EN
58.441 CVE seguite
792 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.441 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più alto In KEV dal, ordina dal più alto
CVE-2022-34723 MED 5.5 microsoft windows_11 Windows DPAPI (Data Protection Application Programming Interface) Information Disclosure Vulnerability 1,1% —
CVE-2020-5862 HIGH 7.5 f5 big-ip_access_policy_manager On BIG-IP 15.1.0-15.1.0.1, 15.0.0-15.0.1.1, and 14.1.0-14.1.2.2, under certain conditions, TMM may crash or stop processing new traffic with the DPDK/ENA driver on AWS systems while sending traffic. This issue does not affect any other platforms, hardware or v 1,1% —
CVE-2019-1185 HIGH 7.3 microsoft windows_10 An elevation of privilege vulnerability exists due to a stack corruption in Windows Subsystem for Linux. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally authenticate 1,1% —
CVE-2017-12630 MED 5.4 apache drill In Apache Drill 1.11.0 and earlier when submitting form from Query page users are able to pass arbitrary script or HTML which will take effect on Profile page afterwards. Example: after submitting special script that returns cookie information from Query page, 1,1% —
CVE-2025-24860 MED 5.4 apache cassandra Incorrect Authorization vulnerability in Apache Cassandra allowing users to access a datacenter or IP/CIDR groups they should not be able to when using CassandraNetworkAuthorizer or CassandraCIDRAuthorizer. Users with restricted data center access can update 1,1% —
CVE-2024-49120 HIGH 8.1 microsoft windows_server_2012 Windows Remote Desktop Services Remote Code Execution Vulnerability 1,1% —
CVE-2023-21717 HIGH 8.8 microsoft sharepoint_enterprise_server Microsoft SharePoint Server Elevation of Privilege Vulnerability 1,1% —
CVE-2021-34707 MED 6.5 cisco evolved_programmable_network_manager A vulnerability in the REST API of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to access sensitive data on an affected system. This vulnerability exists because the application does not sufficiently protect s 1,1% —
CVE-2021-28316 MED 4.2 microsoft windows_10 Windows WLAN AutoConfig Service Security Feature Bypass Vulnerability 1,1% —
CVE-2021-22129 HIGH 8.8 fortinet fortimail Multiple instances of incorrect calculation of buffer size in the Webmail and Administrative interface of FortiMail before 6.4.5 may allow an authenticated attacker with regular webmail access to trigger a buffer overflow and to possibly execute unauthorized c 1,1% —
CVE-2020-3484 MED 5.3 cisco vision_dynamic_signage_director A vulnerability in the web-based management interface of Cisco Vision Dynamic Signage Director could allow an unauthenticated, remote attacker to view potentially sensitive information on an affected device. The vulnerability is due to incorrect permissions wi 1,1% —
CVE-2013-2854 HIGH 7.5 google chrome Google Chrome before 27.0.1453.110 on Windows provides an incorrect handle to a renderer process in unspecified circumstances, which allows remote attackers to cause a denial of service or possibly have other impact via unknown vectors. 1,1% —
CVE-2025-49813 HIGH 7.2 fortinet fortiadc An improper neutralization of special elements used in an OS Command ("OS Command Injection") vulnerability [CWE-78] in Fortinet FortiADC version 7.2.0 and before 7.1.1 allows a remote and authenticated attacker with low privilege to execute unauthorized code 1,1% —
CVE-2024-43550 HIGH 7.4 microsoft windows_10_1507 Windows Secure Channel Spoofing Vulnerability 1,1% —
CVE-2022-21887 HIGH 7.0 microsoft windows_11 Win32k Elevation of Privilege Vulnerability 1,1% —
CVE-2019-1713 HIGH 8.1 cisco adaptive_security_appliance_software A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to i 1,1% —
CVE-2019-1665 MED 4.7 cisco hyperflex_hx_data_platform A vulnerability in the web-based management interface of Cisco HyperFlex software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected system. The vul 1,1% —
CVE-2019-1341 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when umpo.dll of the Power Service, improperly handles a Registry Restore Key function, aka 'Windows Power Service Elevation of Privilege Vulnerability'. 1,1% —
CVE-2018-0435 CRIT 9.1 cisco umbrella A vulnerability in the Cisco Umbrella API could allow an authenticated, remote attacker to view and modify data across their organization and other organizations. The vulnerability is due to insufficient authentication configurations for the API interface of C 1,1% —
CVE-2014-8032 MED 4.0 cisco webex_meetings_server The OutlookAction LI in Cisco WebEx Meetings Server allows remote authenticated users to obtain sensitive encrypted-password information via unspecified vectors, aka Bug IDs CSCuj40453 and CSCuj40449. 1,1% —
CVE-2011-2546 MED 5.0 cisco sa500_software SQL injection vulnerability in the web-based management interface on Cisco SA 500 series security appliances with software before 2.1.19 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCtq65669. 1,1% —
CVE-2008-5079 MED 4.9 linux linux_kernel net/atm/svc.c in the ATM subsystem in the Linux kernel 2.6.27.8 and earlier allows local users to cause a denial of service (kernel infinite loop) by making two calls to svc_listen for the same socket, and then reading a /proc/net/atm/*vc file, related to corr 1,1% —
CVE-1999-0157 MED 5.0 cisco ios Cisco PIX firewall and CBAC IP fragmentation attack results in a denial of service. 1,1% —
CVE-2025-49217 CRIT 9.8 trendmicro trend_micro_endpoint_encryption An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49213 but is in a different method 1,1% —
CVE-2025-30392 CRIT 9.8 microsoft azure_ai_bot_service Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network. 1,1% —