58.535 CVE seguite
797 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.535 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2015-8967 | HIGH 7.8 | google android arch/arm64/kernel/sys.c in the Linux kernel before 4.0 allows local users to bypass the "strict page permissions" protection mechanism and modify the system-call table, and consequently gain privileges, by leveraging write access. | 0,8% | — |
| CVE-2008-4113 | MED 4.7 | linux linux_kernel The sctp_getsockopt_hmac_ident function in net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.26.4, when the SCTP-AUTH extension is enabled, relies on an untrusted length value to limit copying of | 0,8% | — |
| CVE-2026-57308 | CRIT 9.8 | apache syncope Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging unsanitized sort parameter | 0,8% | — |
| CVE-2026-0288 | HIGH 7.5 | paloaltonetworks pan-os Multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent (TSA) component of Palo Alto Networks PAN-OS software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition or potentially execute arbitr | 0,8% | — |
| CVE-2023-23775 | MED 6.5 | fortinet fortisoar Multiple improper neutralization of special elements used in SQL commands ('SQL Injection') vulnerabilities [CWE-89] in FortiSOAR 7.2.0 and before 7.0.3 may allow an authenticated attacker to execute unauthorized code or commands via specifically crafted strin | 0,8% | — |
| CVE-2022-30223 | MED 5.7 | microsoft windows_10 Windows Hyper-V Information Disclosure Vulnerability | 0,8% | — |
| CVE-2021-32595 | MED 6.5 | fortinet fortiportal Multiple uncontrolled resource consumption vulnerabilities in the web interface of FortiPortal before 6.0.6 may allow a single low-privileged user to induce a denial of service via multiple HTTP requests. | 0,8% | — |
| CVE-2020-16022 | HIGH 8.8 | google chrome Insufficient policy enforcement in networking in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to potentially bypass firewall controls via a crafted HTML page. | 0,8% | — |
| CVE-2018-0434 | HIGH 7.4 | cisco vedge_1000_firmware A vulnerability in the Zero Touch Provisioning feature of the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data by using an invalid certificate. The vulnerability is due to insufficient certific | 0,8% | — |
| CVE-2017-4951 | HIGH 8.8 | vmware airwatch VMware AirWatch Console (9.2.x before 9.2.2 and 9.1.x before 9.1.5) contains a Cross Site Request Forgery vulnerability when accessing the App Catalog. An attacker may exploit this issue by tricking users into installing a malicious application on their device | 0,8% | — |
| CVE-2026-50516 | CRIT 9.4 | microsoft azure_kubernetes_service Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. | 0,8% | — |
| CVE-2022-49330 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tcp: fix tcp_mtup_probe_success vs wrong snd_cwnd syzbot got a new report [1] finally pointing to a very old bug, added in initial support for MTU probing. tcp_mtu_probe() has checks about | 0,8% | — |
| CVE-2021-26613 | HIGH 8.1 | tobesoft nexacro improper input validation vulnerability in nexacro permits copying file to the startup folder using rename method. | 0,8% | — |
| CVE-2021-1397 | MED 4.7 | cisco c125_m5_firmware A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of | 0,8% | — |
| CVE-2019-5588 | MED 6.1 | fortinet fortios A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4 under SSL VPN web portal may allow an attacker to execute unauthorized malicious script code via the "err" parameter of the error process HTTP requests. | 0,8% | — |
| CVE-2019-5586 | MED 6.1 | fortinet fortios A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiOS 5.2.0 to 5.6.10, 6.0.0 to 6.0.4 under SSL VPN web portal may allow an attacker to execute unauthorized malicious script code via the "param" parameter of the error process HTTP requests. | 0,8% | — |
| CVE-2018-0148 | HIGH 8.8 | cisco ucs_director A vulnerability in the web-based management interface of Cisco UCS Director Software and Cisco Integrated Management Controller (IMC) Supervisor Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and | 0,8% | — |
| CVE-2018-0107 | HIGH 8.8 | cisco prime_service_catalog A vulnerability in the web framework of Cisco Prime Service Catalog could allow an unauthenticated, remote attacker to execute unwanted actions on an affected device. The vulnerability is due to a lack of cross-site request forgery (CSRF) protection. An attack | 0,8% | — |
| CVE-2017-6756 | HIGH 8.8 | cisco prime_collaboration_provisioning A vulnerability in the Web UI Application of the Cisco Prime Collaboration Provisioning Tool through 12.2 could allow an unauthenticated, remote attacker to execute unwanted actions. The vulnerability is due to a lack of defense against cross-site request forg | 0,8% | — |
| CVE-2016-2075 | MED 5.4 | vmware vrealize_business_advanced_and_enterprise Cross-site scripting (XSS) vulnerability in VMware vRealize Business Advanced and Enterprise 8.x before 8.2.5 on Linux allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | 0,8% | — |
| CVE-2016-1356 | LOW 3.7 | cisco firesight_system_software Cisco FireSIGHT System Software 6.1.0 does not use a constant-time algorithm for verifying credentials, which makes it easier for remote attackers to enumerate valid usernames by measuring timing differences, aka Bug ID CSCuy41615. | 0,8% | — |
| CVE-2025-48802 | MED 6.5 | microsoft windows_11_22h2 Improper certificate validation in Windows SMB allows an authorized attacker to perform spoofing over a network. | 0,8% | — |
| CVE-2025-47160 | MED 5.4 | microsoft windows_10_1507 Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network. | 0,8% | — |
| CVE-2024-43529 | HIGH 7.3 | microsoft windows_10_21h2 Windows Print Spooler Elevation of Privilege Vulnerability | 0,8% | — |
| CVE-2024-35255 | MED 5.5 | microsoft authentication_library Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability | 0,8% | — |