EN
58.306 CVE seguite
790 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.306 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più alto In KEV dal, ordina dal più alto
CVE-2018-1035 MED 5.3 microsoft windows_10 A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka "Windows Security Feature Bypass Vulnerability." This affects Windows 10, Windows 10 Servers. 1,3% —
CVE-2009-4455 MED 6.5 cisco adaptive_security_appliance_5500 The default configuration of Cisco ASA 5500 Series Adaptive Security Appliance (Cisco ASA) 7.0, 7.1, 7.2, 8.0, 8.1, and 8.2 allows portal traffic to access arbitrary backend servers, which might allow remote authenticated users to bypass intended access restri 1,3% —
CVE-2002-0880 MED 5.0 cisco skinny_client_control_protocol_software Cisco IP Phone (VoIP) models 7910, 7940, and 7960 allow remote attackers to cause a denial of service (crash) via malformed packets as demonstrated by (1) "jolt", (2) "jolt2", (3) "raped", (4) "hping2", (5) "bloop", (6) "bubonic", (7) "mutant", (8) "trash", an 1,3% —
CVE-2023-50270 MED 6.5 apache dolphinscheduler Session Fixation Apache DolphinScheduler before version 3.2.0, which session is still valid after the password change. Users are recommended to upgrade to version 3.2.1, which fixes this issue. 1,3% —
CVE-2023-24816 MED 4.5 ipython ipython IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language. Versions prior to 8.1.0 are subject to a command injection vulnerability with very specific p 1,3% —
CVE-2019-15983 MED 4.9 cisco data_center_network_manager A vulnerability in the SOAP API of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system. To exploit this vulnerability, an attacker would need administrat 1,3% —
CVE-2019-12706 HIGH 7.5 cisco email_security_appliance_firmware A vulnerability in the Sender Policy Framework (SPF) functionality of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the configured user filters on an affected device. The vulnerability 1,3% —
CVE-2012-6596 MED 5.0 paloaltonetworks pan-os Palo Alto Networks PAN-OS 4.0.x before 4.0.9 and 4.1.x before 4.1.3 stores cleartext LDAP bind passwords in authd.log, which allows context-dependent attackers to obtain sensitive information by reading this file, aka Ref ID 35493. 1,3% —
CVE-2024-36886 CRIT 9.8 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: tipc: fix UAF in error path Sam Page (sam4k) working with Trend Micro Zero Day Initiative reported a UAF in the tipc_buf_append() error path: BUG: KASAN: slab-use-after-free in kfree_skb_li 1,3% —
CVE-2023-3467 HIGH 8.0 citrix netscaler_application_delivery_controller Privilege Escalation to root administrator (nsroot) 1,3% —
CVE-2021-1460 MED 5.3 cisco cgr1000_firmware A vulnerability in the Cisco IOx Application Framework of Cisco 809 Industrial Integrated Services Routers (Industrial ISRs), Cisco 829 Industrial ISRs, Cisco CGR 1000 Compute Module, and Cisco IC3000 Industrial Compute Gateway could allow an unauthenticated, 1,3% —
CVE-2019-13617 MED 6.5 f5 njs njs through 0.3.3, used in NGINX, has a heap-based buffer over-read in nxt_vsprintf in nxt/nxt_sprintf.c during error handling, as demonstrated by an njs_regexp_literal call that leads to an njs_parser_lexer_error call and then an njs_parser_scope_error call. 1,3% —
CVE-2017-1520 LOW 3.7 ibm db2 IBM DB2 9.7, 10,1, 10.5, and 11.1 is vulnerable to an unauthorized command that allows the database to be activated when authentication type is CLIENT. IBM X-Force ID: 129830. 1,3% —
CVE-2015-6358 MED 5.9 cisco pvc2300_firmware Multiple Cisco embedded devices use hardcoded X.509 certificates and SSH host keys embedded in the firmware, which allows remote attackers to defeat cryptographic protection mechanisms and conduct man-in-the-middle attacks by leveraging knowledge of these cert 1,3% —
CVE-2023-38186 HIGH 8.8 microsoft windows_10_21h2 Windows Mobile Device Management Elevation of Privilege Vulnerability 1,3% —
CVE-2023-3269 HIGH 7.8 fedoraproject fedora A vulnerability exists in the memory management subsystem of the Linux kernel. The lock handling for accessing and updating virtual memory areas (VMAs) is incorrect, leading to use-after-free problems. This issue can be successfully exploited to execute arbitr 1,3% —
CVE-2023-31103 HIGH 7.5 apache inlong Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0.  Attackers can change the immutable name and type of cluster of InLong. Users are advised to upgrade to A 1,3% —
CVE-2015-3101 MED 4.3 adobe air The Flash broker in Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0 1,3% —
CVE-2014-3307 MED 6.8 cisco universal_small_cell_series_firmware The DHCP client implementation in Universal Small Cell firmware on Cisco Small Cell products allows remote attackers to execute arbitrary commands via crafted DHCP messages, aka Bug ID CSCup47513. 1,3% —
CVE-2024-30020 HIGH 8.1 microsoft windows_10_1507 Windows Cryptographic Services Remote Code Execution Vulnerability 1,3% —
CVE-2022-30200 HIGH 7.8 microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability 1,3% —
CVE-2021-1577 CRIT 9.1 cisco application_policy_infrastructure_controller A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Controller (Cloud APIC) could allow an unauthenticated, remote attacker to read or write arbitrary files on an aff 1,3% —
CVE-2019-9965 HIGH 7.8 xnview xnview_mp XnView MP 0.93.1 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to ntdll!RtlReAllocateHeap. 1,3% —
CVE-2017-8624 HIGH 7.8 microsoft windows_10 CLFS in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability due to the way it handles objects 1,3% —
CVE-2017-8622 HIGH 7.8 microsoft windows_10 Windows Subsystem for Linux in Windows 10 1703 allows an elevation of privilege vulnerability when it fails to properly handle handles NT pipes, aka "Windows Subsystem for Linux Elevation of Privilege Vulnerability". 1,3% —