58.507 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.507 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2002-0499 | LOW 2.1 | linux linux_kernel The d_path function in Linux kernel 2.2.20 and earlier, and 2.4.18 and earlier, truncates long pathnames without generating an error, which could allow local users to force programs to perform inappropriate operations on the wrong directories. | 1,0% | — |
| CVE-2025-20236 | HIGH 8.8 | cisco webex_teams A vulnerability in the custom URL parser of Cisco Webex App could allow an unauthenticated, remote attacker to persuade a user to download arbitrary files, which could allow the attacker to execute arbitrary commands on the host of the targeted user. This v | 1,0% | — |
| CVE-2024-21374 | MED 5.0 | microsoft teams Microsoft Teams for Android Information Disclosure Vulnerability | 1,0% | — |
| CVE-2023-28513 | MED 5.9 | ibm mq IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.2 CD, and 9.3 CD and IBM MQ Appliance 9.2 LTS, 9.3 LTS, 9.2 CD, and 9.2 LTS, under certain configurations, is vulnerable to a denial of service attack caused by an error processing messages. IBM X-Force ID: 250397 | 1,0% | — |
| CVE-2022-30306 | MED 6.6 | fortinet fortiweb A stack-based buffer overflow vulnerability [CWE-121] in the CA sign functionality of FortiWeb version 7.0.1 and below, 6.4 all versions, version 6.3.19 and below may allow an authenticated attacker to achieve arbitrary code execution via specifically crafted | 1,0% | — |
| CVE-2017-6161 | MED 5.3 | f5 big-ip_access_policy_manager In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, GTM, Link Controller, PEM, WebAccelerator software version 12.0.0 - 12.1.2, 11.6.0 - 11.6.1, 11.4.0 - 11.5.4, 11.2.1, when ConfigSync is configured, attackers on adjacent networks may be able | 1,0% | — |
| CVE-2009-4141 | HIGH 7.2 | linux linux_kernel Use-after-free vulnerability in the fasync_helper function in fs/fcntl.c in the Linux kernel before 2.6.33-rc4-git1 allows local users to gain privileges via vectors that include enabling O_ASYNC (aka FASYNC or FIOASYNC) on a locked file, and then closing this | 1,0% | — |
| CVE-2026-49818 | MED 6.5 | apache apache-airflow-providers-samba The Apache Airflow Samba provider's `GCSToSambaOperator` joined GCS object names to the SMB destination path without a containment check, so an object named with `../` segments resolved a write path outside the configured `destination_path`. An attacker able t | 1,0% | — |
| CVE-2025-34195 | CRIT 9.8 | vasion virtual_appliance_application Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 1.0.735 and Application prior to 20.0.1330 (Windows client deployments) contain a remote code execution vulnerability during driver installation caused by unquoted program paths. The | 1,0% | — |
| CVE-2024-35161 | HIGH 7.5 | apache traffic_server Apache Traffic Server forwards malformed HTTP chunked trailer section to origin servers. This can be utilized for request smuggling and may also lead cache poisoning if the origin servers are vulnerable. This issue affects Apache Traffic Server: from 8.0.0 th | 1,0% | — |
| CVE-2023-20861 | MED 6.5 | vmware spring_framework In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2.22.RELEASE, and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition. | 1,0% | — |
| CVE-2022-30197 | MED 5.5 | microsoft windows_10 Windows Kernel Information Disclosure Vulnerability | 1,0% | — |
| CVE-2022-20819 | MED 6.5 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information from an affected device. This vulnerability exists because administrative privilege leve | 1,0% | — |
| CVE-2021-34772 | MED 4.7 | cisco orbital A vulnerability in the web-based management interface of Cisco Orbital could allow an unauthenticated, remote attacker to redirect users to a malicious webpage. This vulnerability is due to improper validation of URL paths in the web-based management interface | 1,0% | — |
| CVE-2017-7109 | MED 6.1 | apple icloud An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. iTunes before 12.7 on Windows is affected. tvOS before 11 is affected. The issue involves the "WebKit" compone | 1,0% | — |
| CVE-2025-65037 | CRIT 10.0 | microsoft azure_container_apps Improper control of generation of code ('code injection') in Azure Container Apps allows an unauthorized attacker to execute code over a network. | 1,0% | — |
| CVE-2025-29831 | HIGH 7.5 | microsoft windows_server_2008 Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network. | 1,0% | — |
| CVE-2023-6240 | MED 6.5 | linux linux_kernel A Marvin vulnerability side-channel leakage was found in the RSA decryption operation in the Linux Kernel. This issue may allow a network attacker to decrypt ciphertexts or forge signatures, limiting the services that use that private key. | 1,0% | — |
| CVE-2023-46227 | HIGH 7.5 | apache inlong Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong. This issue affects Apache InLong: from 1.4.0 through 1.8.0, the attacker can use \t to bypass. Users are advised to upgrade to Apache InLong's 1.9.0 or cherry-pick [ | 1,0% | — |
| CVE-2023-35394 | MED 4.6 | microsoft azure_hdinsight Azure HDInsight Jupyter Notebook Spoofing Vulnerability | 1,0% | — |
| CVE-2022-21964 | MED 5.5 | microsoft windows_10 Remote Desktop Licensing Diagnoser Information Disclosure Vulnerability | 1,0% | — |
| CVE-2022-20806 | MED 4.3 | cisco telepresence_video_communication_server Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to write files or disclose sensitive information on an affe | 1,0% | — |
| CVE-2020-3519 | HIGH 8.1 | cisco data_center_network_manager A vulnerability in a specific REST API method of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to conduct a path traversal attack on an affected device. The vulnerability is due to insufficient validation of us | 1,0% | — |
| CVE-2020-3317 | HIGH 7.5 | cisco secure_firewall_threat_defense A vulnerability in the ssl_inspection component of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to crash Snort instances. The vulnerability is due to insufficient input validation in the ssl_inspection component | 1,0% | — |
| CVE-2024-49103 | MED 4.3 | microsoft windows_10_1809 Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability | 1,0% | — |