EN
58.304 CVE seguite
789 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.304 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più alto In KEV dal, ordina dal più alto
CVE-2009-3282 HIGH 7.8 vmware fusion Integer overflow in the vmx86 kernel extension in VMware Fusion before 2.0.6 build 196839 allows host OS users to cause a denial of service to the host OS via unspecified vectors. 1,8% —
CVE-2008-2637 MED 4.3 f5 firepass_ssl_vpn Multiple cross-site scripting (XSS) vulnerabilities in F5 FirePass SSL VPN 6.0.2 hotfix 3, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via quotes in (1) the css_exceptions parameter in vdesk/admincon/webyfiers.p 1,8% —
CVE-2024-38116 HIGH 8.8 microsoft windows_10_1507 Windows IP Routing Management Snapin Remote Code Execution Vulnerability 1,8% —
CVE-2022-28889 MED 4.3 apache druid In Apache Druid 0.22.1 and earlier, the server did not set appropriate headers to prevent clickjacking. Druid 0.23.0 and later prevent clickjacking using the Content-Security-Policy header. 1,8% —
CVE-2018-0328 MED 6.1 cisco unified_communications_manager A vulnerability in the web framework of Cisco Unified Communications Manager and Cisco Unified Presence could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system. Th 1,8% —
CVE-2007-6753 MED 6.2 microsoft windows_2000 Untrusted search path vulnerability in Shell32.dll in Microsoft Windows 2000, Windows XP, Windows Vista, Windows Server 2008, and Windows 7, when using an environment configured with a string such as %APPDATA% or %PROGRAMFILES% in a certain way, allows local u 1,8% —
CVE-2021-1730 MED 5.4 microsoft exchange_server <p>A spoofing vulnerability exists in Microsoft Exchange Server which could result in an attack that would allow a malicious actor to impersonate the user.</p> <p>This update addresses this vulnerability.</p> <p>To prevent these types of attacks, Microsoft rec 1,8% —
CVE-2019-1105 MED 5.4 microsoft outlook A spoofing vulnerability exists in the way Microsoft Outlook for Android software parses specifically crafted email messages. An authenticated attacker could exploit the vulnerability by sending a specially crafted email message to a victim. The attacker who s 1,8% —
CVE-2018-18333 HIGH 7.8 trendmicro antivirus_\+_security A DLL hijacking vulnerability in Trend Micro Security 2019 (Consumer) versions below 15.0.0.1163 and below could allow an attacker to manipulate a specific DLL and escalate privileges on vulnerable installations. 1,8% —
CVE-2016-3656 HIGH 7.5 paloaltonetworks pan-os The GlobalProtect Portal in Palo Alto Networks PAN-OS before 5.0.18, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7.0.x before 7.0.5H2 allows remote attackers to cause a denial of service (service crash) via a crafted request. 1,8% —
CVE-2015-0073 HIGH 7.2 microsoft windows_7 The Windows Registry Virtualization feature in the kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly restrict changes 1,8% —
CVE-2011-2058 HIGH 7.5 cisco ios The cat6000-dot1x component in Cisco IOS 12.2 before 12.2(33)SXI7 does not properly handle an external loop between a pair of dot1x enabled ports, which allows remote attackers to cause a denial of service (traffic storm) via unspecified vectors that trigger m 1,8% —
CVE-2025-32724 HIGH 7.5 microsoft windows_10_1507 Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network. 1,8% —
CVE-2024-43611 HIGH 8.8 microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 1,8% —
CVE-2015-6352 MED 4.3 cisco hosted_collaboration_solution Cisco Unified Communications Domain Manager before 10.6(1) provides different error messages for pathname access attempts depending on whether the pathname exists, which allows remote attackers to map a filesystem via a series of requests, aka Bug ID CSCut6789 1,8% —
CVE-2013-5526 HIGH 7.1 cisco unified_ip_phone_9951 Cisco 9900 fourth-generation IP phones do not properly perform SDP negotiation, which allows remote attackers to cause a denial of service (device reboot) via crafted SDP packets, aka Bug ID CSCuf06698. 1,8% —
CVE-2013-1659 HIGH 7.6 vmware esxi VMware vCenter Server 4.0 before Update 4b, 5.0 before Update 2, and 5.1 before 5.1.0b; VMware ESXi 3.5 through 5.1; and VMware ESX 3.5 through 4.1 do not properly implement the Network File Copy (NFC) protocol, which allows man-in-the-middle attackers to exec 1,8% —
CVE-2012-2529 HIGH 7.2 microsoft windows_7 Integer overflow in the kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages i 1,8% —
CVE-2025-21172 HIGH 7.5 microsoft .net .NET and Visual Studio Remote Code Execution Vulnerability 1,8% —
CVE-2021-40736 HIGH 7.8 adobe audition Adobe Audition version 14.4 (and earlier) is affected by a memory corruption vulnerability, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability. 1,8% —
CVE-2021-40735 HIGH 7.8 adobe audition Adobe Audition version 14.4 (and earlier) is affected by a memory corruption vulnerability, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability. 1,8% —
CVE-2019-10211 CRIT 9.8 postgresql postgresql Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via bundled OpenSSL executing code from unprotected directory. 1,8% —
CVE-2021-1538 MED 4.7 cisco common_services_platform_collector A vulnerability in the configuration dashboard of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to execute arbitrary code. This vulnerability is due to insufficient sanitization of configuration entries. An attac 1,8% —
CVE-2016-2188 MED 4.6 canonical ubuntu_linux The iowarrior_probe function in drivers/usb/misc/iowarrior.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descripto 1,8% —
CVE-2008-3514 MED 5.0 vmware virtualcenter VMware VirtualCenter 2.5 before Update 2 and 2.0.2 before Update 5 relies on client-side "enabled/disabled functionality" for access control, which allows remote attackers to determine valid user names by enabling functionality in the GUI and then making an "a 1,8% —