57.808 CVE seguite
783 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.808 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2014-3115 | MED 6.8 | fortinet fortiweb Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration console in Fortinet FortiWeb before 5.2.0 allow remote attackers to hijack the authentication of administrators via system/config/adminadd and other unspecified vectors. | 1,2% | — |
| CVE-2008-1744 | HIGH 7.8 | cisco unified_callmanager The Certificate Authority Proxy Function (CAPF) service in Cisco Unified Communications Manager (CUCM) 4.1 before 4.1(3)SR7, 4.2 before 4.2(3)SR4, and 4.3 before 4.3(2) allows remote attackers to cause a denial of service (service crash) via malformed network | 1,2% | — |
| CVE-2008-1742 | HIGH 7.8 | cisco unified_communications_manager Memory leak in the Certificate Trust List (CTL) Provider service in Cisco Unified Communications Manager (CUCM) 5.x before 5.1(3) allows remote attackers to cause a denial of service (memory consumption and service interruption) via a series of malformed TCP p | 1,2% | — |
| CVE-2024-30074 | HIGH 8.0 | microsoft windows_server_2008 Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability | 1,2% | — |
| CVE-2022-22483 | MED 6.5 | ibm db2 IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to an information disclosure in some scenarios due to unauthorized access caused by improper privilege management when CREATE OR REPLACE command is used. IBM X-Force ID: 225979. | 1,2% | — |
| CVE-2021-27074 | MED 6.2 | microsoft azure_sphere Azure Sphere Unsigned Code Execution Vulnerability | 1,2% | — |
| CVE-2021-1724 | MED 6.1 | microsoft dynamics_365_business_central Microsoft Dynamics Business Central Cross-site Scripting Vulnerability | 1,2% | — |
| CVE-2019-0733 | MED 5.3 | microsoft windows_10 A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement, aka 'Windows Defender Application Control Security Feature Bypass Vulnerability'. | 1,2% | — |
| CVE-2018-15329 | HIGH 7.2 | f5 big-ip_access_policy_manager On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.1, or 12.1.0-12.1.3.7, or Enterprise Manager 3.1.1, when authenticated administrative users run commands in the Traffic Management User Interface (TMUI), also referred to as the BIG-IP Configuration utility, restriction | 1,2% | — |
| CVE-2018-15327 | HIGH 7.2 | f5 big-ip_access_policy_manager In BIG-IP 14.0.0-14.0.0.2 or 13.0.0-13.1.1.1 or Enterprise Manager 3.1.1, when authenticated administrative users run commands in the Traffic Management User Interface (TMUI), also referred to as the BIG-IP Configuration utility, restrictions on allowed comman | 1,2% | — |
| CVE-2018-8224 | HIGH 7.0 | microsoft windows_7 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "Windows Kernel Elevation of Privilege Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2. | 1,2% | — |
| CVE-2018-8169 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists when the (Human Interface Device) HID Parser Library driver improperly handles objects in memory, aka "HIDParser Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8. | 1,2% | — |
| CVE-2017-9794 | MED 4.3 | apache geode When a cluster is operating in secure mode, a user with read privileges for specific data regions can use the gfsh command line utility to execute queries. In Apache Geode before 1.2.1, the query results may contain data from another user's concurrently execut | 1,2% | — |
| CVE-2014-3264 | MED 6.3 | cisco adaptive_security_appliance_software Cisco Adaptive Security Appliance (ASA) Software 9.1(.5) and earlier allows remote authenticated users to cause a denial of service (device reload) via crafted attributes in a RADIUS packet, aka Bug ID CSCun69561. | 1,2% | — |
| CVE-2014-0704 | HIGH 7.1 | cisco wireless_lan_controller The IGMP implementation on Cisco Wireless LAN Controller (WLC) devices 4.x, 5.x, 6.x, 7.0 before 7.0.250.0, 7.1, 7.2, and 7.3, when IGMPv3 Snooping is enabled, allows remote attackers to cause a denial of service (memory over-read and device restart) via a cra | 1,2% | — |
| CVE-2008-4545 | MED 4.0 | cisco unity Cisco Unity 4.x before 4.2(1)ES161, 5.x before 5.0(1)ES53, and 7.x before 7.0(2)ES8 uses weak permissions for the D:\CommServer\Reports directory, which allows remote authenticated users to obtain sensitive information by reading files in this directory. | 1,2% | — |
| CVE-1999-1367 | MED 4.6 | microsoft internet_explorer Internet Explorer 5.0 does not properly reset the username/password cache for Web sites that do not use standard cache controls, which could allow users on the same system to access restricted web sites that were visited by other users. | 1,2% | — |
| CVE-2026-24308 | HIGH 7.5 | apache zookeeper Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all platforms allows an attacker to expose sensitive information stored in client configuration in the client's logfile. Configuration values are exposed at INFO level | 1,2% | — |
| CVE-2024-50919 | CRIT 9.8 | jpress jpress Jpress until v5.1.1 has arbitrary file uploads on the windows platform, and the construction of non-standard file formats such as .jsp. can lead to arbitrary command execution | 1,2% | — |
| CVE-2024-43615 | HIGH 7.1 | microsoft windows_10_1809 Microsoft OpenSSH for Windows Remote Code Execution Vulnerability | 1,2% | — |
| CVE-2021-47308 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: scsi: libfc: Fix array index out of bound exception Fix array index out of bound exception in fc_rport_prli_resp(). | 1,2% | — |
| CVE-2024-35955 | HIGH 8.8 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: kprobes: Fix possible use-after-free issue on kprobe registration When unloading a module, its state is changing MODULE_STATE_LIVE -> MODULE_STATE_GOING -> MODULE_STATE_UNFORMED. Each chang | 1,2% | — |
| CVE-2023-52160 | MED 6.5 | debian debian_linux The implementation of PEAP in wpa_supplicant through 2.10 allows authentication bypass. For a successful attack, wpa_supplicant must be configured to not verify the network's TLS certificate during Phase 1 authentication, and an eap_peap_decrypt vulnerability | 1,2% | — |
| CVE-2023-46838 | HIGH 7.5 | debian debian_linux Transmit requests in Xen's virtual network protocol can consist of multiple parts. While not really useful, except for the initial part any of them may be of zero length, i.e. carry no data at all. Besides a certain initial portion of the to be transferred d | 1,2% | — |
| CVE-2023-33130 | HIGH 7.3 | microsoft sharepoint_server Microsoft SharePoint Server Spoofing Vulnerability | 1,2% | — |