58.535 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.535 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2018-0475 | HIGH 7.4 | cisco ios A vulnerability in the implementation of the cluster feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to trigger a denial of service (DoS) condition on an affected device. The vulnerability is due to imp | 0,9% | — |
| CVE-2018-0441 | HIGH 7.4 | cisco access_points A vulnerability in the 802.11r Fast Transition feature set of Cisco IOS Access Points (APs) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a corruption | 0,9% | — |
| CVE-2014-1910 | MED 5.8 | citrix sharefile_mobile Citrix ShareFile Mobile and ShareFile Mobile for Tablets before 2.4.4 for Android do not verify X.509 certificates from SSL servers, which allow man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | 0,9% | — |
| CVE-2012-3924 | LOW 3.5 | cisco ios The SSLVPN implementation in Cisco IOS 15.1 and 15.2, when DTLS is enabled, does not properly handle certain outbound ACL configurations, which allows remote authenticated users to cause a denial of service (device crash) via a session involving a PPP over ATM | 0,9% | — |
| CVE-2012-3923 | LOW 3.5 | cisco ios The SSLVPN implementation in Cisco IOS 12.4, 15.0, 15.1, and 15.2, when DTLS is not enabled, does not properly handle certain outbound ACL configurations, which allows remote authenticated users to cause a denial of service (device crash) via a session involvi | 0,9% | — |
| CVE-2012-1344 | LOW 3.5 | cisco ios Cisco IOS 15.1 and 15.2, when a clientless SSL VPN is configured, allows remote authenticated users to cause a denial of service (device reload) by using a web browser to refresh the SSL VPN portal page, as demonstrated by the Android browser, aka Bug ID CSCtr | 0,9% | — |
| CVE-2026-50324 | MED 5.9 | microsoft windows_10_1607 Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network. | 0,9% | — |
| CVE-2025-55333 | MED 6.1 | microsoft windows_10_1507 Incomplete comparison with missing factors in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. | 0,9% | — |
| CVE-2024-53948 | MED 5.3 | apache superset Generation of Error Message Containing analytics metadata Information in Apache Superset. This issue affects Apache Superset: before 4.1.0. Users are recommended to upgrade to version 4.1.0, which fixes the issue. | 0,9% | — |
| CVE-2024-43470 | HIGH 7.3 | microsoft azure_network_watcher_agent Azure Network Watcher VM Agent Elevation of Privilege Vulnerability | 0,9% | — |
| CVE-2024-30072 | HIGH 7.8 | microsoft windows_11_22h2 Microsoft Event Trace Log File Parsing Remote Code Execution Vulnerability | 0,9% | — |
| CVE-2023-35629 | MED 6.8 | microsoft windows_10_1507 Microsoft USBHUB 3.0 Device Driver Remote Code Execution Vulnerability | 0,9% | — |
| CVE-2020-2005 | HIGH 7.1 | paloaltonetworks pan-os A cross-site scripting (XSS) vulnerability exists when visiting malicious websites with the Palo Alto Networks GlobalProtect Clientless VPN that can compromise the user's active session. This issue affects: PAN-OS 7.1 versions earlier than 7.1.26; PAN-OS 8.1 v | 0,9% | — |
| CVE-2020-1138 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists when the Storage Service improperly handles file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges on the victim system. To exploit the vulnerability, an attacker | 0,9% | — |
| CVE-2020-1132 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles file and folder links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status. To exploit th | 0,9% | — |
| CVE-2020-1121 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows improperly handles calls to Clipboard Service. An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the local system. An attacker could then in | 0,9% | — |
| CVE-2017-3874 | MED 5.4 | cisco unified_communications_manager A vulnerability in the web framework of Cisco Unified Communications Manager (CallManager) could allow an authenticated, remote attacker to perform a cross-site scripting (XSS) attack. More Information: CSCvb70033. Known Affected Releases: 11.5(1.11007.2). Kno | 0,9% | — |
| CVE-2011-4777 | MED 4.3 | parallels parallels_plesk_panel Cross-site scripting (XSS) vulnerability in the Site Editor (aka SiteBuilder) feature in Parallels Plesk Panel 10.4.4_build20111103.18 allows remote attackers to inject arbitrary web script or HTML via the login parameter to preferences.html. | 0,9% | — |
| CVE-2009-4910 | MED 4.3 | cisco asa_5580 Cross-site scripting (XSS) vulnerability in the WebVPN portal on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCsq78 | 0,9% | — |
| CVE-2026-84939 | CRIT 9.1 | apache freemarker Path traversal vulnerability in Apache FreeMarker template loading mechanism, if the attacker can specify an arbitrary malformed locale identifier to FreeMarker, and the localized lookup configuration setting is enabled (it's by default enabled). This issue a | 0,9% | — |
| CVE-2026-66143 | HIGH 7.5 | apache neethi It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2 via certain crafted policies, which may lead to a denial of service attack via resource consumption. Users are recommended to upgrade to ve | 0,9% | — |
| CVE-2026-34481 | HIGH 7.5 | apache log4j Apache Log4j's JsonTemplateLayout https://logging.apache.org/log4j/2.x/manual/json-template-layout.html , in versions up to and including 2.25.3, produces invalid JSON output when log events contain non-finite floating-point values (NaN, Infinity, or -Infinit | 0,9% | — |
| CVE-2025-24055 | MED 4.3 | microsoft windows_10_1507 Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to disclose information with a physical attack. | 0,9% | — |
| CVE-2024-26193 | MED 6.4 | microsoft azure_migrate Azure Migrate Remote Code Execution Vulnerability | 0,9% | — |
| CVE-2023-2984 | HIGH 8.8 | pimcore pimcore Path Traversal: '\..\filename' in GitHub repository pimcore/pimcore prior to 10.5.22. | 0,9% | — |