58.507 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.507 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-55051 | MED 6.5 | microsoft sharepoint_server Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. | 0,9% | — |
| CVE-2023-28506 | HIGH 8.8 | rocketsoftware unidata Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow, where a string is copied into a buffer using a memcpy-like function and a user-provided | 0,9% | — |
| CVE-2023-20883 | HIGH 7.5 | vmware spring_boot In Spring Boot versions 3.0.0 - 3.0.6, 2.7.0 - 2.7.11, 2.6.0 - 2.6.14, 2.5.0 - 2.5.14 and older unsupported versions, there is potential for a denial-of-service (DoS) attack if Spring MVC is used together with a reverse proxy cache. | 0,9% | — |
| CVE-2022-22300 | MED 4.3 | fortinet fortianalyzer A improper handling of insufficient permissions or privileges in Fortinet FortiAnalyzer version 5.6.0 through 5.6.11, FortiAnalyzer version 6.0.0 through 6.0.11, FortiAnalyzer version 6.2.0 through 6.2.9, FortiAnalyzer version 6.4.0 through 6.4.7, FortiAnalyze | 0,9% | — |
| CVE-2021-41376 | LOW 2.3 | microsoft azure_sphere Azure Sphere Information Disclosure Vulnerability | 0,9% | — |
| CVE-2020-3474 | MED 4.3 | cisco ios_xe Multiple vulnerabilities in the web management framework of Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privileges to gain unauthorized read access to sensitive data or cause the web management software to hang or crash, | 0,9% | — |
| CVE-2020-0989 | MED 5.5 | microsoft windows_10 <p>An information disclosure vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions. An attacker who successfully exploited this vulnerability could bypass access restrictions to read files.</p> <p>To exploit | 0,9% | — |
| CVE-2020-0858 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the "Public Account Pictures" folder improperly handles junctions.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Elevation of Privil | 0,9% | — |
| CVE-2017-6675 | MED 6.1 | cisco industrial_network_director A vulnerability in the web interface of Cisco Industrial Network Director could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against an affected system. More Information: CSCvd25405. Known Affected Releases | 0,9% | — |
| CVE-2013-0885 | HIGH 7.5 | google chrome Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly restrict API privileges during interaction with the Chrome Web Store, which has unspecified impact and attack vectors. | 0,9% | — |
| CVE-2025-49688 | HIGH 8.8 | microsoft windows_server_2012 Double free in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | 0,9% | — |
| CVE-2025-49676 | HIGH 8.8 | microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | 0,9% | — |
| CVE-2025-49672 | HIGH 8.8 | microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | 0,9% | — |
| CVE-2023-30995 | HIGH 7.5 | ibm aspera_faspex IBM Aspera Faspex 4.0 through 4.4.2 and 5.0 through 5.0.5 could allow a malicious actor to bypass IP whitelist restrictions using a specially crafted HTTP request. IBM X-Force ID: 254268. | 0,9% | — |
| CVE-2022-35822 | HIGH 7.1 | microsoft windows_10 Windows Defender Credential Guard Security Feature Bypass Vulnerability | 0,9% | — |
| CVE-2022-3534 | MED 5.5 | debian debian_linux A vulnerability has been found in Linux Kernel up to 5.10.162/5.15.85/6.0.15/6.1.1. The impacted element is the function btf_dump_name_dups of the file tools/lib/bpf/btf_dump.c of the component libbpf. The manipulation leads to use after free. Upgrading to ver | 0,9% | — |
| CVE-2022-20814 | HIGH 7.4 | cisco telepresence_video_communication_server A vulnerability in the certificate validation of Cisco Expressway-C and Cisco TelePresence VCS could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data. The vulnerability is due to a lack of validation | 0,9% | — |
| CVE-2021-36967 | HIGH 8.0 | microsoft windows_10 Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability | 0,9% | — |
| CVE-2019-1719 | MED 6.1 | cisco identity_services_engine A vulnerability in the web-based guest portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerability is due to | 0,9% | — |
| CVE-2018-0367 | MED 5.4 | cisco registered_envelope_service A vulnerability in the web-based management interface of the Cisco Registered Envelope Service could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the affected ser | 0,9% | — |
| CVE-2018-0003 | MED 6.5 | juniper junos A specially crafted MPLS packet received or processed by the system, on an interface configured with MPLS, will store information in the system memory. Subsequently, if this stored information is accessed, this may result in a kernel crash leading to a denial | 0,9% | — |
| CVE-2017-4940 | MED 6.1 | vmware esxi The ESXi Host Client in VMware ESXi (6.5 before ESXi650-201712103-SG, 5.5 before ESXi600-201711103-SG and 5.5 before ESXi550-201709102-SG) contains a vulnerability that may allow for stored cross-site scripting (XSS). An attacker can exploit this vulnerability | 0,9% | — |
| CVE-2010-4243 | MED 4.9 | linux linux_kernel fs/exec.c in the Linux kernel before 2.6.37 does not enable the OOM Killer to assess use of stack memory by arrays representing the (1) arguments and (2) environment, which allows local users to cause a denial of service (memory consumption) via a crafted exec | 0,9% | — |
| CVE-2010-3858 | MED 4.9 | canonical ubuntu_linux The setup_arg_pages function in fs/exec.c in the Linux kernel before 2.6.36, when CONFIG_STACK_GROWSDOWN is used, does not properly restrict the stack memory consumption of the (1) arguments and (2) environment for a 32-bit application on a 64-bit platform, wh | 0,9% | — |
| CVE-2026-34479 | HIGH 7.5 | apache log4j The Log4j1XmlLayout from the Apache Log4j 1-to-Log4j 2 bridge fails to escape characters forbidden by the XML 1.0 standard, producing malformed XML output. Conforming XML parsers are required to reject documents containing such characters with a fatal error, w | 0,9% | — |