EN
58.507 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.507 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più alto In KEV dal, ordina dal più alto
CVE-2020-16877 HIGH 7.1 microsoft windows_10 <p>An elevation of privilege vulnerability exists when Microsoft Windows improperly handles reparse points. An attacker who successfully exploited this vulnerability could overwrite or delete a targeted file that would normally require elevated permissions.</p 1,0% —
CVE-2017-3869 MED 5.4 cisco prime_infrastructure An API Credentials Management vulnerability in the APIs for Cisco Prime Infrastructure could allow an authenticated, remote attacker to access an API that should be restricted to a privileged user. The attacker needs to have valid credentials. More Information 1,0% —
CVE-2014-3823 MED 4.3 juniper junos_pulse_secure_access_service The Juniper Junos Pulse Secure Access Service (SSL VPN) devices with IVE OS 8.0 before 8.0r1, 7.4 before 7.4r5, and 7.1 before 7.1r18 allows remote attackers to conduct clickjacking attacks via unspecified vectors. 1,0% —
CVE-2014-2193 MED 4.3 cisco unified_web_and_e-mail_interaction_manager Cisco Unified Web and E-Mail Interaction Manager places session identifiers in GET requests, which allows remote attackers to inject conversation text by obtaining a valid identifier, aka Bug ID CSCuj43084. 1,0% —
CVE-2013-3401 MED 4.3 cisco telepresence_tc_software The SIP implementation in Cisco TelePresence TC Software allows remote attackers to trigger unintended use of NOTIFY messages via unspecified vectors, aka Bug ID CSCud96080. 1,0% —
CVE-2013-3376 MED 4.3 cisco video_surveillance_operations_manager Open redirect vulnerability in the help page in Cisco Video Surveillance Operations Manager allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL, aka Bug ID CSCty74490. 1,0% —
CVE-2011-3649 LOW 2.6 mozilla firefox Mozilla Firefox 7.0 and Thunderbird 7.0, when the Direct2D (aka D2D) API is used on Windows in conjunction with the Azure graphics back-end, allow remote attackers to bypass the Same Origin Policy, and obtain sensitive image data from a different domain, by in 1,0% —
CVE-2026-58281 HIGH 8.3 microsoft edge_chromium Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. 1,0% —
CVE-2024-36912 CRIT 9.6 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Drivers: hv: vmbus: Track decrypted status in vmbus_gpadl In CoCo VMs it is possible for the untrusted host to cause set_memory_encrypted() or set_memory_decrypted() to fail such that an err 1,0% —
CVE-2023-25504 MED 4.9 apache superset A malicious actor who has been authenticated and granted specific permissions in Apache Superset may use the import dataset feature in order to conduct Server-Side Request Forgery attacks and query internal resources on behalf of the server where Superset is d 1,0% —
CVE-2021-26884 MED 5.5 microsoft windows_10 Windows Media Photo Codec Information Disclosure Vulnerability 1,0% —
CVE-2021-26869 MED 5.5 microsoft windows_10 Windows ActiveX Installer Service Information Disclosure Vulnerability 1,0% —
CVE-2021-24107 MED 5.5 microsoft windows_10 Windows Event Tracing Information Disclosure Vulnerability 1,0% —
CVE-2026-63520 HIGH 8.1 microsoft sharepoint_server Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. 1,0% —
CVE-2025-47988 HIGH 7.5 microsoft azure_monitor_agent Improper control of generation of code ('code injection') in Azure Monitor Agent allows an unauthorized attacker to execute code over an adjacent network. 1,0% —
CVE-2024-30033 HIGH 7.0 microsoft windows_10_21h2 Windows Search Service Elevation of Privilege Vulnerability 1,0% —
CVE-2022-45786 HIGH 8.1 apache age There are issues with the AGE drivers for Golang and Python that enable SQL injections to occur. This impacts AGE for PostgreSQL 11 & AGE for PostgreSQL 12, all versions up-to-and-including 1.1.0, when using those drivers. The fix is to update to the latest G 1,0% —
CVE-2022-43641 HIGH 7.8 foxit pdf_editor This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 12.0.1.12430. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicio 1,0% —
CVE-2022-26890 HIGH 7.5 f5 big-ip_access_policy_manager On F5 BIG-IP Advanced WAF, ASM, and APM 16.1.x versions prior to 16.1.2.1, 15.1.x versions prior to 15.1.5, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, when ASM or Advanced WAF, as well as APM, are configured on a virtual server, th 1,0% —
CVE-2022-20809 MED 4.3 cisco telepresence_video_communication_server Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to write files or disclose sensitive information on an affe 1,0% —
CVE-2020-1122 MED 5.5 microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Language Pack Installer improperly handles file operations. An attacker who successfully exploited this vulnerability could run processes in an elevated context.</p> <p>An attacker could exploi 1,0% —
CVE-2013-5539 MED 6.0 cisco identity_services_engine The upload-dialog implementation in Cisco Identity Services Engine (ISE) allows remote authenticated users to upload files with an arbitrary file type, and consequently conduct attacks against unspecified other systems, via a crafted file, aka Bug ID CSCui6751 1,0% —
CVE-2026-20307 CRIT 9.9 A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have at le 1,0% —
CVE-2024-30096 MED 5.5 microsoft windows_10_1809 Windows Cryptographic Services Information Disclosure Vulnerability 1,0% —
CVE-2023-45757 MED 6.1 apache brpc Security vulnerability in Apache bRPC <=1.6.0 on all platforms allows attackers to inject XSS code to the builtin rpcz page. An attacker that can send http request to bRPC server with rpcz enabled can inject arbitrary XSS code to the builtin rpcz page. Soluti 1,0% —