58.254 CVE seguite
789 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.254 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2015-7749 | HIGH 7.8 | juniper junos The PFE daemon in Juniper vSRX virtual firewalls with Junos OS before 15.1X49-D20 allows remote attackers to cause a denial of service via an unspecified connection request to the "host-OS." | 2,2% | — |
| CVE-2015-6327 | HIGH 7.8 | cisco adaptive_security_appliance_software The IKEv1 implementation in Cisco Adaptive Security Appliance (ASA) software 7.2 and 8.2 before 8.2(5.58), 8.3 and 8.4 before 8.4(7.29), 8.5 through 8.7 before 8.7(1.17), 9.0 before 9.0(4.37), 9.1 before 9.1(6.8), 9.2 before 9.2(4), and 9.3 before 9.3(3) allow | 2,2% | — |
| CVE-2006-7216 | MED 4.0 | apache derby Apache Derby before 10.2.1.6 does not determine privilege requirements for lock table statements at compilation time, and consequently does not enforce privilege requirements at execution time, which allows remote authenticated users to lock arbitrary tables. | 2,2% | — |
| CVE-2021-24109 | MED 6.8 | microsoft azure_kubernetes_service Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability | 2,2% | — |
| CVE-2018-0181 | HIGH 7.3 | cisco cisco_policy_suite_diameter_routing_agent A vulnerability in the Redis implementation used by the Cisco Policy Suite for Mobile and Cisco Policy Suite Diameter Routing Agent software could allow an unauthenticated, remote attacker to modify key-value pairs for short-lived events stored by the Redis se | 2,2% | — |
| CVE-2017-3151 | MED 6.1 | apache atlas Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to Stored Cross-Site Scripting in the edit-tag functionality. | 2,2% | — |
| CVE-2016-6397 | CRIT 9.8 | cisco ip_interoperability_and_collaboration_system A vulnerability in the interdevice communications interface of the Cisco IP Interoperability and Collaboration System (IPICS) Universal Media Services (UMS) could allow an unauthenticated, remote attacker to modify configuration parameters of the UMS and cause | 2,2% | — |
| CVE-2025-24993 | HIGH 7.8 | microsoft windows_10_1507 Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. | 2,2% | |
| CVE-2024-38160 | CRIT 9.1 | microsoft windows_10_1607 Windows Network Virtualization Remote Code Execution Vulnerability | 2,2% | — |
| CVE-2024-38159 | CRIT 9.1 | microsoft windows_10_1607 Windows Network Virtualization Remote Code Execution Vulnerability | 2,2% | — |
| CVE-2021-21683 | MED 6.5 | jenkins jenkins The file browser in Jenkins 2.314 and earlier, LTS 2.303.1 and earlier may interpret some paths to files as absolute on Windows, resulting in a path traversal vulnerability allowing attackers with Overall/Read permission (Windows controller) or Job/Workspace p | 2,2% | — |
| CVE-2013-6012 | HIGH 8.5 | juniper junos Juniper Junos 12.1X44 before 12.1.X44-D20 and 12.1X45 before 12.1X45-D15, when the no-validate option is enabled, does not properly handle configuration validation errors during the config commit phase of the boot-up sequence, which allows remote attackers to | 2,2% | — |
| CVE-2013-1148 | HIGH 7.8 | cisco ios The General Responder implementation in the IP Service Level Agreement (SLA) feature in Cisco IOS 15.2 and IOS XE 3.1.xS through 3.4.xS before 3.4.5S and 3.5.xS through 3.7.xS before 3.7.2S allows remote attackers to cause a denial of service (device reload) v | 2,2% | — |
| CVE-2022-25169 | MED 5.5 | apache tika The BPG parser in versions of Apache Tika before 1.28.2 and 2.4.0 may allocate an unreasonable amount of memory on carefully crafted files. | 2,2% | — |
| CVE-2021-42315 | HIGH 8.8 | microsoft defender_for_iot Microsoft Defender for IoT Remote Code Execution Vulnerability | 2,2% | — |
| CVE-2021-42314 | HIGH 8.8 | microsoft defender_for_iot Microsoft Defender for IoT Remote Code Execution Vulnerability | 2,2% | — |
| CVE-2015-3252 | CRIT 9.8 | apache cloudstack Apache CloudStack before 4.5.2 does not properly preserve VNC passwords when migrating KVM virtual machines, which allows remote attackers to gain access by connecting to the VNC server. | 2,2% | — |
| CVE-2022-38041 | HIGH 7.5 | microsoft windows_10 Windows Secure Channel Denial of Service Vulnerability | 2,2% | — |
| CVE-2022-28199 | MED 6.5 | nvidia data_plane_development_kit NVIDIA’s distribution of the Data Plane Development Kit (MLNX_DPDK) contains a vulnerability in the network stack, where error recovery is not handled properly, which can allow a remote attacker to cause denial of service and some impact to data integrity and | 2,2% | — |
| CVE-2022-38449 | MED 5.5 | adobe acrobat Adobe Acrobat Reader versions 22.002.20212 (and earlier) and 20.005.30381 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations s | 2,2% | — |
| CVE-2021-31942 | HIGH 7.8 | microsoft 3d_viewer 3D Viewer Remote Code Execution Vulnerability | 2,2% | — |
| CVE-2014-3329 | MED 4.3 | cisco prime_data_center_network_manager Cross-site scripting (XSS) vulnerability in the web-server component in Cisco Prime Data Center Network Manager (DCNM) 6.3(2) and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCum86620. | 2,2% | — |
| CVE-2006-0367 | MED 6.5 | cisco call_manager Unspecified vulnerability in Cisco CallManager 3.2 and earlier, 3.3 before 3.3(5)SR1, 4.0 before 4.0(2a)SR2c, and 4.1 before 4.1(3)SR2 allows remote authenticated users with read-only administrative privileges to obtain full administrative privileges via a "cr | 2,2% | — |
| CVE-2025-21369 | HIGH 8.8 | microsoft windows_10_1507 Microsoft Digest Authentication Remote Code Execution Vulnerability | 2,2% | — |
| CVE-2025-21368 | HIGH 8.8 | microsoft windows_10_1507 Microsoft Digest Authentication Remote Code Execution Vulnerability | 2,2% | — |