EN
58.535 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.535 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più alto In KEV dal, ordina dal più alto
CVE-2020-3137 MED 6.1 cisco email_security_appliance A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected dev 0,8% —
CVE-2020-3136 MED 6.1 cisco jabber_guest A vulnerability in the web-based management interface of Cisco Jabber Guest could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerabi 0,8% —
CVE-2020-16993 MED 5.4 microsoft azure_sphere Azure Sphere Elevation of Privilege Vulnerability 0,8% —
CVE-2018-21033 MED 6.5 hitachi automation_director A vulnerability in Hitachi Command Suite prior to 8.6.2-00, Hitachi Automation Director prior to 8.6.2-00 and Hitachi Infrastructure Analytics Advisor prior to 4.2.0-00 allow authenticated remote users to load an arbitrary Cascading Style Sheets (CSS) token se 0,8% —
CVE-2011-2481 MED 4.6 apache tomcat Apache Tomcat 7.0.x before 7.0.17 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld files of arbitrary web applications via a crafted appli 0,8% —
CVE-2026-52924 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: sctp: purge outqueue on stale COOKIE-ECHO handling sctp_stream_update() is only invoked when the association is moved into COOKIE_WAIT during association setup/reconfiguration. In this path, 0,8% —
CVE-2026-46590 HIGH 8.8 apache camel Deserialization of Untrusted Data vulnerability in Apache Camel PQC component. The camel-pqc component persists post-quantum key metadata (KeyMetadata) through pluggable KeyLifecycleManager implementations. HashicorpVaultKeyLifecycleManager and AwsSecretsMana 0,8% —
CVE-2025-47997 MED 6.5 microsoft sql_server_2016 Concurrent execution using shared resource with improper synchronization ('race condition') in SQL Server allows an authorized attacker to disclose information over a network. 0,8% —
CVE-2024-47197 HIGH 7.5 apache maven_archetype Exposure of Sensitive Information to an Unauthorized Actor, Insecure Storage of Sensitive Information vulnerability in Maven Archetype Plugin. This issue affects Maven Archetype Plugin: from 3.2.1 before 3.3.0. Users are recommended to upgrade to version 3.3 0,8% —
CVE-2024-38186 HIGH 7.8 microsoft windows_10_1607 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability 0,8% —
CVE-2023-33306 MED 6.5 fortinet fortios A null pointer dereference in Fortinet FortiOS before 7.2.5, before 7.0.11 and before 6.4.13, FortiProxy before 7.2.4 and before 7.0.10 allows attacker to denial of sslvpn service via specifically crafted request in bookmark parameter. 0,8% —
CVE-2023-20087 MED 4.9 cisco identity_services_engine Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to download arbitrary files from the filesystem of an affected device. These vulnerabilities are due to insuffi 0,8% —
CVE-2023-20077 MED 4.9 cisco identity_services_engine Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to download arbitrary files from the filesystem of an affected device. These vulnerabilities are due to insuffi 0,8% —
CVE-2021-26874 HIGH 7.8 microsoft windows_10 Windows Overlay Filter Elevation of Privilege Vulnerability 0,8% —
CVE-2019-1859 HIGH 7.2 cisco sf200-24_firmware A vulnerability in the Secure Shell (SSH) authentication process of Cisco Small Business Switches software could allow an attacker to bypass client-side certificate authentication and revert to password authentication. The vulnerability exists because OpenSSH 0,8% —
CVE-2019-15218 MED 4.6 canonical ubuntu_linux An issue was discovered in the Linux kernel before 5.1.8. There is a NULL pointer dereference caused by a malicious USB device in the drivers/media/usb/siano/smsusb.c driver. 0,8% —
CVE-2017-18509 HIGH 7.8 canonical ubuntu_linux An issue was discovered in net/ipv6/ip6mr.c in the Linux kernel before 4.11. By setting a specific socket option, an attacker can control a pointer in kernel land and cause an inet_csk_listen_stop general protection fault, or potentially execute arbitrary code 0,8% —
CVE-2017-12305 MED 6.7 cisco ip_phone_8800_series_firmware A vulnerability in the debug interface of Cisco IP Phone 8800 series could allow an authenticated, local attacker to execute arbitrary commands, aka Debug Shell Command Injection. The vulnerability is due to insufficient input validation. An attacker could exp 0,8% —
CVE-2015-2344 MED 5.4 vmware vrealize_automation Cross-site scripting (XSS) vulnerability in VMware vRealize Automation 6.x before 6.2.4 on Linux allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. 0,8% —
CVE-2012-4092 MED 5.8 cisco unified_computing_system The management interface in the Central Software component in Cisco Unified Computing System (UCS) does not properly validate the identity of vCenter consoles, which allows man-in-the-middle attackers to read or modify an inter-device data stream by spoofing a 0,8% —
CVE-2026-44617 MED 6.5 apache zeppelin LDAP filter injection vulnerability in Apache Zeppelin. LdapRealm used RFC 4514 distinguished-name escaping when constructing LDAP search filters instead of RFC 4515 filter escaping, leaving special filter characters insufficiently escaped.                   T 0,8% —
CVE-2024-49092 MED 6.8 microsoft windows_10_1809 Windows Mobile Broadband Driver Elevation of Privilege Vulnerability 0,8% —
CVE-2024-49083 MED 6.8 microsoft windows_10_1809 Windows Mobile Broadband Driver Elevation of Privilege Vulnerability 0,8% —
CVE-2023-36556 HIGH 8.8 fortinet fortimail An incorrect authorization vulnerability [CWE-863] in FortiMail webmail version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.5 and below 6.4.7 allows an authenticated attacker to login on other users accounts from the same web domain via crafted HTTP or HTTP 0,8% —
CVE-2023-25753 MED 6.5 apache shenyu There exists an SSRF (Server-Side Request Forgery) vulnerability located at the /sandbox/proxyGateway endpoint. This vulnerability allows us to manipulate arbitrary requests and retrieve corresponding responses by inputting any URL into the requestUrl paramet 0,8% —