58.285 CVE seguite
789 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.285 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2021-27265 | LOW 3.3 | foxitsoftware foxit_reader This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PhantomPDF 10.1.0.37527. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicio | 2,0% | — |
| CVE-2021-27262 | LOW 3.3 | foxitsoftware foxit_reader This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PhantomPDF 10.1.0.37527. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicio | 2,0% | — |
| CVE-2013-5971 | MED 6.8 | vmware vcenter_server Session fixation vulnerability in the vSphere Web Client Server in VMware vCenter Server 5.0 before Update 3 allows remote attackers to hijack web sessions and gain privileges via unspecified vectors. | 2,0% | — |
| CVE-2013-5554 | HIGH 7.5 | cisco wide_area_application_services_mobile Directory traversal vulnerability in the web-management interface in the server in Cisco Wide Area Application Services (WAAS) Mobile before 3.5.5 allows remote attackers to upload and execute arbitrary files via a crafted POST request, aka Bug ID CSCuh69773. | 2,0% | — |
| CVE-2022-41042 | HIGH 7.4 | microsoft visual_studio_code Visual Studio Code Information Disclosure Vulnerability | 2,0% | — |
| CVE-2018-0309 | HIGH 7.7 | cisco nx-os A vulnerability in the implementation of a specific CLI command and the associated Simple Network Management Protocol (SNMP) MIB for Cisco NX-OS (in standalone NX-OS mode) on Cisco Nexus 3000 and 9000 Series Switches could allow an authenticated, remote attack | 2,0% | — |
| CVE-2019-0636 | MED 5.5 | microsoft windows_10 An information vulnerability exists when Windows improperly discloses file information, aka 'Windows Information Disclosure Vulnerability'. | 2,0% | — |
| CVE-2018-0344 | HIGH 7.2 | cisco vbond_orchestrator A vulnerability in the vManage dashboard for the configuration and management service of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject and execute arbitrary commands with vmanage user privileges on an affected system. The vu | 2,0% | — |
| CVE-2017-8554 | MED 4.7 | microsoft windows_10 The kernel in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an authenticated attacker to obtain memory contents via | 2,0% | — |
| CVE-2017-6651 | HIGH 7.5 | cisco webex_meetings_server A vulnerability in Cisco WebEx Meetings Server could allow unauthenticated, remote attackers to gain information that could allow them to access scheduled customer meetings. The vulnerability is due to an incomplete configuration of the robots.txt file on cust | 2,0% | — |
| CVE-2016-10609 | HIGH 8.1 | chromedriver126_project chromedriver126 chromedriver126 is chromedriver version 1.26 for linux OS. chromedriver126 downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an at | 2,0% | — |
| CVE-2013-6170 | MED 4.3 | juniper junos Juniper Junos 10.0 before 10.0S28, 10.4 before 10.4R7, 11.1 before 11.1R5, 11.2 before 11.2R2, and 11.4 before 11.4R1, when in a Next-Generation Multicast VPN (NGEN MVPN) environment, allows remote attackers to cause a denial of service (RPD routing daemon cra | 2,0% | — |
| CVE-2013-6015 | MED 4.3 | juniper junos Juniper Junos before 10.4S14, 11.4 before 11.4R5-S2, 12.1R before 12.1R3, 12.1X44 before 12.1X44-D20, and 12.1X45 before 12.1X45-D15 on SRX Series services gateways, when a plugin using TCP proxy is configured, allows remote attackers to cause a denial of serv | 2,0% | — |
| CVE-2026-26132 | HIGH 7.8 | microsoft windows_10_21h2 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 2,0% | — |
| CVE-2025-55693 | HIGH 7.4 | microsoft windows_11_24h2 Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally. | 2,0% | — |
| CVE-2023-28303 | LOW 3.3 | microsoft snip_\&_sketch Windows Snipping Tool Information Disclosure Vulnerability | 2,0% | — |
| CVE-2023-20869 | HIGH 8.2 | vmware fusion VMware Workstation (17.x) and VMware Fusion (13.x) contain a stack-based buffer-overflow vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine. | 2,0% | — |
| CVE-2020-17508 | HIGH 7.5 | apache traffic_server The ATS ESI plugin has a memory disclosure vulnerability. If you are running the plugin please upgrade. Apache Traffic Server versions 7.0.0 to 7.1.11 and 8.0.0 to 8.1.0 are affected. | 2,0% | — |
| CVE-2018-11802 | MED 4.3 | apache solr In Apache Solr, the cluster can be partitioned into multiple collections and only a subset of nodes actually host any given collection. However, if a node receives a request for a collection it does not host, it proxies the request to a relevant node and serve | 2,0% | — |
| CVE-2017-12614 | MED 6.1 | apache airflow It was noticed an XSS in certain 404 pages that could be exploited to perform an XSS attack. Chrome will detect this as a reflected XSS attempt and prevent the page from loading. Firefox and other browsers don't, and are vulnerable to this attack. Mitigation: | 2,0% | — |
| CVE-2016-6416 | MED 5.9 | cisco content_security_management_appliance The FTP service in Cisco AsyncOS on Email Security Appliance (ESA) devices 9.6.0-000 through 9.9.6-026, Web Security Appliance (WSA) devices 9.0.0-162 through 9.5.0-444, and Content Security Management Appliance (SMA) devices allows remote attackers to cause a | 2,0% | — |
| CVE-2015-0591 | MED 5.0 | cisco unified_communications_domain_manager Cisco Unified Communications Domain Manager (UCDM) 10 allows remote attackers to cause a denial of service (daemon hang and GUI outage) via a flood of malformed TCP packets, aka Bug ID CSCur44177. | 2,0% | — |
| CVE-2015-0579 | MED 5.0 | cisco telepresence_video_communication_server Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway allow remote attackers to cause a denial of service (memory and CPU consumption, and partial outage) via crafted SIP packets, aka Bug ID CSCur12473. | 2,0% | — |
| CVE-2012-5416 | HIGH 7.8 | cisco unified_meetingplace Buffer overflow in Cisco Unified MeetingPlace Web Conferencing before 7.1MR1 Patch 1, 8.0 before 8.0MR1 Patch 1, and 8.5 before 8.5MR3 allows remote attackers to cause a denial of service (daemon hang) via unspecified parameters in a POST request, aka Bug ID C | 2,0% | — |
| CVE-2021-40760 | HIGH 7.8 | adobe after_effects Adobe After Effects version 18.4.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious .m4a file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is requi | 2,0% | — |