58.450 CVE seguite
792 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.450 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-20967 | HIGH 8.8 | microsoft system_center_operations_manager Improper input validation in System Center Operations Manager allows an authorized attacker to elevate privileges over a network. | 1,1% | — |
| CVE-2025-66518 | HIGH 8.8 | apache kyuubi Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allow.list and use local files which are not listed in the config. This issue affects Apache Kyuubi: from 1.6.0 through 1.10 | 1,1% | — |
| CVE-2024-49071 | MED 6.5 | microsoft defender_for_endpoint Improper authorization of an index that contains sensitive information from a Global Files search in Windows Defender allows an authorized attacker to disclose information over a network. | 1,1% | — |
| CVE-2022-41746 | CRIT 9.1 | trendmicro apex_one A forced browsing vulnerability in Trend Micro Apex One could allow an attacker with access to the Apex One console on affected installations to escalate privileges and modify certain agent groupings. Please note: an attacker must first obtain the ability to l | 1,1% | — |
| CVE-2022-21846 | CRIT 9.0 | microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 1,1% | — |
| CVE-2020-7858 | MED 6.8 | cdnetworks aquanplayer There is a directory traversing vulnerability in the download page url of AquaNPlayer 2.0.0.92. The IP of the download page url is localhost and an attacker can traverse directories using "dot dot" sequences(../../) to view host file on the system. This vulner | 1,1% | — |
| CVE-2020-5427 | HIGH 7.2 | vmware spring_cloud_data_flow In Spring Cloud Data Flow, versions 2.6.x prior to 2.6.5, versions 2.5.x prior 2.5.4, an application is vulnerable to SQL injection when requesting task execution. | 1,1% | — |
| CVE-2020-1684 | HIGH 7.5 | juniper junos On Juniper Networks SRX Series configured with application identification inspection enabled, receipt of specific HTTP traffic can cause high CPU load utilization, which could lead to traffic interruption. Application identification is enabled by default and i | 1,1% | — |
| CVE-2019-6655 | MED 5.3 | f5 big-ip_access_policy_manager On versions 13.0.0-13.1.0.1, 12.1.0-12.1.4.1, 11.6.1-11.6.4, and 11.5.1-11.5.9, BIG-IP platforms where AVR, ASM, APM, PEM, AFM, and/or AAM is provisioned may leak sensitive data. | 1,1% | — |
| CVE-2018-0116 | HIGH 7.2 | cisco mobility_services_engine A vulnerability in the RADIUS authentication module of Cisco Policy Suite could allow an unauthenticated, remote attacker to be authorized as a subscriber without providing a valid password; however, the attacker must provide a valid username. The vulnerabilit | 1,1% | — |
| CVE-2017-6658 | HIGH 7.5 | cisco sourcefire_snort Cisco Sourcefire Snort 3.0 before build 233 has a Buffer Overread related to use of a decoder array. The size was off by one making it possible to read past the end of the array with an ether type of 0xFFFF. Increasing the array size solves this problem. | 1,1% | — |
| CVE-2017-6657 | HIGH 7.5 | cisco snort\+\+ Cisco Sourcefire Snort 3.0 before build 233 mishandles Ether Type Validation. Since valid ether type and IP protocol numbers do not overlap, Snort++ stores all protocol decoders in a single array. That makes it possible to craft packets that have IP protocol n | 1,1% | — |
| CVE-2013-1121 | MED 5.4 | cisco nx-os The regex engine in the BGP implementation in Cisco NX-OS, when a complex regular expression is configured for inbound routes, allows remote attackers to cause a denial of service (device reload) via a crafted AS path set, aka Bug ID CSCuf49554. | 1,1% | — |
| CVE-2011-2561 | HIGH 7.1 | cisco unified_communications_manager The SIP process in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 7.x before 7.1(5b)su4 and 8.x before 8.0(1) does not properly handle SDP data within a SIP call in certain situations related to use of the g729ar8 codec for a Media Termi | 1,1% | — |
| CVE-2010-2981 | HIGH 7.1 | cisco unified_wireless_network_solution_software Cisco Unified Wireless Network (UWN) Solution 7.x before 7.0.98.0 allows remote attackers to cause a denial of service (device crash) by pinging a virtual interface, aka Bug ID CSCte55370. | 1,1% | — |
| CVE-2005-1837 | HIGH 7.5 | fortinet fortinet_firewall Fortinet firewall running FortiOS 2.x contains a hardcoded username with the password set to the serial number, which allows local users with console access to gain privileges. | 1,1% | — |
| CVE-1999-0230 | MED 5.0 | cisco ios Buffer overflow in Cisco 7xx routers through the telnet service. | 1,1% | — |
| CVE-2025-20374 | MED 4.9 | cisco unified_contact_center_express A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to perform a directory traversal and access arbitrary resources. This vulnerability is due to an insufficient input validation associated to specific UI feature | 1,1% | — |
| CVE-2023-36639 | HIGH 7.2 | fortinet fortios A use of externally-controlled format string in Fortinet FortiProxy versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.10, FortiOS versions 7.4.0, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiPA | 1,1% | — |
| CVE-2022-41121 | HIGH 7.8 | microsoft powershell Windows Graphics Component Elevation of Privilege Vulnerability | 1,1% | — |
| CVE-2022-3910 | HIGH 7.8 | linux linux_kernel Use After Free vulnerability in Linux Kernel allows Privilege Escalation. An improper Update of Reference Count in io_uring leads to Use-After-Free and Local Privilege Escalation. When io_msg_ring was invoked with a fixed file, it called io_fput_file() which i | 1,1% | — |
| CVE-2022-34719 | HIGH 7.8 | microsoft windows_10 Windows Distributed File System (DFS) Elevation of Privilege Vulnerability | 1,1% | — |
| CVE-2022-21897 | HIGH 7.8 | microsoft windows_10 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 1,1% | — |
| CVE-2020-5864 | HIGH 7.4 | f5 nginx_controller In versions of NGINX Controller prior to 3.2.0, communication between NGINX Controller and NGINX Plus instances skip TLS verification by default. | 1,1% | — |
| CVE-2017-10887 | HIGH 7.8 | bookwalker book_walker Untrusted search path vulnerability in BOOK WALKER for Windows Ver.1.2.9 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | 1,1% | — |