58.290 CVE seguite
789 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.290 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2025-21389 | HIGH 7.5 | microsoft windows_10_1507 Uncontrolled resource consumption in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to deny service over a network. | 1,9% | — |
| CVE-2021-28592 | HIGH 7.8 | adobe illustrator Adobe Illustrator version 25.2.3 (and earlier) is affected by an Out-of-bounds Write vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the cu | 1,9% | — |
| CVE-2021-28591 | HIGH 7.8 | adobe illustrator Adobe Illustrator version 25.2.3 (and earlier) is affected by an Out-of-bounds Write vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the cu | 1,9% | — |
| CVE-2017-12623 | MED 6.5 | apache nifi An authorized user could upload a template which contained malicious code and accessed sensitive files via an XML External Entity (XXE) attack. The fix to properly handle XML External Entities was applied on the Apache NiFi 1.4.0 release. Users running a prior | 1,9% | — |
| CVE-2025-23242 | HIGH 7.3 | nvidia riva NVIDIA Riva contains a vulnerability where a user could cause an improper access control issue. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, denial of service, or information disclosure. | 1,9% | — |
| CVE-2022-29143 | HIGH 7.5 | microsoft sql_server Microsoft SQL Server Remote Code Execution Vulnerability | 1,9% | — |
| CVE-2019-1763 | HIGH 7.5 | cisco ip_conference_phone_8832_firmware A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an unauthenticated, remote attacker to bypass authorization, access critical services, and cause a denial of service | 1,9% | — |
| CVE-2018-17341 | HIGH 8.1 | bigtreecms bigtree_cms BigTree 4.2.23 on Windows, when Advanced or Simple Rewrite routing is enabled, allows remote attackers to bypass authentication via a ..\ substring, as demonstrated by a launch.php?bigtree_htaccess_url=admin/images/..\ URI. | 1,9% | — |
| CVE-2018-0343 | HIGH 8.8 | cisco vbond_orchestrator A vulnerability in the configuration and management service of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to execute arbitrary code with vmanage user privileges or cause a denial of service (DoS) condition on an affected system. Th | 1,9% | — |
| CVE-2016-6399 | HIGH 7.5 | cisco ace_4700_series_application_control_engine_appliance Cisco ACE30 Application Control Engine Module through A5 3.3 and ACE 4700 Application Control Engine appliances through A5 3.3 allow remote attackers to cause a denial of service (device reload) via crafted (1) SSL or (2) TLS packets, aka Bug ID CSCvb16317. | 1,9% | — |
| CVE-2016-6391 | HIGH 7.5 | cisco ios Cisco IOS 12.2 and 15.0 through 15.3 allows remote attackers to cause a denial of service (traffic-processing outage) via a crafted series of Common Industrial Protocol (CIP) requests, aka Bug ID CSCur69036. | 1,9% | — |
| CVE-2016-6378 | HIGH 7.5 | cisco ios_xe Cisco IOS XE 3.1 through 3.17 and 16.1 through 16.2 allows remote attackers to cause a denial of service (device reload) via crafted ICMP packets that require NAT, aka Bug ID CSCuw85853. | 1,9% | — |
| CVE-2016-1483 | HIGH 7.5 | cisco webex_meetings_server Cisco WebEx Meetings Server 2.6 allows remote attackers to cause a denial of service (CPU consumption) by repeatedly accessing the account-validation component of an unspecified service, aka Bug ID CSCuy92704. | 1,9% | — |
| CVE-2016-1478 | HIGH 7.5 | cisco ios Cisco IOS 15.5(3)S3, 15.6(1)S2, 15.6(2)S1, and 15.6(2)T1 does not properly dequeue invalid NTP packets, which allows remote attackers to cause a denial of service (interface wedge) by sending many crafted NTP packets, aka Bug ID CSCva35619. | 1,9% | — |
| CVE-2016-1426 | HIGH 7.5 | cisco ios_xr Cisco IOS XR 5.x through 5.2.5 on NCS 6000 devices allows remote attackers to cause a denial of service (timer consumption and Route Processor reload) via crafted SSH traffic, aka Bug ID CSCux76819. | 1,9% | — |
| CVE-2015-6396 | HIGH 7.8 | cisco rv110w_wireless-n_vpn_firewall_firmware The CLI command parser on Cisco RV110W, RV130W, and RV215W devices allows local users to execute arbitrary shell commands as an administrator via crafted parameters, aka Bug IDs CSCuv90134, CSCux58161, and CSCux73567. | 1,9% | — |
| CVE-2015-0725 | HIGH 7.8 | cisco videoscape_distribution_suite_for_internet_streaming Cisco Videoscape Distribution Suite Service Broker (aka VDS-SB), when a VDSM configuration on UCS is used, and Videoscape Distribution Suite for Internet Streaming (aka VDS-IS or CDS-IS) before 3.3.1 R7 and 4.x before 4.0.0 R4 allow remote attackers to cause a | 1,9% | — |
| CVE-2023-36401 | HIGH 7.2 | microsoft windows_10_1507 Microsoft Remote Registry Service Remote Code Execution Vulnerability | 1,9% | — |
| CVE-2018-1274 | HIGH 7.5 | broadcom spring_data_commons Spring Data Commons, versions 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property path parser vulnerability caused by unlimited resource allocation. An unauthenticated remote malicious user (or attacker) can issue requests against | 1,9% | — |
| CVE-2010-3939 | HIGH 7.2 | microsoft windows_2003_server Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges via vectors related to | 1,9% | — |
| CVE-2008-5542 | HIGH 9.3 | sunbeltsoftware vipre Sunbelt VIPRE 3.1.1832.2 and possibly 3.1.1633.1, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1 | 1,9% | — |
| CVE-2008-5540 | HIGH 9.3 | secure_computing secure_web_gateway Secure Computing Secure Web Gateway (aka Webwasher), when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have | 1,9% | — |
| CVE-2008-5538 | HIGH 9.3 | prevx prevx1 Prevx Prevx1 2, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extensi | 1,9% | — |
| CVE-2008-5524 | HIGH 9.3 | quickheal cat_quickheal CAT-QuickHeal 10.00 and possibly 9.50, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extens | 1,9% | — |
| CVE-2023-22273 | HIGH 7.2 | adobe robohelp_server Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to Remote Code Execution by an admin authenticated attacker. Exploitation of this is | 1,9% | — |