57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.971 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più alto |
|---|---|---|---|---|
| CVE-2025-0320 | HIGH 7.8 | citrix secure_access_client Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Secure Access Client for Windows | 0,1% | — |
| CVE-2025-0158 | MED 5.5 | ibm entirex IBM EntireX 11.1 could allow a local user to cause a denial of service due to an unhandled error and fault isolation. | 0,1% | — |
| CVE-2025-0154 | MED 5.3 | ibm txseries_for_multiplatforms IBM TXSeries for Multiplatforms 9.1 and 11.1 could disclose sensitive information to a remote attacker due to improper neutralization of HTTP headers. | 0,4% | — |
| CVE-2025-0135 | LOW 3.3 | paloaltonetworks globalprotect An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on macOS devices enables a locally authenticated non administrative user to disable the app. The GlobalProtect app on Windows, Linux, iOS, Android, Chrome OS and Glob | 0,1% | — |
| CVE-2025-0130 | HIGH 7.5 | paloaltonetworks pan-os A missing exception check in Palo Alto Networks PAN-OS® software with the web proxy feature enabled allows an unauthenticated attacker to send a burst of maliciously crafted packets that causes the firewall to become unresponsive and eventually reboot. Repeate | 0,4% | — |
| CVE-2025-0124 | LOW 3.8 | paloaltonetworks pan-os An authenticated file deletion vulnerability in the Palo Alto Networks PAN-OS® software enables an authenticated attacker with network access to the management web interface to delete certain files as the “nobody” user; this includes limited logs and configura | 0,3% | — |
| CVE-2025-0120 | HIGH 7.0 | paloaltonetworks globalprotect A vulnerability with a privilege management mechanism in the Palo Alto Networks GlobalProtect™ app on Windows devices allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY\SYSTEM. However, execution require | 0,2% | — |
| CVE-2025-0118 | HIGH 8.0 | paloaltonetworks globalprotect A vulnerability in the Palo Alto Networks GlobalProtect app on Windows allows a remote attacker to run ActiveX controls within the context of an authenticated Windows user. This enables the attacker to run commands as if they are a legitimate authenticated use | 0,4% | — |
| CVE-2025-0114 | HIGH 7.5 | paloaltonetworks pan-os A Denial of Service (DoS) vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software enables an unauthenticated attacker to render the service unavailable by sending a large number of specially crafted packets over a period of time. This | 0,4% | — |
| CVE-2025-0107 | CRIT 9.8 | paloaltonetworks expedition An OS command injection vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to run arbitrary OS commands as the www-data user in Expedition, which results in the disclosure of usernames, cleartext passwords, device configurations | 78,5% | — |
| CVE-2025-0106 | MED 5.3 | paloaltonetworks expedition A wildcard expansion vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to enumerate files on the host filesystem. | 0,5% | — |
| CVE-2025-0105 | CRIT 9.1 | paloaltonetworks expedition An arbitrary file deletion vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to delete arbitrary files accessible to the www-data user on the host filesystem. | 13,3% | — |
| CVE-2025-0104 | MED 6.1 | paloaltonetworks expedition A reflected cross-site scripting (XSS) vulnerability in Palo Alto Networks Expedition enables attackers to execute malicious JavaScript code in the context of an authenticated Expedition user’s browser if that authenticated user clicks a malicious link that al | 0,4% | — |
| CVE-2025-0103 | HIGH 8.8 | paloaltonetworks expedition An SQL injection vulnerability in Palo Alto Networks Expedition enables an authenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. This vulnerability also enables attackers | 0,6% | — |
| CVE-2024-9965 | HIGH 8.8 | google chrome Insufficient data validation in DevTools in Google Chrome on Windows prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low) | 0,5% | — |
| CVE-2024-9950 | HIGH 7.8 | forescout secureconnector A vulnerability in Forescout SecureConnector v11.3.07.0109 on Windows allows unauthenticated user to modify compliance scripts due to insecure temporary directory. | 0,3% | — |
| CVE-2024-9949 | MED 6.1 | forescout secureconnector Denial of Service in Forescout SecureConnector 11.1.02.1019 on Windows allows Unprivileged user to corrupt the configuration file and cause Denial of Service in the application. | 0,1% | — |
| CVE-2024-9842 | HIGH 7.3 | ivanti secure_access_client Incorrect permissions in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to create arbitrary folders. | 0,2% | — |
| CVE-2024-9827 | HIGH 7.8 | autodesk autocad A maliciously crafted CATPART file when parsed in CC5Dll.dll through Autodesk AutoCAD can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the cont | 0,2% | — |
| CVE-2024-9826 | HIGH 7.8 | autodesk autocad A maliciously crafted 3DM file when parsed in atf_api.dll through Autodesk AutoCAD can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of t | 0,2% | — |
| CVE-2024-9473 | HIGH 7.8 | paloaltonetworks globalprotect A privilege escalation vulnerability in the Palo Alto Networks GlobalProtect app on Windows allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY/SYSTEM through the use of the repair functionality offered b | 0,3% | — |
| CVE-2024-9471 | MED 4.7 | paloaltonetworks pan-os A privilege escalation (PE) vulnerability in the XML API of Palo Alto Networks PAN-OS software enables an authenticated PAN-OS administrator with restricted privileges to use a compromised XML API key to perform actions as a higher privileged PAN-OS administra | 0,3% | — |
| CVE-2024-9469 | MED 5.5 | paloaltonetworks cortex_xdr_agent A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows non-administrative privileges to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then t | 0,2% | — |
| CVE-2024-9468 | HIGH 7.5 | paloaltonetworks pan-os A memory corruption vulnerability in Palo Alto Networks PAN-OS software allows an unauthenticated attacker to crash PAN-OS due to a crafted packet through the data plane, resulting in a denial of service (DoS) condition. Repeated attempts to trigger this condi | 0,4% | — |
| CVE-2024-9467 | MED 6.1 | paloaltonetworks expedition A reflected XSS vulnerability in Palo Alto Networks Expedition enables execution of malicious JavaScript in the context of an authenticated Expedition user's browser if that user clicks on a malicious link, allowing phishing attacks that could lead to Expediti | 0,6% | — |