58.650 CVE seguite
799 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.650 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2022-38432 | HIGH 7.8 | adobe photoshop Adobe Photoshop versions 22.5.8 (and earlier) and 23.4.2 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interac | 0,6% | — |
| CVE-2022-35708 | HIGH 7.8 | adobe bridge Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction | 0,6% | — |
| CVE-2022-31734 | MED 6.1 | cisco ws-c2940-8tf-s_firmware Cisco Catalyst 2940 Series Switches provided by Cisco Systems, Inc. contain a reflected cross-site scripting vulnerability regarding error page generation. An arbitrary script may be executed on the web browser of the user who is using the product. The affecte | 0,6% | — |
| CVE-2022-27875 | MED 5.5 | f5 access_for_android On F5 Access for Android 3.x versions prior to 3.0.8, a Task Hijacking vulnerability exists in the F5 Access for Android application, which may allow an attacker to steal sensitive user information. Note: Software versions which have reached End of Technical S | 0,6% | — |
| CVE-2022-20818 | HIGH 7.8 | cisco sd-wan Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. These vulnerabilities are due to improper access controls on commands within the application CLI. An attacker could exploit t | 0,6% | — |
| CVE-2020-3320 | MED 5.4 | cisco secure_firewall_management_center A vulnerability in the web-based management interface of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. | 0,6% | — |
| CVE-2020-3233 | MED 5.4 | cisco iox A vulnerability in the web-based Local Manager interface of the Cisco IOx Application Framework could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based Local Manager interface of an af | 0,6% | — |
| CVE-2020-3157 | MED 5.4 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface. The vulnerability is due to in | 0,6% | — |
| CVE-2020-24558 | HIGH 7.1 | trendmicro apex_one A vulnerability in an Trend Micro Apex One, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services dll may allow an attacker to manipulate it to cause an out-of-bounds read that crashes multiple processes in the product. An attacker mu | 0,6% | — |
| CVE-2019-19062 | MED 4.7 | canonical ubuntu_linux A memory leak in the crypto_report() function in crypto/crypto_user_base.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering crypto_report_alg() failures, aka CID-ffdde5932042. | 0,6% | — |
| CVE-2019-1890 | MED 6.5 | cisco application_policy_infrastructure_controller A vulnerability in the fabric infrastructure VLAN connection establishment of the Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an unauthenticated, adjacent attacker to bypass security validations and connect | 0,6% | — |
| CVE-2019-18196 | MED 6.7 | teamviewer teamviewer A DLL side loading vulnerability in the Windows Service in TeamViewer versions up to 11.0.133222 (fixed in 11.0.214397), 12.0.181268 (fixed in 12.0.214399), 13.2.36215 (fixed in 13.2.36216), and 14.6.4835 (fixed in 14.7.1965) on Windows could allow an attacker | 0,6% | — |
| CVE-2019-16008 | MED 5.4 | cisco ip_phone_6821_firmware A vulnerability in the web-based GUI of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface of an affected | 0,6% | — |
| CVE-2019-15968 | MED 5.4 | cisco hosted_collaboration_solution A vulnerability in the web-based management interface of Cisco Unified Communications Domain Manager (Unified CDM) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface | 0,6% | — |
| CVE-2019-12702 | MED 5.4 | cisco spa112_firmware A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to conduct cross-site scripting attacks. The vulnerability is due to insufficient validation of user-sup | 0,6% | — |
| CVE-2019-12638 | MED 5.4 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web-based management interface. The vulnerability is | 0,6% | — |
| CVE-2019-12637 | MED 5.4 | cisco identity_services_engine Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web-based management interface. The vulnera | 0,6% | — |
| CVE-2019-0024 | MED 5.4 | juniper advanced_threat_prevention A persistent cross-site scripting (XSS) vulnerability in the Email Collectors menu of Juniper ATP may allow authenticated user to inject arbitrary script and steal sensitive data and credentials from a web administration session, possibly tricking a follow-on | 0,6% | — |
| CVE-2013-6763 | MED 6.9 | linux linux_kernel The uio_mmap_physical function in drivers/uio/uio.c in the Linux kernel before 3.12 does not validate the size of a memory block, which allows local users to cause a denial of service (memory corruption) or possibly gain privileges via crafted mmap operations, | 0,6% | — |
| CVE-2026-70178 | HIGH 8.5 | microsoft fabric Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a network. | 0,6% | — |
| CVE-2026-69857 | HIGH 8.5 | microsoft azure_cosmos_db Authorization bypass through user-controlled key in Azure Cosmos DB allows an authorized attacker to perform spoofing over a network. | 0,6% | — |
| CVE-2026-65818 | HIGH 8.5 | microsoft power_platform Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network. | 0,6% | — |
| CVE-2026-43083 | CRIT 9.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: ioam6: fix OOB and missing lock When trace->type.bit6 is set: if (trace->type.bit6) { ... queue = skb_get_tx_queue(dev, skb); qdisc = rcu_dereference(queue- | 0,6% | — |
| CVE-2026-31636 | CRIT 9.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: rxrpc: fix RESPONSE authenticator parser OOB read rxgk_verify_authenticator() copies auth_len bytes into a temporary buffer and then passes p + auth_len as the parser limit to rxgk_do_verify | 0,6% | — |
| CVE-2026-28710 | CRIT 9.8 | acronis cyber_protect Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186. | 0,6% | — |