58.304 CVE seguite
789 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.304 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2019-12678 | HIGH 7.5 | cisco adaptive_security_appliance A vulnerability in the Session Initiation Protocol (SIP) inspection module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) | 1,8% | — |
| CVE-2019-12659 | HIGH 7.5 | cisco ios_xe A vulnerability in the HTTP server code of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the HTTP server to crash. The vulnerability is due to a logical error in the logging mechanism. An attacker could exploit this vulnerabili | 1,8% | — |
| CVE-2019-12656 | HIGH 7.5 | cisco cgr_1000_firmware A vulnerability in the IOx application environment of multiple Cisco platforms could allow an unauthenticated, remote attacker to cause the IOx web server to stop processing HTTPS requests, resulting in a denial of service (DoS) condition. The vulnerability is | 1,8% | — |
| CVE-2010-1146 | MED 6.9 | linux linux_kernel The Linux kernel 2.6.33.2 and earlier, when a ReiserFS filesystem exists, does not restrict read or write access to the .reiserfs_priv directory, which allows local users to gain privileges by modifying (1) extended attributes or (2) ACLs, as demonstrated by d | 1,8% | — |
| CVE-2024-38104 | HIGH 8.8 | microsoft windows_10_1507 Windows Fax Service Remote Code Execution Vulnerability | 1,8% | — |
| CVE-2023-35329 | MED 6.5 | microsoft windows_10_1507 Windows Authentication Denial of Service Vulnerability | 1,8% | — |
| CVE-2021-26109 | HIGH 8.1 | fortinet fortios An integer overflow or wraparound vulnerability in the memory allocator of SSLVPN in FortiOS before 7.0.1 may allow an unauthenticated attacker to corrupt control data on the heap via specifically crafted requests to SSLVPN, resulting in potentially arbitrary | 1,8% | — |
| CVE-2019-12207 | CRIT 9.8 | f5 njs njs through 0.3.1, used in NGINX, has a heap-based buffer over-read in nxt_utf8_decode in nxt/nxt_utf8.c. | 1,8% | — |
| CVE-2018-15396 | MED 6.8 | cisco unity_connection A vulnerability in the Bulk Administration Tool (BAT) for Cisco Unity Connection could allow an authenticated, remote attacker to cause high disk utilization, resulting in a denial of service (DoS) condition. The vulnerability exists because the affected softw | 1,8% | — |
| CVE-2018-0386 | MED 6.1 | cisco hosted_collaboration_solution A vulnerability in Cisco Unified Communications Domain Manager Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on an affected system. The vulnerability is due to improper validation of input that is passe | 1,8% | — |
| CVE-2017-0528 | HIGH 7.8 | linux linux_kernel An elevation of privilege vulnerability in the kernel security subsystem could enable a local malicious application to to execute code in the context of a privileged process. This issue is rated as High because it is a general bypass for a kernel level defense | 1,8% | — |
| CVE-2017-0508 | HIGH 7.8 | linux linux_kernel An elevation of privilege vulnerability in the kernel ION subsystem could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compro | 1,8% | — |
| CVE-2017-0507 | HIGH 7.8 | linux linux_kernel An elevation of privilege vulnerability in the kernel ION subsystem could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compro | 1,8% | — |
| CVE-2014-3527 | CRIT 9.8 | vmware spring_security When using the CAS Proxy ticket authentication from Spring Security 3.1 to 3.2.4 a malicious CAS Service could trick another CAS Service into authenticating a proxy ticket that was not associated. This is due to the fact that the proxy ticket authentication us | 1,8% | — |
| CVE-2024-26221 | HIGH 7.2 | microsoft windows_server_2016 Windows DNS Server Remote Code Execution Vulnerability | 1,8% | — |
| CVE-2022-48482 | HIGH 7.5 | 3cx 3cx 3CX before 18 Update 2 Security Hotfix build 18.0.2.315 on Windows allows unauthenticated remote attackers to read certain files via /Electron/download directory traversal. Files may have credentials, full backups, call recordings, and chat logs. | 1,8% | — |
| CVE-2020-4934 | MED 4.3 | ibm content_navigator IBM Content Navigator 3.0.CD could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 191752. | 1,8% | — |
| CVE-2017-5658 | MED 5.3 | apache pony_mail The statistics generator in Apache Pony Mail 0.7 to 0.9 was found to be returning timestamp data without proper authorization checks. This could lead to derived information disclosure on private lists about the timing of specific email subjects or text bodies, | 1,8% | — |
| CVE-2017-10601 | CRIT 9.8 | juniper junos A specific device configuration can result in a commit failure condition. When this occurs, a user is logged in without being prompted for a password while trying to login through console, ssh, ftp, telnet or su, etc., This issue relies upon a device configura | 1,8% | — |
| CVE-2016-8493 | HIGH 8.8 | fortinet forticlient In FortiClientWindows 5.4.1 and 5.4.2, an attacker may escalate privilege via a FortiClientNamedPipe vulnerability. | 1,8% | — |
| CVE-2014-8025 | MED 4.3 | cisco jabber_guest The API in the Guest Server in Cisco Jabber, when HTML5 is used, allows remote attackers to obtain sensitive information by sniffing the network during an HTTP (1) GET or (2) POST response, aka Bug ID CSCus19801. | 1,8% | — |
| CVE-2014-8024 | MED 4.3 | cisco jabber_guest The API in the Guest Server in Cisco Jabber, when the HTML5 CORS feature is used, allows remote attackers to obtain sensitive information by sniffing the network during an HTTP (1) GET or (2) POST request, aka Bug ID CSCus19789. | 1,8% | — |
| CVE-2013-6969 | MED 4.3 | cisco webex_training_center The training-registration page in Cisco WebEx Training Center allows remote attackers to modify unspecified fields via unknown vectors, aka Bug ID CSCul35990. | 1,8% | — |
| CVE-2020-24421 | MED 5.5 | adobe indesign Adobe InDesign version 15.1.2 (and earlier) is affected by a NULL pointer dereference bug that occurs when handling a malformed .indd file. The impact is limited to causing a denial-of-service of the client application. User interaction is required to exploit | 1,8% | — |
| CVE-2019-6642 | HIGH 8.8 | f5 big-ip_access_policy_manager In BIG-IP 15.0.0, 14.0.0-14.1.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.2, and 11.5.2-11.6.4, BIG-IQ 6.0.0-6.1.0 and 5.1.0-5.4.0, iWorkflow 2.3.0, and Enterprise Manager 3.1.1, authenticated users with the ability to upload files (via scp, for example) can escalate | 1,8% | — |