58.507 CVE seguite
793 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.507 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2014-3394 | MED 5.0 | cisco adaptive_security_appliance_software The Smart Call Home (SCH) implementation in Cisco ASA Software 8.2 before 8.2(5.50), 8.4 before 8.4(7.15), 8.6 before 8.6(1.14), 8.7 before 8.7(1.13), 9.0 before 9.0(4.8), and 9.1 before 9.1(5.1) allows remote attackers to bypass certificate validation via an | 1,0% | — |
| CVE-2026-23664 | HIGH 7.5 | microsoft azure_iot_explorer Improper restriction of communication channel to intended endpoints in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2024-46668 | HIGH 7.5 | fortinet fortios An allocation of resources without limits or throttling vulnerability [CWE-770] in FortiOS versions 7.4.0 through 7.4.4, versions 7.2.0 through 7.2.8, versions 7.0.0 through 7.0.15, and versions 6.4.0 through 6.4.15 may allow an unauthenticated remote user to | 1,0% | — |
| CVE-2024-20335 | MED 6.5 | cisco wap121_firmware A vulnerability in the web-based management interface of Cisco Small Business 100, 300, and 500 Series Wireless APs could allow an authenticated, remote attacker to perform command injection attacks against an affected device. In order to exploit this vulnerab | 1,0% | — |
| CVE-2022-29144 | HIGH 7.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 1,0% | — |
| CVE-2022-21847 | MED 6.5 | microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability | 1,0% | — |
| CVE-2021-26618 | HIGH 7.1 | tmax tooffice An improper input validation leading to arbitrary file creation was discovered in ToWord of ToOffice. Remote attackers use this vulnerability to execute arbitrary file included malicious code. | 1,0% | — |
| CVE-2018-18966 | MED 4.9 | oscommerce online_merchant osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. The .htaccess file in catalog/images/ bans the html extension, but Internet Explorer render HTML elements in a .eml file. | 1,0% | — |
| CVE-2017-12228 | MED 5.9 | cisco ios A vulnerability in the Cisco Network Plug and Play application of Cisco IOS 12.4 through 15.6 and Cisco IOS XE 3.3 through 16.4 could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data by using an invalid certificate. The v | 1,0% | — |
| CVE-2015-7997 | MED 4.3 | citrix netscaler_application_delivery_controller_firmware Multiple cross-site scripting (XSS) vulnerabilities in the Nitro API in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 133.9, 10.5 before Build 58.11, and 10.5.e before Build 56.1505.e on NetScaler Service Delive | 1,0% | — |
| CVE-2013-1245 | MED 4.0 | cisco webex_social The user-management page in Cisco WebEx Social relies on client-side validation of values in the Screen Name, First Name, Middle Name, Last Name, Email Address, and Job Title fields, which allows remote authenticated users to bypass intended access restriction | 1,0% | — |
| CVE-2026-69824 | CRIT 9.8 | microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an unauthorized attacker to execute code over a network. | 1,0% | — |
| CVE-2026-69819 | CRIT 9.8 | microsoft windows_10_1607 Out-of-bounds write in RPC Runtime allows an unauthorized attacker to execute code over a network. | 1,0% | — |
| CVE-2026-69431 | CRIT 9.8 | microsoft windows_10_1607 Heap-based buffer overflow in Telnet Client allows an unauthorized attacker to execute code over a network. | 1,0% | — |
| CVE-2026-69408 | CRIT 9.8 | microsoft windows_10_1607 Integer overflow or wraparound in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. | 1,0% | — |
| CVE-2026-69276 | CRIT 9.8 | microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Microsoft UxTheme Library (uxtheme.dll) allows an unauthorized attacker to execute code over a network. | 1,0% | — |
| CVE-2025-39964 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, | 1,0% | |
| CVE-2024-52055 | MED 4.9 | wowza streaming_engine Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to read any file on the file system if the target directory contains an XML definition file. | 1,0% | — |
| CVE-2024-39863 | MED 5.4 | apache airflow Apache Airflow versions before 2.9.3 have a vulnerability that allows an authenticated attacker to inject a malicious link when installing a provider. Users are recommended to upgrade to version 2.9.3, which fixes this issue. | 1,0% | — |
| CVE-2023-35635 | MED 5.5 | microsoft windows_11_22h2 Windows Kernel Denial of Service Vulnerability | 1,0% | — |
| CVE-2021-34774 | MED 4.9 | cisco common_services_platform_collector A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to access sensitive data on an affected system. This vulnerability exists because the application does not su | 1,0% | — |
| CVE-2020-17038 | HIGH 7.8 | microsoft windows_10 Win32k Elevation of Privilege Vulnerability | 1,0% | — |
| CVE-2020-0998 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context.</p> <p>In a local attack scenario, | 1,0% | — |
| CVE-2020-0870 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Shell infrastructure component improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context.</p> <p>To exploit this vulnera | 1,0% | — |
| CVE-2020-0838 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when NTFS improperly checks access. An attacker who successfully exploited this vulnerability could run processes in an elevated context.</p> <p>To exploit the vulnerability, an attacker would first have to log | 1,0% | — |