58.151 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.151 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2014-3289 | MED 4.3 | cisco content_security_management_appliance Cross-site scripting (XSS) vulnerability in the web management interface in Cisco AsyncOS on the Email Security Appliance (ESA) 8.0, Web Security Appliance (WSA) 8.0 (.5 Hot Patch 1) and earlier, and Content Security Management Appliance (SMA) 8.3 and earlier | 2,4% | — |
| CVE-2014-2309 | MED 6.1 | linux linux_kernel The ip6_route_add function in net/ipv6/route.c in the Linux kernel through 3.13.6 does not properly count the addition of routes, which allows remote attackers to cause a denial of service (memory consumption) via a flood of ICMPv6 Router Advertisement packets | 2,4% | — |
| CVE-2021-35999 | HIGH 7.8 | adobe prelude Adobe Prelude version 10.0 (and earlier) is affected by a memory corruption vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current use | 2,4% | — |
| CVE-2018-1786 | MED 5.3 | ibm spectrum_protect IBM Spectrum Protect 7.1 and 8.1 dsmc and dsmcad processes incorrectly accumulate TCP/IP sockets in a CLOSE_WAIT state. This can cause TCP/IP resource leakage and may result in a denial of service. IBM X-Force ID: 148871. | 2,4% | — |
| CVE-2016-1956 | MED 6.5 | mozilla firefox Mozilla Firefox before 45.0 on Linux, when an Intel video driver is used, allows remote attackers to cause a denial of service (memory consumption or stack memory corruption) by triggering use of a WebGL shader. | 2,4% | — |
| CVE-2015-5738 | HIGH 7.5 | f5 traffix_signaling_delivery_controller The RSA-CRT implementation in the Cavium Software Development Kit (SDK) 2.x, when used on OCTEON II CN6xxx Hardware on Linux to support TLS with Perfect Forward Secrecy (PFS), makes it easier for remote attackers to obtain private RSA keys by conducting a Lens | 2,4% | — |
| CVE-2022-41106 | HIGH 8.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 2,4% | — |
| CVE-2018-0277 | HIGH 8.6 | cisco identity_services_engine A vulnerability in the Extensible Authentication Protocol-Transport Layer Security (EAP-TLS) certificate validation during EAP authentication for the Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause the ISE applicat | 2,4% | — |
| CVE-2022-3594 | MED 5.3 | debian debian_linux A vulnerability was found in Linux Kernel. It has been declared as problematic. Affected by this vulnerability is the function intr_callback of the file drivers/net/usb/r8152.c of the component BPF. The manipulation leads to logging of excessive data. The atta | 2,4% | — |
| CVE-2008-7032 | MED 6.8 | f5 big-ip Web Management Console Cross-site request forgery (CSRF) vulnerability in the web management console in F5 BIG-IP 9.4.3 allows remote attackers to hijack the authentication of administrators for requests that create new administrators and execute shell command | 2,4% | — |
| CVE-2022-24097 | HIGH 7.8 | adobe after_effects Adobe After Effects versions 22.2 (and earlier) and 18.4.4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction | 2,4% | — |
| CVE-2018-11782 | MED 6.5 | apache subversion In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit when a well-formed read-only request produces a particular answer. This can lead to disruption for users of the server. | 2,4% | — |
| CVE-2015-0771 | MED 6.3 | cisco ios The IKE implementation in the WS-IPSEC-3 service module in Cisco IOS 12.2 on Catalyst 6500 devices allows remote authenticated users to cause a denial of service (device reload) by sending a crafted message during IPsec tunnel setup, aka Bug ID CSCur70505. | 2,4% | — |
| CVE-2025-21276 | HIGH 7.5 | microsoft windows_10_1507 Windows MapUrlToZone Denial of Service Vulnerability | 2,4% | — |
| CVE-2021-34533 | HIGH 7.8 | microsoft windows_10 Windows Graphics Component Font Parsing Remote Code Execution Vulnerability | 2,4% | — |
| CVE-2021-34530 | HIGH 7.8 | microsoft windows_10 Windows Graphics Component Remote Code Execution Vulnerability | 2,4% | — |
| CVE-2018-0908 | MED 6.1 | microsoft identity_manager Microsoft Identity Manager 2016 SP1 allows an attacker to gain elevated privileges when it does not properly sanitize a specially crafted attribute value being displayed to a user on an affected MIM 2016 server, aka "Microsoft Identity Manager XSS Elevation of | 2,4% | — |
| CVE-2022-30651 | HIGH 7.8 | adobe incopy Adobe InCopy versions 17.2 (and earlier) and 16.4.1 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulne | 2,4% | — |
| CVE-2017-8707 | MED 5.3 | microsoft windows_10 The Windows Hyper-V component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it fails to properly | 2,4% | — |
| CVE-2017-8706 | MED 5.3 | microsoft windows_10 The Windows Hyper-V component on Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper | 2,4% | — |
| CVE-2005-0177 | HIGH 7.8 | linux linux_kernel nls_ascii.c in Linux before 2.6.8.1 uses an incorrect table size, which allows attackers to cause a denial of service (kernel crash) via a buffer overflow. | 2,4% | — |
| CVE-2026-40398 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Remote Desktop allows an authorized attacker to elevate privileges locally. | 2,4% | — |
| CVE-2024-38015 | HIGH 7.5 | microsoft windows_server_2012 Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability | 2,4% | — |
| CVE-2021-43882 | CRIT 9.0 | microsoft defender_for_iot Microsoft Defender for IoT Remote Code Execution Vulnerability | 2,4% | — |
| CVE-2019-0871 | MED 6.1 | microsoft azure_devops_server A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability'. This CVE ID is unique f | 2,4% | — |