57.725 CVE seguite
783 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.725 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2017-15941 | MED 6.1 | paloaltonetworks pan-os Cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.7, when the GlobalProtect gateway or portal is configured, allows remote attackers to inject arbitrary web scrip | 1,2% | — |
| CVE-2017-12416 | MED 6.1 | paloaltonetworks pan-os Cross-site scripting (XSS) vulnerability in the GlobalProtect internal and external gateway interface in Palo Alto Networks PAN-OS before 6.1.18, 7.0.x before 7.0.17, 7.1.x before 7.1.12, and 8.0.x before 8.0.3 allows remote attackers to inject arbitrary web s | 1,2% | — |
| CVE-2017-9467 | MED 6.1 | paloaltonetworks pan-os Cross-site scripting (XSS) vulnerability in the GlobalProtect external interface in Palo Alto Networks PAN-OS before 6.1.18, 7.x before 7.0.16, 7.1.x before 7.1.11, and 8.x before 8.0.3 allows remote attackers to inject arbitrary web script or HTML via unspeci | 1,2% | — |
| CVE-2017-9459 | MED 6.1 | paloaltonetworks pan-os Cross-site scripting (XSS) vulnerability in the management web interface in Palo Alto Networks PAN-OS before 6.1.18, 7.x before 7.0.16, 7.1.x before 7.1.11, and 8.x before 8.0.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vec | 1,2% | — |
| CVE-2026-42898 | CRIT 9.9 | microsoft dynamics_365 Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network. | 1,2% | — |
| CVE-2024-23114 | CRIT 9.8 | apache camel Deserialization of Untrusted Data vulnerability in Apache Camel CassandraQL Component AggregationRepository which is vulnerable to unsafe deserialization. Under specific conditions it is possible to deserialize malicious payload.This issue affects Apache Camel | 1,2% | — |
| CVE-2021-1616 | MED 4.7 | cisco ios_xe A vulnerability in the H.323 application level gateway (ALG) used by the Network Address Translation (NAT) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass the ALG. This vulnerability is due to insufficient data valida | 1,2% | — |
| CVE-2020-7815 | HIGH 7.8 | tobesoft xplatform XPLATFORM v9.2.260 and eariler versions contain a vulnerability that could allow remote files to be downloaded by setting the arguments to the vulnerable method. this can be leveraged for code execution. File download vulnerability in ____COMPONENT____ of TOBE | 1,2% | — |
| CVE-2020-3256 | MED 4.9 | cisco hosted_collaboration_mediation_fulfillment A vulnerability in the web-based management interface of Cisco Hosted Collaboration Mediation Fulfillment (HCM-F) Software could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system. To exploit this vu | 1,2% | — |
| CVE-2018-17184 | MED 5.4 | apache syncope A malicious user with enough administration entitlements can inject html-like elements containing JavaScript statements into Connector names, Report names, AnyTypeClass keys and Policy descriptions. When another user with enough administration entitlements edi | 1,2% | — |
| CVE-2018-5537 | MED 5.3 | f5 big-ip_access_policy_manager A remote attacker may be able to disrupt services on F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.5, 11.6.0-11.6.3.1, or 11.2.1-11.5.6 if the TMM virtual server is configured with a HTML or a Rewrite profile. TMM may restart while processing some specially prepare | 1,2% | — |
| CVE-2017-2336 | CRIT 9.6 | juniper screenos A reflected cross site scripting vulnerability in NetScreen WebUI of Juniper Networks Juniper NetScreen Firewall+VPN running ScreenOS allows a network based attacker to inject HTML/JavaScript content into the management session of other users including the adm | 1,2% | — |
| CVE-2016-10289 | HIGH 7.0 | linux linux_kernel An elevation of privilege vulnerability in the Qualcomm crypto driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process | 1,2% | — |
| CVE-2026-20921 | HIGH 7.5 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network. | 1,2% | — |
| CVE-2025-20156 | CRIT 9.9 | cisco meeting_management A vulnerability in the REST API of Cisco Meeting Management could allow a remote, authenticated attacker with low privileges to elevate privileges to administrator on an affected device. This vulnerability exists because proper authorization is not enforced | 1,2% | — |
| CVE-2024-43613 | HIGH 7.2 | microsoft azure_database_for_postgresql_flexible_server Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability | 1,2% | — |
| CVE-2022-21931 | MED 4.2 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 1,2% | — |
| CVE-2022-21930 | MED 4.2 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 1,2% | — |
| CVE-2018-8561 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka "DirectX Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows Server 2019, Windows Server | 1,2% | — |
| CVE-2018-8485 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka "DirectX Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows Server 2019, Windows Server | 1,2% | — |
| CVE-2018-8471 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Microsoft RemoteFX Virtual GPU miniport driver handles objects in memory, aka "Microsoft RemoteFX Virtual GPU miniport driver Elevation of Privilege Vulnerability." This affects Windows Server | 1,2% | — |
| CVE-2018-8343 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the Network Driver Interface Specification (NDIS) when ndis.sys fails to check the length of a buffer prior to copying memory to it, aka "Windows NDIS Elevation of Privilege Vulnerability." This affects Windows | 1,2% | — |
| CVE-2018-8342 | HIGH 7.8 | microsoft windows_7 An elevation of privilege vulnerability exists in the Network Driver Interface Specification (NDIS) when ndis.sys fails to check the length of a buffer prior to copying memory to it, aka "Windows NDIS Elevation of Privilege Vulnerability." This affects Windows | 1,2% | — |
| CVE-2018-1351 | MED 4.8 | fortinet fortimanager A Cross-site Scripting (XSS) vulnerability in Fortinet FortiManager 6.0.0, 5.6.6 and below versions allows attacker to execute HTML/javascript code via managed remote devices CLI commands by viewing the remote device CLI config installation log. | 1,2% | — |
| CVE-2024-49108 | HIGH 8.1 | microsoft windows_server_2016 Windows Remote Desktop Services Remote Code Execution Vulnerability | 1,2% | — |