58.507 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.507 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2014-3406 | HIGH 7.1 | cisco intrusion_prevention_system Race condition in the IP logging feature in Cisco Intrusion Prevention System (IPS) Software 7.1(7)E4 and earlier allows remote attackers to cause a denial of service (device reload) via crafted IP traffic that matches a problematic rule, aka Bug ID CSCud82085 | 0,9% | — |
| CVE-2025-24043 | HIGH 7.5 | microsoft windbg Improper verification of cryptographic signature in .NET allows an authorized attacker to execute code over a network. | 0,9% | — |
| CVE-2024-37358 | HIGH 8.6 | apache james_server Similarly to CVE-2024-34055, Apache James is vulnerable to denial of service through the abuse of IMAP literals from both authenticated and unauthenticated users, which could be used to cause unbounded memory allocation and very long computations Version 3.7. | 0,9% | — |
| CVE-2024-31079 | MED 4.8 | f5 nginx_open_source When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate or cause other potential impact. This attack requires that a request be specifically timed during the connectio | 0,9% | — |
| CVE-2024-28917 | MED 6.2 | microsoft azure_arc_extension_microsoft.azstackhci.operator Azure Arc-enabled Kubernetes Extension Cluster-Scope Elevation of Privilege Vulnerability | 0,9% | — |
| CVE-2024-20338 | HIGH 7.3 | cisco secure_client A vulnerability in the ISE Posture (System Scan) module of Cisco Secure Client for Linux could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to the use of an uncontrolled search path element. A | 0,9% | — |
| CVE-2023-34324 | MED 4.9 | linux linux_kernel Closing of an event channel in the Linux kernel can result in a deadlock. This happens when the close is being performed in parallel to an unrelated Xen console action and the handling of a Xen console interrupt in an unprivileged guest. The closing of an eve | 0,9% | — |
| CVE-2023-20272 | MED 6.7 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to upload malicious files to the web root of the application. This vulnerability is due to insufficient file input validation. | 0,9% | — |
| CVE-2017-0430 | HIGH 7.8 | google android An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compr | 0,9% | — |
| CVE-2010-4249 | MED 4.9 | fedoraproject fedora The wait_for_unix_gc function in net/unix/garbage.c in the Linux kernel before 2.6.37-rc3-next-20101125 does not properly select times for garbage collection of inflight sockets, which allows local users to cause a denial of service (system hang) via crafted u | 0,9% | — |
| CVE-2024-20694 | MED 5.5 | microsoft windows_10_1607 Windows CoreMessaging Information Disclosure Vulnerability | 0,9% | — |
| CVE-2023-21564 | HIGH 7.1 | microsoft azure_devops_server Azure DevOps Server Cross-Site Scripting Vulnerability | 0,9% | — |
| CVE-2022-20917 | MED 4.3 | cisco jabber A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) message processing feature of Cisco Jabber could allow an authenticated, remote attacker to manipulate the content of XMPP messages that are used by the affected application. This vulne | 0,9% | — |
| CVE-2021-43081 | MED 6.1 | fortinet fortios An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS version 7.0.3 and below, 6.4.8 and below, 6.2.10 and below, 6.0.14 to 6.0.0. and in FortiProxy version 7.0.1 and below, 2.0.7 to 2.0.0 web filter override form may | 0,9% | — |
| CVE-2021-38869 | CRIT 9.8 | ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.3, 7.4, and 7.5 in some situations may not automatically log users out after they exceede their idle timeout. IBM X-Force ID: 208341. | 0,9% | — |
| CVE-2021-25248 | MED 5.5 | trendmicro apex_one An out-of-bounds read information disclosure vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security (10.0 SP1 and Services) could allow an attacker to disclose sensitive information about a named pipe. Ple | 0,9% | — |
| CVE-2020-1676 | HIGH 7.2 | juniper mist_cloud_ui When SAML authentication is enabled, Juniper Networks Mist Cloud UI might incorrectly handle SAML responses, allowing a remote attacker to modify a valid SAML response without invalidating its cryptographic signature to bypass SAML authentication security cont | 0,9% | — |
| CVE-2020-12820 | MED 5.4 | fortinet fortios Under non-default configuration, a stack-based buffer overflow in FortiOS version 6.0.10 and below, version 5.6.12 and below may allow a remote attacker authenticated to the SSL VPN to crash the FortiClient NAC daemon (fcnacd) and potentially execute arbitrary | 0,9% | — |
| CVE-2008-1113 | HIGH 7.8 | vocera_communications vocera_communications_badge Cisco Unified Wireless IP Phone 7921, when using Protected Extensible Authentication Protocol (PEAP), does not validate server certificates, which allows remote wireless access points to steal hashed passwords and conduct man-in-the-middle (MITM) attacks. | 0,9% | — |
| CVE-2006-1095 | HIGH 7.2 | apache mod_python Directory traversal vulnerability in the FileSession object in Mod_python module 3.2.7 for Apache allows local users to execute arbitrary code via a crafted session cookie. | 0,9% | — |
| CVE-2026-40859 | HIGH 8.1 | apache camel Deserialization of Untrusted Data vulnerability in Apache Camel. The camel-vertx-http component deserializes HTTP response bodies carrying the Content-Type application/x-java-serialized-object using a raw java.io.ObjectInputStream, without applying any Object | 0,9% | — |
| CVE-2026-25173 | HIGH 8.0 | microsoft windows_10_1607 Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. | 0,9% | — |
| CVE-2026-24464 | MED 6.8 | f5 big-ip_access_policy_manager When running in Appliance mode, a directory traversal vulnerability exists in an undisclosed iControl REST endpoint that may allow an authenticated attacker with administrator role privileges to cross a security boundary and delete files. Note: Software versi | 0,9% | — |
| CVE-2026-23907 | MED 5.3 | apache pdfbox-examples This issue affects the ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.35, from 3.0.0 through 3.0.6. The ExtractEmbeddedFiles example contains a path traversal vulnerability (CWE-22) because the filename that is obtained from PDComp | 0,9% | — |
| CVE-2024-44947 | MED 5.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: fuse: Initialize beyond-EOF page contents before setting uptodate fuse_notify_store(), unlike fuse_do_readpage(), does not enable page zeroing (because it can be used to change partial page | 0,9% | — |