58.515 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.515 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2020-27722 | MED 6.5 | f5 big-ip_access_policy_manager In BIG-IP APM versions 15.0.0-15.0.1.3, 14.1.0-14.1.3, and 13.1.0-13.1.3.4, under certain conditions, the VDI plugin does not observe plugin flow-control protocol causing excessive resource consumption. | 0,9% | — |
| CVE-2020-26558 | MED 4.2 | bluetooth bluetooth_core_specification Bluetooth LE and BR/EDR secure pairing in Bluetooth Core Specification 2.1 through 5.2 may permit a nearby man-in-the-middle attacker to identify the Passkey used during pairing (in the Passkey authentication procedure) by reflection of the public key and the | 0,9% | — |
| CVE-2019-6664 | HIGH 7.5 | f5 big-ip_access_policy_manager On BIG-IP 15.0.0 and 14.1.0-14.1.0.6, under certain conditions, network protections on the management port do not follow current best practices. | 0,9% | — |
| CVE-2018-21032 | MED 4.3 | hitachi automation_director A vulnerability in Hitachi Command Suite prior to 8.7.1-00 and Hitachi Automation Director prior to 8.5.0-00 allow authenticated remote users to expose technical information through error messages. Hitachi Command Suite includes Hitachi Device Manager and Hita | 0,9% | — |
| CVE-2017-0535 | MED 4.7 | linux linux_kernel An information disclosure vulnerability in the HTC sound codec driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Produ | 0,9% | — |
| CVE-2006-3547 | MED 5.5 | vmware player EMC VMware Player allows user-assisted attackers to cause a denial of service (unrecoverable application failure) via a long value of the ide1:0.fileName parameter in the .vmx file of a virtual machine. NOTE: third parties have disputed this issue, saying tha | 0,9% | — |
| CVE-2026-56623 | HIGH 7.1 | apache mina_sshd Path traversal on Windows in Apache MINA SSHD component sshd-git. Apache MINA SSHD is a Java library for client-side and server-side SSH. A git server implemented with Apache MINA SSHD component sshd-git and running on Windows could allow an authenticated | 0,9% | — |
| CVE-2024-56202 | MED 4.3 | apache traffic_server Expected Behavior Violation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.8, from 10.0.0 through 10.0.3. Users are recommended to upgrade to versions 9.2.9 or 10.0.4 or newer, which fixes the issue. | 0,9% | — |
| CVE-2024-49109 | MED 6.6 | microsoft windows_10_1809 Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability | 0,9% | — |
| CVE-2024-49101 | MED 6.6 | microsoft windows_10_1809 Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability | 0,9% | — |
| CVE-2024-42145 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: IB/core: Implement a limit on UMAD receive List The existing behavior of ib_umad, which maintains received MAD packets in an unbounded list, poses a risk of uncontrolled growth. As user-spac | 0,9% | — |
| CVE-2023-5727 | MED 6.5 | mozilla firefox The executable file warning was not presented when downloading .msix, .msixbundle, .appx, and .appxbundle files, which can run commands on a user's computer. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.* | 0,9% | — |
| CVE-2023-23384 | HIGH 7.3 | microsoft sql_server Microsoft SQL Server Remote Code Execution Vulnerability | 0,9% | — |
| CVE-2022-21978 | HIGH 8.2 | microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability | 0,9% | — |
| CVE-2022-20920 | HIGH 7.7 | cisco ios A vulnerability in the SSH implementation of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload. This vulnerability is due to improper handling of resources during an exceptional sit | 0,9% | — |
| CVE-2020-2033 | MED 5.3 | paloaltonetworks globalprotect When the pre-logon feature is enabled, a missing certification validation in Palo Alto Networks GlobalProtect app can disclose the pre-logon authentication cookie to a man-in-the-middle attacker on the same local area network segment with the ability to manipu | 0,9% | — |
| CVE-2020-1014 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the Microsoft Windows Update Client when it does not properly handle privileges, aka 'Microsoft Windows Update Client Elevation of Privilege Vulnerability'. | 0,9% | — |
| CVE-2020-0805 | MED 5.3 | microsoft windows_10 <p>A security feature bypass vulnerability exists when a Windows Projected Filesystem improperly handles file redirections. An attacker who successfully exploited this vulnerability could delete a targeted file they would not have permissions to.</p> <p>To exp | 0,9% | — |
| CVE-2019-1568 | MED 6.1 | paloaltonetworks demisto Cross-site scripting (XSS) vulnerability in Palo Alto Networks Demisto 4.5 build 40249 may allow an unauthenticated attacker to run arbitrary JavaScript or HTML. | 0,9% | — |
| CVE-2019-0041 | HIGH 8.6 | juniper junos On EX4300-MP Series devices with any lo0 filters applied, transit network traffic may reach the control plane via loopback interface (lo0). The device may fail to forward such traffic. This issue affects Juniper Networks Junos OS 18.2 versions prior to 18.2R1- | 0,9% | — |
| CVE-2018-11805 | MED 6.7 | apache spamassassin In Apache SpamAssassin before 3.4.3, nefarious CF files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA 3.4.3, we recommend that users should on | 0,9% | — |
| CVE-2017-17541 | MED 6.1 | fortinet fortianalyzer_firmware A Cross-site Scripting (XSS) vulnerability in Fortinet FortiManager 6.0.0, 5.6.4 and below versions, FortiAnalyzer 6.0.0, 5.6.4 and below versions allows inject Javascript code and HTML tags through the CN value of CA and CRL certificates via the import CA and | 0,9% | — |
| CVE-2017-12307 | MED 6.1 | cisco esw2-350g-52_firmware A vulnerability in the web framework of Cisco Small Business Managed Switches software could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web interface of an affected system. The vulne | 0,9% | — |
| CVE-2026-54428 | HIGH 7.5 | apache httpcomponents_core Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending oversized comp | 0,9% | — |
| CVE-2026-54399 | HIGH 7.5 | apache httpcomponents_core Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending messages with ex | 0,9% | — |