57.620 CVE seguite
783 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.620 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2021-38642 | MED 6.1 | microsoft edge Microsoft Edge for iOS Spoofing Vulnerability | 1,2% | — |
| CVE-2021-38641 | MED 6.1 | microsoft edge Microsoft Edge for Android Spoofing Vulnerability | 1,2% | — |
| CVE-2019-1942 | MED 4.3 | cisco identity_services_engine A vulnerability in the sponsor portal web interface for Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to impact the integrity of an affected system by executing arbitrary SQL queries. The vulnerability is due to insufficien | 1,2% | — |
| CVE-2019-0028 | HIGH 7.5 | juniper junos On Junos devices with the BGP graceful restart helper mode enabled or the BGP graceful restart mechanism enabled, a BGP session restart on a remote peer that has the graceful restart mechanism enabled may cause the local routing protocol daemon (RPD) process t | 1,2% | — |
| CVE-2017-2290 | HIGH 8.8 | puppet mcollective-puppet-agent On Windows installations of the mcollective-puppet-agent plugin, version 1.12.0, a non-administrator user can create an executable that will be executed with administrator privileges on the next "mco puppet" run. Puppet Enterprise users are not affected. This | 1,2% | — |
| CVE-2025-33051 | HIGH 7.5 | microsoft exchange_server Exposure of sensitive information to an unauthorized actor in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network. | 1,2% | — |
| CVE-2025-27017 | MED 6.5 | apache nifi Apache NiFi 1.13.0 through 2.2.0 includes the username and password used to authenticate with MongoDB in the NiFi provenance events that MongoDB components generate during processing. An authorized user with read access to the provenance events of those proces | 1,2% | — |
| CVE-2024-43600 | HIGH 7.8 | microsoft office Microsoft Office Elevation of Privilege Vulnerability | 1,2% | — |
| CVE-2022-22375 | HIGH 7.2 | ibm security_verify_privilege_on-premises IBM Security Verify Privilege On-Premises 11.5 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 221681. | 1,2% | — |
| CVE-2023-36794 | HIGH 7.8 | microsoft .net Visual Studio Remote Code Execution Vulnerability | 1,2% | — |
| CVE-2021-31978 | MED 5.5 | microsoft malware_protection_engine Microsoft Defender Denial of Service Vulnerability | 1,2% | — |
| CVE-2020-2022 | HIGH 7.5 | paloaltonetworks pan-os An information exposure vulnerability exists in Palo Alto Networks Panorama software that discloses the token for the Panorama web interface administrator's session to a managed device when the Panorama administrator performs a context switch into that device. | 1,2% | — |
| CVE-2020-1420 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when Windows Error Reporting improperly handles file operations.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Error Reporting Information Disclosu | 1,2% | — |
| CVE-2020-1358 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows Resource Policy component improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Resource Policy Information Dis | 1,2% | — |
| CVE-2023-34367 | MED 6.5 | microsoft windows_7 Windows 7 is vulnerable to a full blind TCP/IP hijacking attack. The vulnerability exists in Windows 7 (any Windows until Windows 8) and in any implementation of TCP/IP, which is vulnerable to the Idle scan attack (including many IoT devices). NOTE: The vendor | 1,2% | — |
| CVE-2022-40308 | HIGH 7.5 | apache archiva If anonymous read enabled, it's possible to read the database file directly without logging in. | 1,2% | — |
| CVE-2020-1426 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1367, CVE-2020-1389, CVE-2020-1419. | 1,2% | — |
| CVE-2020-1391 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows Agent Activation Runtime (AarSvc) fails to properly handle objects in memory, aka 'Windows Agent Activation Runtime Information Disclosure Vulnerability'. | 1,2% | — |
| CVE-2020-1389 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel fails to properly initialize a memory address, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1367, CVE-2020-1419, CVE-2020-1426. | 1,2% | — |
| CVE-2020-1386 | MED 5.5 | microsoft windows_10 An information vulnerability exists when Windows Connected User Experiences and Telemetry Service improperly discloses file information, aka 'Connected User Experiences and Telemetry Service Information Disclosure Vulnerability'. | 1,2% | — |
| CVE-2020-1367 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1389, CVE-2020-1419, CVE-2020-1426. | 1,2% | — |
| CVE-2020-1330 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions, aka 'Windows Mobile Device Management Diagnostics Information Disclosure Vulnerability'. | 1,2% | — |
| CVE-2012-1868 | MED 6.9 | microsoft windows_xp Race condition in the thread-creation implementation in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP3 allows local users to gain privileges via a crafted application, aka "Win32k.sys Race Condition Vulnerability." | 1,2% | — |
| CVE-2012-1867 | HIGH 8.4 | microsoft windows_2003_server Integer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted T | 1,2% | — |
| CVE-2005-3174 | MED 4.6 | microsoft windows_2000 Microsoft Windows 2000 before Update Rollup 1 for SP4 allows users to log on to the domain, even when their password has expired, if the fully qualified domain name (FQDN) is 8 characters long. | 1,2% | — |