57.620 CVE seguite
783 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.620 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2018-0820 | HIGH 7.8 | microsoft windows_10 The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulne | 1,2% | — |
| CVE-2018-0742 | HIGH 7.8 | microsoft windows_10 The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulne | 1,2% | — |
| CVE-2017-6764 | MED 5.4 | cisco adaptive_security_appliance_software A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) 9.5(1) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affe | 1,2% | — |
| CVE-2017-6661 | MED 6.1 | cisco content_security_management_appliance A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA) and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of | 1,2% | — |
| CVE-2009-0438 | MED 5.0 | ibm websphere_application_server IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 on Windows allows remote attackers to bypass "Authorization checking" and obtain sensitive information from JSP pages via a crafted request. NOTE: this is probably a duplicate of CVE-2008-5412. | 1,2% | — |
| CVE-2024-28925 | HIGH 8.0 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 1,2% | — |
| CVE-2012-0055 | HIGH 7.8 | canonical ubuntu_linux OverlayFS in the Linux kernel before 3.0.0-16.28, as used in Ubuntu 10.0.4 LTS and 11.10, is missing inode security checks which could allow attackers to bypass security restrictions and perform unauthorized actions. | 1,2% | — |
| CVE-2024-31141 | MED 6.5 | apache kafka Files or Directories Accessible to External Parties, Improper Privilege Management vulnerability in Apache Kafka Clients. Apache Kafka Clients accept configuration data for customizing behavior, and includes ConfigProvider plugins in order to manipulate these | 1,2% | — |
| CVE-2024-21448 | MED 5.0 | microsoft teams Microsoft Teams for Android Information Disclosure Vulnerability | 1,2% | — |
| CVE-2023-36009 | MED 5.5 | microsoft 365_apps Microsoft Word Information Disclosure Vulnerability | 1,2% | — |
| CVE-2023-32056 | HIGH 7.8 | microsoft windows_10_1809 Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability | 1,2% | — |
| CVE-2021-3772 | MED 6.5 | debian debian_linux A flaw was found in the Linux SCTP stack. A blind attacker may be able to kill an existing SCTP association through invalid chunks if the attacker knows the IP-addresses and port numbers being used and the attacker can send packets with spoofed IP addresses. | 1,2% | — |
| CVE-2021-26418 | MED 4.6 | microsoft sharepoint_foundation Microsoft SharePoint Server Spoofing Vulnerability | 1,2% | — |
| CVE-2020-1679 | HIGH 7.5 | juniper junos On Juniper Networks PTX and QFX Series devices with packet sampling configured using tunnel-observation mpls-over-udp, sampling of a malformed packet can cause the Kernel Routing Table (KRT) queue to become stuck. KRT is the module within the Routing Process D | 1,2% | — |
| CVE-2020-1749 | HIGH 7.5 | linux linux_kernel A flaw was found in the Linux kernel's implementation of some networking protocols in IPsec, such as VXLAN and GENEVE tunnels over IPv6. When an encrypted tunnel is created between two hosts, the kernel isn't correctly routing tunneled data over the encrypted | 1,2% | — |
| CVE-2020-5891 | HIGH 7.5 | f5 big-ip_access_policy_manager On BIG-IP 15.1.0-15.1.0.1, 15.0.0-15.0.1.2, and 14.1.0-14.1.2.3, undisclosed HTTP/2 requests can lead to a denial of service when sent to a virtual server configured with the Fallback Host setting and a server-side HTTP/2 profile. | 1,2% | — |
| CVE-2019-1933 | MED 5.8 | cisco email_security_appliance A vulnerability in the email message scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured filters on the device. The vulnerability is due to improper input validation o | 1,2% | — |
| CVE-2018-10648 | CRIT 9.8 | citrix xenmobile_server There are Unauthenticated File Upload Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3. | 1,2% | — |
| CVE-2024-51569 | HIGH 7.5 | apache nimble Out-of-bounds Read vulnerability in Apache NimBLE. Missing proper validation of HCI Number Of Completed Packets could lead to out-of-bound access when parsing HCI event and invalid read from HCI transport memory. This issue requires broken or bogus Bluetooth | 1,2% | — |
| CVE-2024-49048 | HIGH 8.1 | microsoft torchgeo TorchGeo Remote Code Execution Vulnerability | 1,2% | — |
| CVE-2024-29178 | HIGH 8.8 | apache streampark On versions before 2.1.4, a user could log in and perform a template injection attack resulting in Remote Code Execution on the server, The attacker must successfully log into the system to launch an attack, so this is a moderate-impact vulnerability. Mitigat | 1,2% | — |
| CVE-2024-24683 | MED 6.5 | apache hop_engine Improper Input Validation vulnerability in Apache Hop Engine.This issue affects Apache Hop Engine: before 2.8.0. Users are recommended to upgrade to version 2.8.0, which fixes the issue. When Hop Server writes links to the PrepareExecutionPipelineServlet pag | 1,2% | — |
| CVE-2023-51770 | HIGH 7.5 | apache dolphinscheduler Arbitrary File Read Vulnerability in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.1. We recommend users to upgrade Apache DolphinScheduler to version 3.2.1, which fixes the issue. | 1,2% | — |
| CVE-2022-45438 | MED 5.3 | apache superset When explicitly enabling the feature flag DASHBOARD_CACHE (disabled by default), the system allowed for an unauthenticated user to access dashboard configuration metadata using a REST API Get endpoint. This issue affects Apache Superset version 1.5.2 and prior | 1,2% | — |
| CVE-2018-0135 | MED 4.3 | cisco unified_communications_manager A vulnerability in Cisco Unified Communications Manager could allow an authenticated, remote attacker to access sensitive information on an affected system. The vulnerability exists because the affected software improperly validates user-supplied search input. | 1,2% | — |