EN
58.650 CVE seguite
798 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.650 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più alto In KEV dal, ordina dal più alto
CVE-2020-5947 MED 4.3 f5 big-ip_access_policy_manager In versions 16.0.0-16.0.0.1 and 15.1.0-15.1.1, on specific BIG-IP platforms, attackers may be able to obtain TCP sequence numbers from the BIG-IP system that can be reused in future connections with the same source and destination port and IP numbers. Only the 0,7% —
CVE-2020-10727 MED 5.5 apache artemis A flaw was found in ActiveMQ Artemis management API from version 2.7.0 up until 2.12.0, where a user inadvertently stores passwords in plaintext in the Artemis shadow file (etc/artemis-users.properties file) when executing the `resetUsers` operation. A local a 0,7% —
CVE-2019-6688 MED 4.3 f5 big-ip_access_policy_manager On BIG-IP versions 15.0.0-15.0.1.1, 14.1.0-14.1.2.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5 and BIG-IQ versions 6.0.0-6.1.0 and 5.2.0-5.4.0, a user is able to obtain the secret that was being used to encrypt a BIG-IP UCS backup file w 0,7% —
CVE-2015-6307 MED 6.1 cisco firepower Cisco FirePOWER (formerly Sourcefire) 7000 and 8000 devices with software 5.4.0.1 allow remote attackers to cause a denial of service (inspection-engine outage) via crafted packets, aka Bug ID CSCuu10871. 0,7% —
CVE-2014-0219 MED 5.5 apache karaf Apache Karaf before 4.0.10 enables a shutdown port on the loopback interface, which allows local users to cause a denial of service (shutdown) by sending a shutdown command to all listening high ports. 0,7% —
CVE-1999-0138 HIGH 7.2 apple a_ux The suidperl and sperl program do not give up root privileges when changing UIDs back to the original users, allowing root access. 0,7% —
CVE-2026-65017 MED 6.5 apache airflow Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments. When an administrator has enabled multi-team mode and exposed the Config API, an authenticated Viewer holding only configuration-read access — with n 0,7% —
CVE-2026-45860 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conncount: increase the connection clean up limit to 64 After the optimization to only perform one GC per jiffy, a new problem was introduced. If more than 8 new connections ar 0,7% —
CVE-2026-31379 MED 6.1 apache ofbiz Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This 0,7% —
CVE-2024-38078 HIGH 7.5 microsoft windows_11_21h2 Xbox Wireless Adapter Remote Code Execution Vulnerability 0,7% —
CVE-2023-21738 HIGH 7.8 microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability 0,7% —
CVE-2022-26240 MED 6.5 beckmancoulter remisol_advance The default privileges for the running service Normand Message Buffer in Beckman Coulter Remisol Advance v2.0.12.1 and prior allows non-privileged users to overwrite and manipulate executables and libraries. This allows attackers to access sensitive data. 0,7% —
CVE-2021-1690 HIGH 7.8 microsoft windows_10 Windows WalletService Elevation of Privilege Vulnerability 0,7% —
CVE-2021-1689 HIGH 7.8 microsoft windows_10 Windows Multipoint Management Elevation of Privilege Vulnerability 0,7% —
CVE-2021-1688 HIGH 7.8 microsoft windows_10 Windows CSC Service Elevation of Privilege Vulnerability 0,7% —
CVE-2021-1687 HIGH 7.8 microsoft windows_10 Windows WalletService Elevation of Privilege Vulnerability 0,7% —
CVE-2021-1686 HIGH 7.8 microsoft windows_10 Windows WalletService Elevation of Privilege Vulnerability 0,7% —
CVE-2021-1681 HIGH 7.8 microsoft windows_10 Windows WalletService Elevation of Privilege Vulnerability 0,7% —
CVE-2021-1662 HIGH 7.8 microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability 0,7% —
CVE-2021-1659 HIGH 7.8 microsoft windows_10 Windows CSC Service Elevation of Privilege Vulnerability 0,7% —
CVE-2018-1353 MED 4.3 fortinet fortimanager An information disclosure vulnerability in Fortinet FortiManager 6.0.1 and below versions allows a standard user with adom assignment read the interface settings of vdoms unrelated to the assigned adom. 0,7% —
CVE-2015-7363 MED 5.4 fortinet fortianalyzer_firmware Cross-site scripting (XSS) vulnerability in the advanced settings page in Fortinet FortiManager 5.x before 5.0.12 and 5.2.x before 5.2.3, in hardware models with a hard disk, and FortiAnalyzer 5.x before 5.0.13 and 5.2.x before 5.2.3 allows remote administrato 0,7% —
CVE-2026-55956 MED 6.5 apache tomcat Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of the constraint. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22 0,7% —
CVE-2026-20837 HIGH 7.8 microsoft windows_10_1809 Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally. 0,7% —
CVE-2025-55674 MED 6.5 apache superset A bypass of the DISALLOWED_SQL_FUNCTIONS security feature in Apache Superset allows for the execution of blocked SQL functions. An attacker can use a special inline block to circumvent the denylist. This allows a user with SQL Lab access to execute functions t 0,7% —