58.273 CVE seguite
789 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.273 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2017-3884 | MED 6.5 | cisco evolved_programmable_network_manager A vulnerability in the web interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to access sensitive data. The attacker does not need administrator credentials and could use t | 2,1% | — |
| CVE-2017-3824 | MED 6.8 | cisco ios_xe A vulnerability in the handling of list headers in Cisco cBR Series Converged Broadband Routers could allow an unauthenticated, remote attacker to cause the device to reload, resulting in a denial of service (DoS) condition. Cisco cBR-8 Converged Broadband Rou | 2,1% | — |
| CVE-2013-6480 | LOW 2.1 | apache libcloud Libcloud 0.12.3 through 0.13.2 does not set the scrub_data parameter for the destroy DigitalOcean API, which allows local users to obtain sensitive information by leveraging a new VM. | 2,1% | — |
| CVE-2011-0090 | HIGH 7.2 | microsoft windows_2003_server win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate user-mode input, which allows local users to gain pri | 2,1% | — |
| CVE-2010-2025 | MED 6.8 | cisco scientific_atlanta_webstar_dpc2100r2 Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface on the Cisco Scientific Atlanta WebSTAR DPC2100R2 cable modem with firmware 2.0.2r1256-060303 allow remote attackers to hijack the authentication of administrators for requests tha | 2,1% | — |
| CVE-2021-43016 | MED 5.5 | adobe incopy Adobe InCopy version 16.4 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of t | 2,1% | — |
| CVE-2021-21061 | LOW 3.3 | adobe acrobat Acrobat Pro DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a Use-after-free vulnerability when parsing a specially crafted PDF file. An unauthenticated attacker could leverage th | 2,1% | — |
| CVE-2024-39426 | HIGH 7.8 | adobe acrobat Acrobat Reader versions 20.005.30636, 24.002.20965, 24.002.20964, 24.001.30123 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker | 2,1% | — |
| CVE-2022-30145 | HIGH 7.5 | microsoft windows_10 Windows Encrypting File System (EFS) Remote Code Execution Vulnerability | 2,1% | — |
| CVE-2022-23974 | HIGH 7.5 | apache pinot In 0.9.3 or older versions of Apache Pinot segment upload path allowed segment directories to be imported into pinot tables. In pinot installations that allow open access to the controller a specially crafted request can potentially be exploited to cause disru | 2,1% | — |
| CVE-2021-41357 | HIGH 7.8 | microsoft windows_10_2004 Win32k Elevation of Privilege Vulnerability | 2,1% | |
| CVE-2021-40450 | HIGH 7.8 | microsoft windows_10_1809 Win32k Elevation of Privilege Vulnerability | 2,1% | |
| CVE-2019-1868 | HIGH 7.5 | cisco webex_meetings_server A vulnerability in the web-based management interface of Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to access sensitive system information. The vulnerability is due to improper access control to files within the web-based manag | 2,1% | — |
| CVE-2008-3579 | HIGH 7.8 | calacode atmail Calacode @Mail 5.41 on Linux does not require administrative authentication for build-plesk-upgrade.php, which allows remote attackers to obtain sensitive information by creating and downloading a backup archive of the entire @Mail directory tree. NOTE: this | 2,1% | — |
| CVE-2024-26163 | MED 4.7 | microsoft edge_chromium Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | 2,1% | — |
| CVE-2022-21991 | HIGH 8.1 | microsoft visual_studio_code Visual Studio Code Remote Development Extension Remote Code Execution Vulnerability | 2,1% | — |
| CVE-2017-12622 | HIGH 7.1 | apache geode When an Apache Geode cluster before v1.3.0 is operating in secure mode and an authenticated user connects to a Geode cluster using the gfsh tool with HTTP, the user is able to obtain status information and control cluster members even without CLUSTER:MANAGE pr | 2,1% | — |
| CVE-2025-49220 | CRIT 9.8 | trendmicro apex_central An insecure deserialization operation in Trend Micro Apex Central below version 8.0.7007 could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49219 but is in a different method. | 2,1% | — |
| CVE-2023-34478 | CRIT 9.8 | apache shiro Apache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentication bypass when used together with APIs or other web frameworks that route requests based on non-normalized requests. Mitigation: Update | 2,1% | — |
| CVE-2020-3336 | HIGH 7.2 | cisco roomos A vulnerability in the software upgrade process of Cisco TelePresence Collaboration Endpoint Software and Cisco RoomOS Software could allow an authenticated, remote attacker to modify the filesystem to cause a denial of service (DoS) or gain privileged access | 2,1% | — |
| CVE-2019-17560 | CRIT 9.1 | apache netbeans The "Apache NetBeans" autoupdate system does not validate SSL certificates and hostnames for https based downloads. This allows an attacker to intercept downloads of autoupdates and modify the download, potentially injecting malicious code. “Apache NetBeans" v | 2,1% | — |
| CVE-2015-4182 | MED 5.5 | cisco identity_services_engine_software The administrative web interface in Cisco Identity Services Engine (ISE) before 1.3 allows remote authenticated users to bypass intended access restrictions, and obtain sensitive information or change settings, via unspecified vectors, aka Bug ID CSCui72087. | 2,1% | — |
| CVE-2001-0016 | HIGH 7.2 | microsoft windows_nt NTLM Security Support Provider (NTLMSSP) service does not properly check the function number in an LPC request, which could allow local users to gain administrator level access. | 2,1% | — |
| CVE-2021-25640 | MED 6.1 | apache dubbo In Apache Dubbo prior to 2.6.9 and 2.7.9, the usage of parseURL method will lead to the bypass of white host check which can cause open redirect or SSRF vulnerability. | 2,1% | — |
| CVE-2021-44739 | MED 4.3 | adobe acrobat Acrobat Reader DC ActiveX Control versions 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by an Information Disclosure vulnerability. An unauthenticated attacker could leverage this vulnerability to obtain NT | 2,1% | — |