57.620 CVE seguite
783 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.620 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2020-3596 | MED 5.9 | cisco expressway A vulnerability in the Session Initiation Protocol (SIP) of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The | 1,2% | — |
| CVE-2020-1455 | MED 5.3 | microsoft sql_server_management_studio A denial of service vulnerability exists when Microsoft SQL Server Management Studio (SSMS) improperly handles files. An attacker could exploit the vulnerability to trigger a denial of service. To exploit the vulnerability, an attacker would first require exec | 1,2% | — |
| CVE-2020-15603 | HIGH 7.5 | trendmicro antivirus\+_2020 An invalid memory read vulnerability in a Trend Micro Secuity 2020 (v16.0.0.1302 and below) consumer family of products' driver could allow an attacker to manipulate the specific driver to do a system call operation with an invalid address, resulting in a pote | 1,2% | — |
| CVE-2017-6749 | MED 5.4 | cisco web_security_appliance A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected | 1,2% | — |
| CVE-2017-5045 | MED 6.1 | debian debian_linux XSS Auditor in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed detection of a blocked iframe load, which allowed a remote attacker to brute force JavaScript variables via a crafted HTML page. | 1,2% | — |
| CVE-2017-3848 | MED 6.1 | cisco prime_infrastructure A vulnerability in the HTTP web-based management interface of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of the affected system. More Information | 1,2% | — |
| CVE-2017-3868 | MED 6.1 | cisco unified_computing_system_director A vulnerability in the web-based management interface of Cisco UCS Director could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. More Informat | 1,2% | — |
| CVE-2017-3866 | MED 6.1 | cisco prime_service_catalog A vulnerability in the web framework code of Cisco Prime Service Catalog could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of the affected system. More Information: CSCvc79842 C | 1,2% | — |
| CVE-2017-3802 | MED 6.1 | cisco unified_communications_manager A vulnerability in Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system. More Information: CSCvc20679. Known Affected Relea | 1,2% | — |
| CVE-2014-2713 | MED 5.0 | juniper junos Juniper Junos before 11.4R11, 12.1 before 12.1R9, 12.2 before 12.2R7, 12.3R4 before 12.3R4-S3, 13.1 before 13.1R4, 13.2 before 13.2R2, and 13.3 before 13.3R1, as used in MX Series and T4000 routers, allows remote attackers to cause a denial of service (PFE res | 1,2% | — |
| CVE-2010-0485 | HIGH 7.8 | microsoft windows_2000 The Windows kernel-mode drivers in win32k.sys in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 Gold and SP2, Windows 7, and Server 2008 R2 "do not properly validate all callback parameters when creating a new windo | 1,2% | — |
| CVE-2022-21895 | HIGH 7.8 | microsoft windows_10 Windows User Profile Service Elevation of Privilege Vulnerability | 1,2% | — |
| CVE-2021-43242 | HIGH 7.6 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability | 1,2% | — |
| CVE-2019-5512 | HIGH 8.8 | vmware workstation VMware Workstation (15.x before 15.0.3, 14.x before 14.1.6) running on Windows does not handle COM classes appropriately. Successful exploitation of this issue may allow hijacking of COM classes used by the VMX process, on a Windows host, leading to elevation | 1,2% | — |
| CVE-2016-8966 | MED 5.9 | ibm bigfix_inventory IBM BigFix Inventory v9 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle | 1,2% | — |
| CVE-2016-8434 | HIGH 7.0 | linux linux_kernel An elevation of privilege vulnerability in the Qualcomm GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device comprom | 1,2% | — |
| CVE-2016-7458 | MED 5.8 | vmware vsphere_client VMware vSphere Client 5.5 before U3e and 6.0 before U2a allows remote vCenter Server and ESXi instances to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External En | 1,2% | — |
| CVE-2010-3416 | CRIT 9.8 | google chrome Google Chrome before 6.0.472.59 on Linux does not properly implement the Khmer locale, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors. | 1,2% | — |
| CVE-2004-1163 | MED 5.0 | cisco cns_network_registrar Cisco CNS Network Registrar Central Configuration Management (CCM) server 6.0 through 6.1.1.3 allows remote attackers to cause a denial of service (CPU consumption) by ending a connection after sending a certain sequence of packets. | 1,2% | — |
| CVE-2026-40860 | CRIT 9.8 | apache camel JmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding class in camel-sjms, deserialized the payload of incoming JMS ObjectMessage values via javax.jms.ObjectMessage.getObject() without applying any ObjectInputFilter, class allowlist or cl | 1,2% | — |
| CVE-2023-43667 | HIGH 7.5 | apache inlong Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0, the attacker can create misleading or false log records, making it har | 1,2% | — |
| CVE-2022-35753 | HIGH 8.1 | microsoft windows_10_1507 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | 1,2% | — |
| CVE-2022-35752 | HIGH 8.1 | microsoft windows_10_1507 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | 1,2% | — |
| CVE-2022-35745 | HIGH 8.1 | microsoft windows_10_1507 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | 1,2% | — |
| CVE-2022-20758 | MED 6.8 | cisco ios_xr A vulnerability in the implementation of the Border Gateway Protocol (BGP) Ethernet VPN (EVPN) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to the | 1,2% | — |