58.507 CVE seguite
793 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.507 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2023-33128 | HIGH 7.3 | microsoft .net .NET and Visual Studio Remote Code Execution Vulnerability | 1,0% | — |
| CVE-2023-33126 | HIGH 7.3 | microsoft .net .NET and Visual Studio Remote Code Execution Vulnerability | 1,0% | — |
| CVE-2022-20846 | MED 4.3 | cisco ios_xr A vulnerability in the Cisco Discovery Protocol implementation for Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause the Cisco Discovery Protocol process to reload on an affected device. This vulnerability is due | 1,0% | — |
| CVE-2021-36184 | HIGH 8.8 | fortinet fortiwlm A improper neutralization of Special Elements used in an SQL Command ('SQL Injection') in Fortinet FortiWLM version 8.6.1 and below allows attacker to disclosure device, users and database information via crafted HTTP requests. | 1,0% | — |
| CVE-2021-34754 | MED 5.8 | cisco secure_firewall_management_center Multiple vulnerabilities in the payload inspection for Ethernet Industrial Protocol (ENIP) traffic for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured rules for ENIP traffic. These vulnerabilit | 1,0% | — |
| CVE-2021-34696 | MED 5.8 | cisco ios_xe A vulnerability in the access control list (ACL) programming of Cisco ASR 900 and ASR 920 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to incorrect programming of hard | 1,0% | — |
| CVE-2021-22023 | HIGH 7.2 | vmware cloud_foundation The vRealize Operations Manager API (8.x prior to 8.5) has insecure object reference vulnerability. A malicious actor with administrative access to vRealize Operations Manager API may be able to modify other users information leading to an account takeover. | 1,0% | — |
| CVE-2021-21682 | MED 4.3 | jenkins jenkins Jenkins 2.314 and earlier, LTS 2.303.1 and earlier accepts names of jobs and other entities with a trailing dot character, potentially replacing the configuration and data of other entities on Windows. | 1,0% | — |
| CVE-2021-1591 | MED 5.8 | cisco nx-os A vulnerability in the EtherChannel port subscription logic of Cisco Nexus 9500 Series Switches could allow an unauthenticated, remote attacker to bypass access control list (ACL) rules that are configured on an affected device. This vulnerability is due to ov | 1,0% | — |
| CVE-2020-5022 | MED 5.3 | ibm spectrum_protect_plus IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may allow unauthenticated and unauthorized access to VDAP proxy which can result in an attacker obtaining information they are not authorized to access. IBM X-Force ID: 193658. | 1,0% | — |
| CVE-2020-10942 | MED 5.3 | canonical ubuntu_linux In the Linux kernel before 5.5.8, get_raw_socket in drivers/vhost/net.c lacks validation of an sk_family field, which might allow attackers to trigger kernel stack corruption via crafted system calls. | 1,0% | — |
| CVE-2019-15712 | HIGH 7.2 | fortinet fortimail An improper access control vulnerability in FortiMail admin webUI 6.2.0, 6.0.0 to 6.0.6, 5.4.10 and below may allow administrators to access web console they should not be authorized for. | 1,0% | — |
| CVE-2017-8580 | HIGH 7.0 | microsoft windows_10 Win32k in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability when it fails to | 1,0% | — |
| CVE-2017-7151 | HIGH 7.0 | apple iphone_os A race condition was addressed with additional validation. This issue affected versions prior to iOS 11.2, macOS High Sierra 10.13.2, tvOS 11.2, watchOS 4.2, iTunes 12.7.2 for Windows, macOS High Sierra 10.13.4. | 1,0% | — |
| CVE-2024-38211 | HIGH 8.2 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 1,0% | — |
| CVE-2022-30176 | HIGH 7.8 | microsoft azure_real_time_operating_system_guix_studio Azure RTOS GUIX Studio Remote Code Execution Vulnerability | 1,0% | — |
| CVE-2021-23005 | CRIT 9.1 | f5 big-iq_centralized_management On all 7.x and 6.x versions (fixed in 8.0.0), when using a Quorum device for BIG-IQ high availability (HA) for automatic failover, BIG-IQ does not make use of Transport Layer Security (TLS) with the Corosync protocol. Note: Software versions which have reached | 1,0% | — |
| CVE-2020-1975 | MED 6.8 | paloaltonetworks pan-os Missing XML validation vulnerability in the PAN-OS web interface on Palo Alto Networks PAN-OS software allows authenticated users to inject arbitrary XML that results in privilege escalation. This issue affects PAN-OS 8.1 versions earlier than PAN-OS 8.1.12 an | 1,0% | — |
| CVE-2020-17001 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 1,0% | — |
| CVE-2020-1661 | MED 5.3 | juniper junos On Juniper Networks Junos OS devices configured as a DHCP forwarder, the Juniper Networks Dynamic Host Configuration Protocol Daemon (jdhcp) process might crash when receiving a malformed DHCP packet. This issue only affects devices configured as DHCP forwarde | 1,0% | — |
| CVE-2019-6678 | MED 5.3 | f5 big-ip_access_policy_manager On BIG-IP versions 15.0.0-15.0.1, 14.1.0-14.1.2.2, 14.0.0-14.0.1, and 13.1.0-13.1.3.1, the TMM process may restart when the packet filter feature is enabled. | 1,0% | — |
| CVE-2019-16156 | MED 6.1 | fortinet fortiweb An Improper Neutralization of Input vulnerability in the Anomaly Detection Parameter Name in Fortinet FortiWeb 6.0.5, 6.2.0, and 6.1.1 may allow a remote unauthenticated attacker to perform a Cross Site Scripting attack (XSS). | 1,0% | — |
| CVE-2019-12415 | MED 5.5 | apache poi In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External En | 1,0% | — |
| CVE-2018-8599 | HIGH 7.8 | microsoft visual_studio An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly impersonates certain file operations, aka "Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability." This affects Microsoft Vi | 1,0% | — |
| CVE-2016-6034 | MED 6.8 | ibm tivoli_storage_manager_for_virtual_environments_data_protection_for_vmware IBM Tivoli Storage Manager for Virtual Environments (VMware) could disclose the Windows domain credentials to a user with a high level of privileges. | 1,0% | — |