EN
58.414 CVE seguite
792 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.414 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più alto In KEV dal, ordina dal più alto
CVE-2021-31380 MED 5.3 juniper session_and_resource_control A configuration weakness in the JBoss Application Server (AppSvr) component of Juniper Networks SRC Series allows a remote attacker to send a specially crafted query to cause the web server to disclose sensitive information in the HTTP response which allows th 1,1% —
CVE-2020-27133 CRIT 9.9 cisco jabber Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated privileges or gain access to sensitive informati 1,1% —
CVE-2019-13399 MED 5.9 fortinet fcm-mb40_firmware Dynacolor FCM-MB40 v1.2.0.0 devices have a hard-coded SSL/TLS key that is used during an administrator's SSL conversation. 1,1% —
CVE-2018-6757 HIGH 7.5 mcafee true_key Privilege Escalation vulnerability in Microsoft Windows client in McAfee True Key (TK) 5.1.230.7 and earlier allows local users to execute arbitrary code via specially crafted malware. 1,1% —
CVE-2018-5197 HIGH 7.8 tobesoft xplatform A vulnerability in the ExtCommon.dll user extension module version 9.2, 9.2.1, 9.2.2 of Xplatform ActiveX could allow attacker to perform a command injection attack. The vulnerability is due to insufficient input validation of command parameters. An crafted ma 1,1% —
CVE-2017-2305 HIGH 8.8 juniper junos_space On Juniper Networks Junos Space versions prior to 16.1R1, due to an insufficient authorization check, readonly users on the Junos Space administrative web interface can create privileged users, allowing privilege escalation. 1,1% —
CVE-2017-0212 HIGH 7.6 microsoft windows_10 Windows Hyper-V allows an elevation of privilege vulnerability when Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 fail to properly validate vSMB packet data, aka "Windows Hyper-V vSMB Elevation of Privilege Vulnerability". 1,1% —
CVE-2023-21560 MED 6.6 microsoft windows_10_1607 Windows Boot Manager Security Feature Bypass Vulnerability 1,1% —
CVE-2021-34791 MED 4.7 cisco adaptive_security_appliance Multiple vulnerabilities in the Application Level Gateway (ALG) for the Network Address Translation (NAT) feature of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to 1,1% —
CVE-2021-34790 MED 4.7 cisco adaptive_security_appliance Multiple vulnerabilities in the Application Level Gateway (ALG) for the Network Address Translation (NAT) feature of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to 1,1% —
CVE-2021-31187 HIGH 7.8 microsoft windows_10 Windows WalletService Elevation of Privilege Vulnerability 1,1% —
CVE-2017-7662 HIGH 8.8 apache cxf_fediz Apache CXF Fediz ships with an OpenId Connect (OIDC) service which has a Client Registration Service, which is a simple web application that allows clients to be created, deleted, etc. A CSRF (Cross Style Request Forgery) style vulnerability has been found in 1,1% —
CVE-2026-33111 HIGH 7.5 microsoft copilot_chat Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network. 1,1% —
CVE-2026-26129 HIGH 7.5 microsoft 365_copilot_chat Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network. 1,1% —
CVE-2020-3410 HIGH 8.1 cisco secure_firewall_management_center A vulnerability in the Common Access Card (CAC) authentication feature of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and access the FMC system. The attacker must have a valid CAC to 1,1% —
CVE-2020-2031 MED 4.9 paloaltonetworks pan-os An integer underflow vulnerability in the dnsproxyd component of the PAN-OS management interface allows authenticated administrators to issue a command from the command line interface that causes the component to stop responding. Repeated attempts to send this 1,1% —
CVE-2016-1404 HIGH 7.5 cisco ucs_invicta_c3124sa_appliance Cisco UCS Invicta 4.3, 4.5, and 5.0.1 on Invicta appliances and Invicta Scaling System uses the same hardcoded GnuPG encryption key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms by sniffi 1,1% —
CVE-2011-3317 MED 4.3 cisco secure_access_control_server Multiple cross-site scripting (XSS) vulnerabilities in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCtr78192. 1,1% —
CVE-2024-43394 HIGH 7.5 apache http_server Server-Side Request Forgery (SSRF) in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via  mod_rewrite or apache expressions that pass unvalidated request input. This issue affects Apache HTTP Server: from 2.4.0 thro 1,1% —
CVE-2024-37325 HIGH 8.1 microsoft azure_data_science_virtual_machine Azure Science Virtual Machine (DSVM) Elevation of Privilege Vulnerability 1,1% —
CVE-2023-36387 MED 5.4 apache superset An improper default REST API permission for Gamma users in Apache Superset up to and including 2.1.0 allows for an authenticated Gamma user to test database connections. 1,1% —
CVE-2022-33632 MED 4.7 microsoft 365_apps Microsoft Office Security Feature Bypass Vulnerability 1,1% —
CVE-2022-30137 MED 6.7 microsoft service_fabric Executive Summary An Elevation of Privilege (EOP) vulnerability has been identified within Service Fabric clusters that run Docker containers. Exploitation of this EOP vulnerability requires an attacker to gain remote code execution within a container. All S 1,1% —
CVE-2021-29798 CRIT 9.8 ibm sterling_b2b_integrator IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end databa 1,1% —
CVE-2021-22022 MED 4.9 vmware cloud_foundation The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary file read vulnerability. A malicious actor with administrative access to vRealize Operations Manager API can read any arbitrary file on server leading to information disclosure. 1,1% —