CRIT 9.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: don't return unset power in ieee80211_get_tx_power() We can get a UBSAN warning if ieee80211_get_tx_power() returns the INT_MIN value mac80211 internally uses for "unset powe | 1,3% | — |
| CVE-2023-35798 | MED 4.3 | apache apache-airflow-providers-microsoft-mssql Input Validation vulnerability in Apache Software Foundation Apache Airflow ODBC Provider, Apache Software Foundation Apache Airflow MSSQL Provider.This vulnerability is considered low since it requires DAG code to use `get_sqlalchemy_connection` and someone w | 1,3% | — |
| CVE-2021-37713 | HIGH 8.2 | npmjs tar The npm package "tar" (aka node-tar) before versions 4.4.18, 5.0.10, and 6.1.9 has an arbitrary file creation/overwrite and arbitrary code execution vulnerability. node-tar aims to guarantee that any file whose location would be outside of the extraction targe | 1,3% | — |
| CVE-2021-29986 | HIGH 8.1 | mozilla firefox A suspected race condition when calling getaddrinfo led to memory corruption and a potentially exploitable crash. *Note: This issue only affected Linux operating systems. Other operating systems are unaffected.* This vulnerability affects Thunderbird < 78.13, | 1,3% | — |
| CVE-2021-20445 | MED 6.5 | ibm maximo_for_civil_infrastructure IBM Maximo for Civil Infrastructure 7.6.2 could allow a user to obtain sensitive information due to insecure storeage of authentication credentials. IBM X-Force ID: 196621. | 1,3% | — |
| CVE-2021-1311 | MED 5.4 | cisco webex_meetings A vulnerability in the reclaim host role feature of Cisco Webex Meetings and Cisco Webex Meetings Server could allow an authenticated, remote attacker to take over the host role during a meeting. This vulnerability is due to a lack of protection against brute | 1,3% | — |
| CVE-2017-5111 | HIGH 8.8 | debian debian_linux A use after free in PDFium in Google Chrome prior to 61.0.3163.79 for Linux, Windows, and Mac allowed a remote attacker to potentially exploit memory corruption via a crafted PDF file. | 1,3% | — |
| CVE-2013-0941 | LOW 2.1 | rsa authentication_agent EMC RSA Authentication API before 8.1 SP1, RSA Web Agent before 5.3.5 for Apache Web Server, RSA Web Agent before 5.3.5 for IIS, RSA PAM Agent before 7.0, and RSA Agent before 6.1.4 for Microsoft Windows use an improper encryption algorithm and a weak key for | 1,3% | — |