57.808 CVE seguite
783 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.808 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2014-2157 | HIGH 7.1 | cisco tandberg_2000_mxp Cisco TelePresence System MXP Series Software before F9.3.1 allows remote attackers to cause a denial of service (device reload) via crafted SIP packets, aka Bug ID CSCty45733. | 1,2% | — |
| CVE-2014-2156 | HIGH 7.1 | cisco tandberg_2000_mxp Cisco TelePresence System MXP Series Software before F9.3.1 allows remote attackers to cause a denial of service (device reload) via crafted SIP packets, aka Bug ID CSCty45739. | 1,2% | — |
| CVE-2014-0720 | HIGH 7.1 | cisco ips_sensor_software Cisco IPS Software 7.1 before 7.1(8)E4 and 7.2 before 7.2(2)E4 allows remote attackers to cause a denial of service (Analysis Engine process outage) via a flood of jumbo frames, aka Bug ID CSCuh94944. | 1,2% | — |
| CVE-2014-0734 | HIGH 7.5 | cisco unified_communications_manager SQL injection vulnerability in the Certificate Authority Proxy Function (CAPF) implementation in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote attackers to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCum | 1,2% | — |
| CVE-2013-5482 | MED 4.3 | cisco prime_lan_management_solution Cisco Prime LAN Management Solution (LMS) does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "cross-frame scripting (X | 1,2% | — |
| CVE-2013-1176 | HIGH 7.1 | cisco telepresence_mcu_4500_series_software The DSP card on Cisco TelePresence MCU 4500 and 4501 devices before 4.3(2.30), TelePresence MCU MSE 8510 devices before 4.3(2.30), and TelePresence Server before 2.3(1.55) does not properly validate H.264 data, which allows remote attackers to cause a denial o | 1,2% | — |
| CVE-2023-36871 | MED 6.5 | microsoft windows_10_1507 Azure Active Directory Security Feature Bypass Vulnerability | 1,2% | — |
| CVE-2020-7822 | HIGH 7.8 | hmtalk daviewindy DaviewIndy has a Heap-based overflow vulnerability, triggered when the user opens a malformed image file that is mishandled by Daview.exe. Attackers could exploit this and arbitrary code execution. | 1,2% | — |
| CVE-2020-7803 | HIGH 7.8 | imgtech zoneplayer IMGTech Co,Ltd ZInsX.ocx ActiveX Control in Zoneplayer 2.0.1.3, version 2.0.1.4 and prior versions on Windows. File Donwload vulnerability in ZInsX.ocx of IMGTech Co,Ltd Zoneplayer allows attacker to cause arbitrary code execution. | 1,2% | — |
| CVE-2019-1583 | HIGH 8.0 | paloaltonetworks twistlock Escalation of privilege vulnerability in the Palo Alto Networks Twistlock console 19.07.358 and earlier allows a Twistlock user with Operator capabilities to escalate privileges to that of another user. Active interaction with an affected component is required | 1,2% | — |
| CVE-2018-0210 | HIGH 8.8 | cisco data_center_network_manager A vulnerability in the web-based management interface of Cisco Data Center Network Manager could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerabil | 1,2% | — |
| CVE-2018-6811 | MED 6.1 | citrix netscaler_application_delivery_controller_firmware Multiple cross-site scripting (XSS) vulnerabilities in Citrix NetScaler ADC 10.5, 11.0, 11.1, and 12.0, and NetScaler Gateway 10.5, 11.0, 11.1, and 12.0 allow remote attackers to inject arbitrary web script or HTML via the Citrix NetScaler interface. | 1,2% | — |
| CVE-2017-12253 | HIGH 8.8 | cisco unified_intelligence_center A vulnerability in the Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to execute unwanted actions. The vulnerability is due to a lack of cross-site request forgery (CSRF) protection. An attacker could exploit this vulnerabili | 1,2% | — |
| CVE-2016-6468 | HIGH 8.8 | cisco emergency_responder A vulnerability in the web-based management interface of Cisco Emergency Responder could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. More Information: CSCv | 1,2% | — |
| CVE-2014-3601 | MED 4.3 | canonical ubuntu_linux The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through 3.16.1 miscalculates the number of pages during the handling of a mapping failure, which allows guest OS users to (1) cause a denial of service (host OS memory corruption) or poss | 1,2% | — |
| CVE-2011-1887 | HIGH 7.8 | microsoft windows_7 win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a | 1,2% | — |
| CVE-2024-31867 | MED 6.5 | apache zeppelin Improper Input Validation vulnerability in Apache Zeppelin. The attackers can execute malicious queries by setting improper configuration properties to LDAP search filter. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1. Users are recommended to | 1,2% | — |
| CVE-2023-29352 | MED 6.5 | microsoft remote_desktop_client Windows Remote Desktop Security Feature Bypass Vulnerability | 1,2% | — |
| CVE-2021-31353 | HIGH 7.5 | juniper junos An Improper Handling of Exceptional Conditions vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows an attacker to inject a specific BGP update, causing the routing protocol daemon (RPD) to crash and restart, leading to a Denial of Service (D | 1,2% | — |
| CVE-2017-5075 | MED 4.3 | google chrome Inappropriate implementation in CSP reporting in Blink in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to obtain the value of url fragments via a crafted HTML page. | 1,2% | — |
| CVE-2016-4927 | HIGH 8.1 | juniper junos_space Insufficient validation of SSH keys in Junos Space before 15.2R2 allows man-in-the-middle (MITM) type of attacks while a Space device is communicating with managed devices. | 1,2% | — |
| CVE-1999-0824 | MED 4.6 | microsoft windows_nt A Windows NT user can use SUBST to map a drive letter to a folder, which is not unmapped after the user logs off, potentially allowing that user to modify the location of folders accessed by later users. | 1,2% | — |
| CVE-1999-0384 | MED 4.6 | microsoft office The Forms 2.0 ActiveX control (included with Visual Basic for Applications 5.0) can be used to read text from a user's clipboard when the user accesses documents with ActiveX content. | 1,2% | — |
| CVE-2026-48286 | CRIT 10.0 | adobe campaign Adobe Campaign Classic (ACC) versions 7.4.3 build 9396 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user inter | 1,2% | — |
| CVE-2025-24994 | HIGH 7.3 | microsoft windows_11_22h2 Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally. | 1,2% | — |