57.613 CVE seguite
783 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.613 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2022-42466 | MED 6.1 | apache isis Prior to 2.0.0-M9, it was possible for an end-user to set the value of an editable string property of a domain object to a value that would be rendered unchanged when the value was saved. In particular, the end-user could enter javascript or similar and this w | 1,3% | — |
| CVE-2016-1322 | HIGH 7.5 | cisco spark The REST interface in Cisco Spark 2015-07-04 allows remote attackers to bypass intended access restrictions and create arbitrary user accounts via unspecified web requests, aka Bug ID CSCuv72584. | 1,3% | — |
| CVE-2016-1299 | MED 5.3 | cisco 300_series_managed_switch_firmware The web-management GUI implementation on Cisco Small Business SG300 devices 1.4.1.x allows remote attackers to cause a denial of service (HTTPS outage) via crafted HTTPS requests, aka Bug ID CSCuw87174. | 1,3% | — |
| CVE-2011-2731 | MED 5.1 | vmware springsource_spring_security Race condition in the RunAsManager mechanism in VMware SpringSource Spring Security before 2.0.7 and 3.0.x before 3.0.6 stores the Authentication object in the shared security context, which allows attackers to gain privileges via a crafted thread. | 1,3% | — |
| CVE-2023-20900 | HIGH 7.1 | debian debian_linux A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html in a target virtual machine may be able to elevate their privileges if that targe | 1,3% | — |
| CVE-2021-43220 | LOW 3.1 | microsoft edge_ios Microsoft Edge for iOS Spoofing Vulnerability | 1,3% | — |
| CVE-2021-42308 | LOW 3.1 | microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability | 1,3% | — |
| CVE-2018-0149 | MED 4.8 | cisco integrated_management_controller_supervisor A vulnerability in the web-based management interface of Cisco Integrated Management Controller Supervisor Software and Cisco UCS Director Software could allow an authenticated, remote attacker to conduct a Document Object Model-based (DOM-based), stored cross | 1,3% | — |
| CVE-2014-2146 | MED 6.5 | cisco ios The Zone-Based Firewall (ZBFW) functionality in Cisco IOS, possibly 15.4 and earlier, and IOS XE, possibly 3.13 and earlier, mishandles zone checking for existing sessions, which allows remote attackers to bypass intended resource-access restrictions via spoof | 1,3% | — |
| CVE-2009-1337 | MED 4.4 | linux linux_kernel The exit_notify function in kernel/exit.c in the Linux kernel before 2.6.30-rc1 does not restrict exit signals when the CAP_KILL capability is held, which allows local users to send an arbitrary signal to a process by running a program that modifies the exit_s | 1,3% | — |
| CVE-2026-50517 | CRIT 9.9 | microsoft 365_copilot Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network. | 1,3% | — |
| CVE-2025-20187 | MED 6.5 | cisco catalyst_sd-wan_manager A vulnerability in the application data endpoints of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, remote attacker to write arbitrary files to an affected system. This vulnerability is due to improper validation | 1,3% | — |
| CVE-2022-43720 | MED 5.4 | apache superset An authenticated attacker with write CSS template permissions can create a record with specific HTML tags that will not get properly escaped by the toast message displayed when a user deletes that specific CSS template record. This issue affects Apache Superse | 1,3% | — |
| CVE-2021-1672 | MED 5.5 | microsoft windows_10 Windows Projected File System FS Filter Driver Information Disclosure Vulnerability | 1,3% | — |
| CVE-2020-3585 | MED 5.3 | cisco adaptive_security_appliance_software A vulnerability in the TLS handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 1000 Series firewalls could allow an unauthenticated, remote attacker to gain access to sensitive infor | 1,3% | — |
| CVE-2019-0965 | HIGH 7.6 | microsoft windows_10 A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could run a specially crafted application on a | 1,3% | — |
| CVE-2017-7053 | HIGH 7.8 | apple itunes An issue was discovered in certain Apple products. iTunes before 12.6.2 on Windows is affected. The issue involves the "iTunes" component. It allows attackers to execute arbitrary code in a privileged context via a crafted app. | 1,3% | — |
| CVE-2016-8415 | HIGH 7.0 | linux linux_kernel An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. | 1,3% | — |
| CVE-2016-8412 | HIGH 7.0 | linux linux_kernel An elevation of privilege vulnerability in the Qualcomm camera could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Produ | 1,3% | — |
| CVE-2016-1450 | HIGH 7.5 | cisco webex_meetings_server Cisco WebEx Meetings Server 2.6 allows remote authenticated users to conduct command-injection attacks via vectors related to an upload's file type, aka Bug ID CSCuy92715. | 1,3% | — |
| CVE-2015-0620 | MED 4.0 | cisco telepresence_management_suite The XML parser in Cisco TelePresence Management Suite (TMS) 14.3(.2) and earlier does not properly handle external entities, which allows remote authenticated users to cause a denial of service via POST requests, aka Bug ID CSCus51494. | 1,3% | — |
| CVE-2022-20858 | CRIT 9.8 | cisco nexus_dashboard Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For more information about these vulnerabilit | 1,3% | — |
| CVE-2021-1366 | HIGH 7.8 | cisco anyconnect_secure_mobility_client A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack on an affected device if the VPN Posture (HostScan) Module is | 1,3% | — |
| CVE-2020-16921 | MED 5.5 | microsoft windows_10 <p>An information disclosure vulnerability exists in Text Services Framework when it fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could potentially read data that was not intended to be disclosed. Note t | 1,3% | — |
| CVE-2020-16919 | MED 5.5 | microsoft windows_10 <p>An information disclosure vulnerability exists when the Windows Enterprise App Management Service improperly handles certain file operations. An attacker who successfully exploited this vulnerability could read arbitrary files.</p> <p>An attacker with unpri | 1,3% | — |