58.306 CVE seguite
790 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.306 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2018-1035 | MED 5.3 | microsoft windows_10 A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka "Windows Security Feature Bypass Vulnerability." This affects Windows 10, Windows 10 Servers. | 1,3% | — |
| CVE-2009-4455 | MED 6.5 | cisco adaptive_security_appliance_5500 The default configuration of Cisco ASA 5500 Series Adaptive Security Appliance (Cisco ASA) 7.0, 7.1, 7.2, 8.0, 8.1, and 8.2 allows portal traffic to access arbitrary backend servers, which might allow remote authenticated users to bypass intended access restri | 1,3% | — |
| CVE-2002-0880 | MED 5.0 | cisco skinny_client_control_protocol_software Cisco IP Phone (VoIP) models 7910, 7940, and 7960 allow remote attackers to cause a denial of service (crash) via malformed packets as demonstrated by (1) "jolt", (2) "jolt2", (3) "raped", (4) "hping2", (5) "bloop", (6) "bubonic", (7) "mutant", (8) "trash", an | 1,3% | — |
| CVE-2023-50270 | MED 6.5 | apache dolphinscheduler Session Fixation Apache DolphinScheduler before version 3.2.0, which session is still valid after the password change. Users are recommended to upgrade to version 3.2.1, which fixes this issue. | 1,3% | — |
| CVE-2023-24816 | MED 4.5 | ipython ipython IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language. Versions prior to 8.1.0 are subject to a command injection vulnerability with very specific p | 1,3% | — |
| CVE-2019-15983 | MED 4.9 | cisco data_center_network_manager A vulnerability in the SOAP API of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system. To exploit this vulnerability, an attacker would need administrat | 1,3% | — |
| CVE-2019-12706 | HIGH 7.5 | cisco email_security_appliance_firmware A vulnerability in the Sender Policy Framework (SPF) functionality of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the configured user filters on an affected device. The vulnerability | 1,3% | — |
| CVE-2012-6596 | MED 5.0 | paloaltonetworks pan-os Palo Alto Networks PAN-OS 4.0.x before 4.0.9 and 4.1.x before 4.1.3 stores cleartext LDAP bind passwords in authd.log, which allows context-dependent attackers to obtain sensitive information by reading this file, aka Ref ID 35493. | 1,3% | — |
| CVE-2024-36886 | CRIT 9.8 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: tipc: fix UAF in error path Sam Page (sam4k) working with Trend Micro Zero Day Initiative reported a UAF in the tipc_buf_append() error path: BUG: KASAN: slab-use-after-free in kfree_skb_li | 1,3% | — |
| CVE-2023-3467 | HIGH 8.0 | citrix netscaler_application_delivery_controller Privilege Escalation to root administrator (nsroot) | 1,3% | — |
| CVE-2021-1460 | MED 5.3 | cisco cgr1000_firmware A vulnerability in the Cisco IOx Application Framework of Cisco 809 Industrial Integrated Services Routers (Industrial ISRs), Cisco 829 Industrial ISRs, Cisco CGR 1000 Compute Module, and Cisco IC3000 Industrial Compute Gateway could allow an unauthenticated, | 1,3% | — |
| CVE-2019-13617 | MED 6.5 | f5 njs njs through 0.3.3, used in NGINX, has a heap-based buffer over-read in nxt_vsprintf in nxt/nxt_sprintf.c during error handling, as demonstrated by an njs_regexp_literal call that leads to an njs_parser_lexer_error call and then an njs_parser_scope_error call. | 1,3% | — |
| CVE-2017-1520 | LOW 3.7 | ibm db2 IBM DB2 9.7, 10,1, 10.5, and 11.1 is vulnerable to an unauthorized command that allows the database to be activated when authentication type is CLIENT. IBM X-Force ID: 129830. | 1,3% | — |
| CVE-2015-6358 | MED 5.9 | cisco pvc2300_firmware Multiple Cisco embedded devices use hardcoded X.509 certificates and SSH host keys embedded in the firmware, which allows remote attackers to defeat cryptographic protection mechanisms and conduct man-in-the-middle attacks by leveraging knowledge of these cert | 1,3% | — |
| CVE-2023-38186 | HIGH 8.8 | microsoft windows_10_21h2 Windows Mobile Device Management Elevation of Privilege Vulnerability | 1,3% | — |
| CVE-2023-3269 | HIGH 7.8 | fedoraproject fedora A vulnerability exists in the memory management subsystem of the Linux kernel. The lock handling for accessing and updating virtual memory areas (VMAs) is incorrect, leading to use-after-free problems. This issue can be successfully exploited to execute arbitr | 1,3% | — |
| CVE-2023-31103 | HIGH 7.5 | apache inlong Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Attackers can change the immutable name and type of cluster of InLong. Users are advised to upgrade to A | 1,3% | — |
| CVE-2015-3101 | MED 4.3 | adobe air The Flash broker in Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0 | 1,3% | — |
| CVE-2014-3307 | MED 6.8 | cisco universal_small_cell_series_firmware The DHCP client implementation in Universal Small Cell firmware on Cisco Small Cell products allows remote attackers to execute arbitrary commands via crafted DHCP messages, aka Bug ID CSCup47513. | 1,3% | — |
| CVE-2024-30020 | HIGH 8.1 | microsoft windows_10_1507 Windows Cryptographic Services Remote Code Execution Vulnerability | 1,3% | — |
| CVE-2022-30200 | HIGH 7.8 | microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 1,3% | — |
| CVE-2021-1577 | CRIT 9.1 | cisco application_policy_infrastructure_controller A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Controller (Cloud APIC) could allow an unauthenticated, remote attacker to read or write arbitrary files on an aff | 1,3% | — |
| CVE-2019-9965 | HIGH 7.8 | xnview xnview_mp XnView MP 0.93.1 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to ntdll!RtlReAllocateHeap. | 1,3% | — |
| CVE-2017-8624 | HIGH 7.8 | microsoft windows_10 CLFS in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability due to the way it handles objects | 1,3% | — |
| CVE-2017-8622 | HIGH 7.8 | microsoft windows_10 Windows Subsystem for Linux in Windows 10 1703 allows an elevation of privilege vulnerability when it fails to properly handle handles NT pipes, aka "Windows Subsystem for Linux Elevation of Privilege Vulnerability". | 1,3% | — |