EN
58.304 CVE seguite
789 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.304 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più alto In KEV dal, ordina dal più alto
CVE-2019-12678 HIGH 7.5 cisco adaptive_security_appliance A vulnerability in the Session Initiation Protocol (SIP) inspection module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) 1,8% —
CVE-2019-12659 HIGH 7.5 cisco ios_xe A vulnerability in the HTTP server code of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the HTTP server to crash. The vulnerability is due to a logical error in the logging mechanism. An attacker could exploit this vulnerabili 1,8% —
CVE-2019-12656 HIGH 7.5 cisco cgr_1000_firmware A vulnerability in the IOx application environment of multiple Cisco platforms could allow an unauthenticated, remote attacker to cause the IOx web server to stop processing HTTPS requests, resulting in a denial of service (DoS) condition. The vulnerability is 1,8% —
CVE-2010-1146 MED 6.9 linux linux_kernel The Linux kernel 2.6.33.2 and earlier, when a ReiserFS filesystem exists, does not restrict read or write access to the .reiserfs_priv directory, which allows local users to gain privileges by modifying (1) extended attributes or (2) ACLs, as demonstrated by d 1,8% —
CVE-2024-38104 HIGH 8.8 microsoft windows_10_1507 Windows Fax Service Remote Code Execution Vulnerability 1,8% —
CVE-2023-35329 MED 6.5 microsoft windows_10_1507 Windows Authentication Denial of Service Vulnerability 1,8% —
CVE-2021-26109 HIGH 8.1 fortinet fortios An integer overflow or wraparound vulnerability in the memory allocator of SSLVPN in FortiOS before 7.0.1 may allow an unauthenticated attacker to corrupt control data on the heap via specifically crafted requests to SSLVPN, resulting in potentially arbitrary 1,8% —
CVE-2019-12207 CRIT 9.8 f5 njs njs through 0.3.1, used in NGINX, has a heap-based buffer over-read in nxt_utf8_decode in nxt/nxt_utf8.c. 1,8% —
CVE-2018-15396 MED 6.8 cisco unity_connection A vulnerability in the Bulk Administration Tool (BAT) for Cisco Unity Connection could allow an authenticated, remote attacker to cause high disk utilization, resulting in a denial of service (DoS) condition. The vulnerability exists because the affected softw 1,8% —
CVE-2018-0386 MED 6.1 cisco hosted_collaboration_solution A vulnerability in Cisco Unified Communications Domain Manager Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on an affected system. The vulnerability is due to improper validation of input that is passe 1,8% —
CVE-2017-0528 HIGH 7.8 linux linux_kernel An elevation of privilege vulnerability in the kernel security subsystem could enable a local malicious application to to execute code in the context of a privileged process. This issue is rated as High because it is a general bypass for a kernel level defense 1,8% —
CVE-2017-0508 HIGH 7.8 linux linux_kernel An elevation of privilege vulnerability in the kernel ION subsystem could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compro 1,8% —
CVE-2017-0507 HIGH 7.8 linux linux_kernel An elevation of privilege vulnerability in the kernel ION subsystem could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compro 1,8% —
CVE-2014-3527 CRIT 9.8 vmware spring_security When using the CAS Proxy ticket authentication from Spring Security 3.1 to 3.2.4 a malicious CAS Service could trick another CAS Service into authenticating a proxy ticket that was not associated. This is due to the fact that the proxy ticket authentication us 1,8% —
CVE-2024-26221 HIGH 7.2 microsoft windows_server_2016 Windows DNS Server Remote Code Execution Vulnerability 1,8% —
CVE-2022-48482 HIGH 7.5 3cx 3cx 3CX before 18 Update 2 Security Hotfix build 18.0.2.315 on Windows allows unauthenticated remote attackers to read certain files via /Electron/download directory traversal. Files may have credentials, full backups, call recordings, and chat logs. 1,8% —
CVE-2020-4934 MED 4.3 ibm content_navigator IBM Content Navigator 3.0.CD could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 191752. 1,8% —
CVE-2017-5658 MED 5.3 apache pony_mail The statistics generator in Apache Pony Mail 0.7 to 0.9 was found to be returning timestamp data without proper authorization checks. This could lead to derived information disclosure on private lists about the timing of specific email subjects or text bodies, 1,8% —
CVE-2017-10601 CRIT 9.8 juniper junos A specific device configuration can result in a commit failure condition. When this occurs, a user is logged in without being prompted for a password while trying to login through console, ssh, ftp, telnet or su, etc., This issue relies upon a device configura 1,8% —
CVE-2016-8493 HIGH 8.8 fortinet forticlient In FortiClientWindows 5.4.1 and 5.4.2, an attacker may escalate privilege via a FortiClientNamedPipe vulnerability. 1,8% —
CVE-2014-8025 MED 4.3 cisco jabber_guest The API in the Guest Server in Cisco Jabber, when HTML5 is used, allows remote attackers to obtain sensitive information by sniffing the network during an HTTP (1) GET or (2) POST response, aka Bug ID CSCus19801. 1,8% —
CVE-2014-8024 MED 4.3 cisco jabber_guest The API in the Guest Server in Cisco Jabber, when the HTML5 CORS feature is used, allows remote attackers to obtain sensitive information by sniffing the network during an HTTP (1) GET or (2) POST request, aka Bug ID CSCus19789. 1,8% —
CVE-2013-6969 MED 4.3 cisco webex_training_center The training-registration page in Cisco WebEx Training Center allows remote attackers to modify unspecified fields via unknown vectors, aka Bug ID CSCul35990. 1,8% —
CVE-2020-24421 MED 5.5 adobe indesign Adobe InDesign version 15.1.2 (and earlier) is affected by a NULL pointer dereference bug that occurs when handling a malformed .indd file. The impact is limited to causing a denial-of-service of the client application. User interaction is required to exploit 1,8% —
CVE-2019-6642 HIGH 8.8 f5 big-ip_access_policy_manager In BIG-IP 15.0.0, 14.0.0-14.1.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.2, and 11.5.2-11.6.4, BIG-IQ 6.0.0-6.1.0 and 5.1.0-5.4.0, iWorkflow 2.3.0, and Enterprise Manager 3.1.1, authenticated users with the ability to upload files (via scp, for example) can escalate 1,8% —