58.290 CVE seguite
789 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.290 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2015-0201 | MED 5.0 | pivotal_software spring_framework The Java SockJS client in Pivotal Spring Framework 4.1.x before 4.1.5 generates predictable session ids, which allows remote attackers to send messages to other sessions via unspecified vectors. | 1,9% | — |
| CVE-2011-1789 | MED 5.0 | vmware esx The self-extracting installer in the vSphere Client Installer package in VMware vCenter 4.0 before Update 3 and 4.1 before Update 1, VMware ESXi 4.x before 4.1 Update 1, and VMware ESX 4.x before 4.1 Update 1 does not have a digital signature, which might make | 1,9% | — |
| CVE-2011-1646 | HIGH 9.0 | cisco rvs4000 The web management interface on the Cisco RVS4000 Gigabit Security Router with software 1.x before 1.3.3.4 and 2.x before 2.0.2.7, and the WRVS4400N Gigabit Security Router with software before 2.0.2.1, allows remote authenticated users to execute arbitrary co | 1,9% | — |
| CVE-2008-2252 | HIGH 7.2 | microsoft windows_2000 The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate parameters sent from user mode to the kernel, which allows local users to gain privileges via a crafted applicatio | 1,9% | — |
| CVE-2022-38046 | HIGH 7.5 | microsoft windows_10 Web Account Manager Information Disclosure Vulnerability | 1,9% | — |
| CVE-2018-0333 | MED 5.8 | cisco secure_firewall_management_center A vulnerability in the VPN configuration management of Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to bypass VPN security due to unintended side effects of dynamic configuration changes that could allow an attacker to bypass | 1,9% | — |
| CVE-2012-1848 | HIGH 7.2 | microsoft windows_7 win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly handle user-mode input pass | 1,9% | — |
| CVE-2023-24942 | HIGH 7.5 | microsoft windows_10_1507 Remote Procedure Call Runtime Denial of Service Vulnerability | 1,9% | — |
| CVE-2021-25236 | MED 5.3 | trendmicro officescan A server-side request forgery (SSRF) information disclosure vulnerability in Trend Micro OfficeScan XG SP1 and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to locate online agents via a specific sweep. | 1,9% | — |
| CVE-2020-27016 | HIGH 8.8 | trendmicro interscan_messaging_security_virtual_appliance Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to a cross-site request forgery (CSRF) vulnerability which could allow an attacker to modify policy rules by tricking an authenticated administrator into accessing an attacker | 1,9% | — |
| CVE-2017-6612 | HIGH 8.6 | cisco asr_5000_series_software A vulnerability in the gateway GPRS support node (GGSN) of Cisco ASR 5000 Series Aggregation Services Routers 17.3.9.62033 through 21.1.2 could allow an unauthenticated, remote attacker to redirect HTTP traffic sent to an affected device. More Information: CSC | 1,9% | — |
| CVE-2017-0298 | HIGH 7.3 | microsoft windows_10 A DCOM object in Helppane.exe in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016, when configured to run as the interactive us | 1,9% | — |
| CVE-2023-35381 | HIGH 8.8 | microsoft windows_10_1507 Windows Fax Service Remote Code Execution Vulnerability | 1,9% | — |
| CVE-2022-24534 | HIGH 7.5 | microsoft windows_10 Win32 Stream Enumeration Remote Code Execution Vulnerability | 1,9% | — |
| CVE-2013-3415 | HIGH 7.8 | cisco adaptive_security_appliance_software Cisco Adaptive Security Appliance (ASA) Software 8.4.x before 8.4(3) and 8.6.x before 8.6(1.3) does not properly manage memory upon an AnyConnect SSL VPN client disconnection, which allows remote attackers to cause a denial of service (memory consumption, and | 1,9% | — |
| CVE-2003-0216 | HIGH 9.3 | cisco catos Unknown vulnerability in Cisco Catalyst 7.5(1) allows local users to bypass authentication and gain access to the enable mode without a password. | 1,9% | — |
| CVE-2022-34717 | HIGH 8.8 | microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability | 1,9% | — |
| CVE-2019-14209 | CRIT 9.8 | foxitsoftware phantompdf An issue was discovered in Foxit PhantomPDF before 8.3.10. The application could be exposed to Heap Corruption due to data desynchrony when adding AcroForm. | 1,9% | — |
| CVE-2018-1000204 | MED 5.3 | canonical ubuntu_linux Linux Kernel version 3.18 to 4.16 incorrectly handles an SG_IO ioctl on /dev/sg0 with dxfer_direction=SG_DXFER_FROM_DEV and an empty 6-byte cmdp. This may lead to copying up to 1000 kernel heap pages to the userspace. This has been fixed upstream in https://gi | 1,9% | — |
| CVE-2026-32203 | HIGH 7.5 | microsoft .net Stack-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to deny service over a network. | 1,9% | — |
| CVE-2025-26663 | HIGH 8.1 | microsoft windows_10_1507 Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network. | 1,9% | — |
| CVE-2024-27894 | HIGH 8.5 | apache pulsar The Pulsar Functions Worker includes a capability that permits authenticated users to create functions where the function's implementation is referenced by a URL. The supported URL schemes include "file", "http", and "https". When a function is created using t | 1,9% | — |
| CVE-2023-25693 | CRIT 9.8 | apache apache-airflow-providers-apache-sqoop Improper Input Validation vulnerability in the Apache Airflow Sqoop Provider. This issue affects Apache Airflow Sqoop Provider versions before 3.1.1. | 1,9% | — |
| CVE-2020-2006 | HIGH 7.2 | paloaltonetworks pan-os A stack-based buffer overflow vulnerability in the management server component of PAN-OS that allows an authenticated user to potentially execute arbitrary code with root privileges. This issue affects: All versions of PAN-OS 7.1 and 8.0; PAN-OS 8.1 versions e | 1,9% | — |
| CVE-2018-0460 | MED 6.5 | cisco network_functions_virtualization_infrastructure A vulnerability in the REST API of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to read any file on an affected system. The vulnerability is due to insufficient authorization and parameter validation checks | 1,9% | — |