58.254 CVE seguite
789 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.254 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-32178 | HIGH 7.5 | microsoft .net Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoofing over a network. | 2,3% | — |
| CVE-2018-4278 | MED 4.3 | apple icloud In Safari before 11.1.2, iTunes before 12.8 for Windows, iOS before 11.4.1, tvOS before 11.4.1, iCloud for Windows before 7.6, sound fetched through audio elements may be exfiltrated cross-origin. This issue was addressed with improved audio taint tracking. | 2,3% | — |
| CVE-2018-0754 | MED 5.5 | microsoft windows_10 The Windows Adobe Type Manager Font Driver (Atmfd.dll) in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 al | 2,3% | — |
| CVE-2015-4306 | HIGH 8.5 | cisco prime_collaboration_assurance The web framework in Cisco Prime Collaboration Assurance before 10.5.1.53684-1 allows remote authenticated users to bypass intended login-session read restrictions, and impersonate administrators of arbitrary tenant domains, by discovering a session identifier | 2,3% | — |
| CVE-2024-43515 | HIGH 7.5 | microsoft windows_10_1507 Internet Small Computer Systems Interface (iSCSI) Denial of Service Vulnerability | 2,3% | — |
| CVE-2024-20401 | CRIT 9.8 | cisco secure_email_gateway A vulnerability in the content scanning and message filtering features of Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to overwrite arbitrary files on the underlying operating system. This vulnerability is due to improper handl | 2,3% | — |
| CVE-2022-41073 | HIGH 7.8 | ransomware microsoft windows_10_1507 Windows Print Spooler Elevation of Privilege Vulnerability | 2,3% | |
| CVE-2019-8162 | HIGH 8.1 | adobe acrobat_dc Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have a race condition vulnerability. Successful exploitation could lead to arbitr | 2,3% | — |
| CVE-2018-0245 | MED 5.3 | cisco wireless_lan_controller_software A vulnerability in the REST API of Cisco 5500 and 8500 Series Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to view system information that under normal circumstances should be prohibited. The vulnerability is due to in | 2,3% | — |
| CVE-2017-10617 | MED 5.0 | juniper contrail The ifmap service that comes bundled with Contrail has an XML External Entity (XXE) vulnerability that may allow an attacker to retrieve sensitive system files. Affected releases are Juniper Networks Contrail 2.2 prior to 2.21.4; 3.0 prior to 3.0.3.4; 3.1 prio | 2,3% | — |
| CVE-2012-0366 | HIGH 9.0 | cisco unity_connection Cisco Unity Connection before 7.1.3b(Su2) allows remote authenticated users to change the administrative password by leveraging the Help Desk Administrator role, aka Bug ID CSCtd45141. | 2,3% | — |
| CVE-2009-3722 | HIGH 7.1 | linux linux_kernel The handle_dr function in arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 2.6.31.1 does not properly verify the Current Privilege Level (CPL) before accessing a debug register, which allows guest OS users to cause a denial of service (trap) | 2,3% | — |
| CVE-2022-24457 | HIGH 7.8 | microsoft heif_image_extension HEIF Image Extensions Remote Code Execution Vulnerability | 2,3% | — |
| CVE-2022-24451 | HIGH 7.8 | microsoft vp9_video_extensions VP9 Video Extensions Remote Code Execution Vulnerability | 2,3% | — |
| CVE-2022-22709 | HIGH 7.8 | microsoft vp9_video_extensions VP9 Video Extensions Remote Code Execution Vulnerability | 2,3% | — |
| CVE-2021-45056 | HIGH 7.8 | adobe incopy Adobe InCopy version 16.4 (and earlier) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a mali | 2,3% | — |
| CVE-2020-12817 | HIGH 8.8 | fortinet fortianalyzer An improper neutralization of input vulnerability in FortiAnalyzer before 6.4.1 and 6.2.5 may allow a remote authenticated attacker to inject script related HTML tags via Name parameter of Storage Connectors. | 2,3% | — |
| CVE-2018-0447 | MED 5.3 | cisco email_security_appliance A vulnerability in the anti-spam protection mechanisms of Cisco AsyncOS Software for the Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass certain content filters on an affected device. The vulnerability is due to i | 2,3% | — |
| CVE-2017-6692 | HIGH 8.8 | cisco ultra_services_framework_element_manager A vulnerability in Cisco Ultra Services Framework Element Manager could allow an authenticated, remote attacker to log in to the device with the privileges of the root user, aka an Insecure Default Account Information Vulnerability. More Information: CSCvd8571 | 2,3% | — |
| CVE-2017-6688 | HIGH 8.8 | cisco elastic_services_controller A vulnerability in Cisco Elastic Services Controllers could allow an authenticated, remote attacker to log in to an affected system as the Linux root user, aka an Insecure Default Password Vulnerability. More Information: CSCvc76631. Known Affected Releases: 2 | 2,3% | — |
| CVE-2017-6684 | HIGH 8.8 | cisco elastic_services_controller A vulnerability in Cisco Elastic Services Controllers could allow an authenticated, remote attacker to log in to an affected system as the Linux admin user, aka an Insecure Default Credentials Vulnerability. More Information: CSCvc76651. Known Affected Release | 2,3% | — |
| CVE-2021-38661 | HIGH 7.8 | microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability | 2,3% | — |
| CVE-2021-38660 | HIGH 7.8 | microsoft excel Microsoft Office Graphics Remote Code Execution Vulnerability | 2,3% | — |
| CVE-2021-38644 | HIGH 7.8 | microsoft mpeg-2_video_extension Microsoft MPEG-2 Video Extension Remote Code Execution Vulnerability | 2,3% | — |
| CVE-2013-5509 | HIGH 10.0 | cisco adaptive_security_appliance_software The SSL implementation in Cisco Adaptive Security Appliance (ASA) Software 9.0 before 9.0(2.6) and 9.1 before 9.1(2) allows remote attackers to bypass authentication, and obtain VPN access or administrative access, via a crafted X.509 client certificate, aka B | 2,3% | — |