EN
58.617 CVE seguite
797 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.617 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più alto In KEV dal, ordina dal più alto
CVE-2023-46712 HIGH 7.2 fortinet fortiportal A improper access control in Fortinet FortiPortal version 7.0.0 through 7.0.6, Fortinet FortiPortal version 7.2.0 through 7.2.1 allows attacker to escalate its privilege via specifically crafted HTTP requests. 0,7% —
CVE-2022-34479 MED 6.5 mozilla firefox A malicious website that could create a popup could have resized the popup to overlay the address bar with its own content, resulting in potential user confusion or spoofing attacks. <br>*This bug only affects Thunderbird for Linux. Other operating systems are 0,7% —
CVE-2022-33684 HIGH 8.1 apache pulsar The Apache Pulsar C++ Client does not verify peer TLS certificates when making HTTPS calls for the OAuth2.0 Client Credential Flow, even when tlsAllowInsecureConnection is disabled via configuration. This vulnerability allows an attacker to perform a man in th 0,7% —
CVE-2022-22368 HIGH 7.5 ibm spectrum_scale IBM Spectrum Scale 5.1.0 through 5.1.3.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 221012. 0,7% —
CVE-2022-20949 MED 6.5 cisco secure_firewall_threat_defense A vulnerability in the management web server of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker with high privileges to execute configuration commands on an affected system. This vulnerability exists because acces 0,7% —
CVE-2021-47162 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tipc: skb_linearize the head skb when reassembling msgs It's not a good idea to append the frag skb to a skb's frag_list if the frag_list already has skbs from elsewhere, such as this skb wa 0,7% —
CVE-2021-29754 HIGH 8.8 ibm websphere_application_server IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a privilege escalation vulnerability when using the SAML Web Inbound Trust Association Interceptor (TAI). IBM X-Force ID: 202006. 0,7% —
CVE-2019-19692 MED 6.1 trendmicro apex_one Trend Micro Apex One (2019) is affected by a cross-site scripting (XSS) vulnerability on the product console. Note that the Japanese version of the product is NOT affected. 0,7% —
CVE-2019-1797 HIGH 8.8 cisco wireless_lan_controller_software A vulnerability in the web-based management interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on the device with the pri 0,7% —
CVE-2026-57821 HIGH 8.1 apache fineract A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in versions up to and including 1.14.0. The orderBy request parameter is concatenated into a SQL query without sufficient validation, allowing an authenticated us 0,7% —
CVE-2025-62550 HIGH 8.8 microsoft azure_monitor_agent Out-of-bounds write in Azure Monitor Agent allows an authorized attacker to execute code over a network. 0,7% —
CVE-2025-23318 HIGH 8.1 nvidia triton_inference_server NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, data tamperin 0,7% —
CVE-2024-43643 MED 6.8 microsoft windows_10_1507 Windows USB Video Class System Driver Elevation of Privilege Vulnerability 0,7% —
CVE-2024-43638 MED 6.8 microsoft windows_10_1507 Windows USB Video Class System Driver Elevation of Privilege Vulnerability 0,7% —
CVE-2024-43637 MED 6.8 microsoft windows_10_1507 Windows USB Video Class System Driver Elevation of Privilege Vulnerability 0,7% —
CVE-2024-43634 MED 6.8 microsoft windows_10_1507 Windows USB Video Class System Driver Elevation of Privilege Vulnerability 0,7% —
CVE-2024-43449 MED 6.8 microsoft windows_10_1507 Windows USB Video Class System Driver Elevation of Privilege Vulnerability 0,7% —
CVE-2023-20111 MED 6.5 cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access sensitive information. This vulnerability is due to the improper storage of sensitive information within th 0,7% —
CVE-2022-48655 HIGH 7.8 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Harden accesses to the reset domains Accessing reset domains descriptors by the index upon the SCMI drivers requests through the SCMI reset operations interface can poten 0,7% —
CVE-2021-46999 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: sctp: do asoc update earlier in sctp_sf_do_dupcook_a There's a panic that occurs in a few of envs, the call trace is as below: [] general protection fault, ... 0x29acd70f1000a: 0000 [#1] 0,7% —
CVE-2021-1561 MED 5.4 cisco secure_email_and_web_manager A vulnerability in the spam quarantine feature of Cisco Secure Email and Web Manager, formerly Cisco Security Management Appliance (SMA), could allow an authenticated, remote attacker to gain unauthorized access and modify the spam quarantine settings of anoth 0,7% —
CVE-2015-6932 MED 5.8 vmware vcenter_server VMware vCenter Server 5.5 before u3 and 6.0 before u1 does not verify X.509 certificates from TLS LDAP servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. 0,7% —
CVE-2008-5713 MED 4.9 linux linux_kernel The __qdisc_run function in net/sched/sch_generic.c in the Linux kernel before 2.6.25 on SMP machines allows local users to cause a denial of service (soft lockup) by sending a large amount of network traffic, as demonstrated by multiple simultaneous invocatio 0,7% —
CVE-2026-84501 MED 5.3 apache zookeeper An unauthenticated attacker can inject arbitrary fake log lines into Apache ZooKeeper's operational log by sending a crafted add_auth("ensemble", ...) request containing newline characters (\n). When the ensemble name doesn't match, EnsembleAuthenticationProvi 0,7% —
CVE-2026-84439 MED 5.3 apache zookeeper When audit logging is enabled (zookeeper.audit.enable=true), an unauthenticated attacker can inject arbitrary fields into Apache ZooKeeper's audit log by sending a digest authentication request with tab characters (\t) embedded in the username. Because the aud 0,7% —