EN
58.306 CVE seguite
790 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.306 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più alto In KEV dal, ordina dal più alto
CVE-2022-20878 MED 4.7 cisco application_extension_platform Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpe 1,3% —
CVE-2022-20877 MED 4.7 cisco application_extension_platform Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpe 1,3% —
CVE-2022-20876 MED 4.7 cisco application_extension_platform Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpe 1,3% —
CVE-2022-20875 MED 4.7 cisco application_extension_platform Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpe 1,3% —
CVE-2022-20874 MED 4.7 cisco application_extension_platform Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpe 1,3% —
CVE-2018-1000421 MED 6.5 apache mesos An improper authorization vulnerability exists in Jenkins Mesos Plugin 0.17.1 and earlier in MesosCloud.java that allows attackers with Overall/Read access to initiate a test connection to an attacker-specified Mesos server with attacker-specified credentials 1,3% —
CVE-2016-1358 MED 6.4 cisco prime_infrastructure Cisco Prime Infrastructure 2.2, 3.0, and 3.1(0.0) allows remote authenticated users to read arbitrary files or cause a denial of service via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML Ex 1,3% —
CVE-2016-1334 MED 5.3 cisco small_business_wireless_access_points_firmware Cisco Small Business 500 Wireless Access Point devices with firmware 1.0.4.4 allow remote attackers to set the system time via a crafted POST request, aka Bug ID CSCuy01457. 1,3% —
CVE-2024-38081 HIGH 7.3 microsoft .net .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability 1,3% —
CVE-2023-49733 CRIT 9.8 apache cocoon Improper Restriction of XML External Entity Reference vulnerability in Apache Cocoon.This issue affects Apache Cocoon: from 2.2.0 before 2.3.0. Users are recommended to upgrade to version 2.3.0, which fixes the issue. 1,3% —
CVE-2023-40581 HIGH 8.3 yt-dlp_project yt-dlp yt-dlp is a youtube-dl fork with additional features and fixes. yt-dlp allows the user to provide shell command lines to be executed at various stages in its download steps through the `--exec` flag. This flag allows output template expansion in its argument, 1,3% —
CVE-2022-40160 MED 6.5 apache commons_jxpath ** DISPUTED ** This record was originally reported by the oss-fuzz project who failed to consider the security context in which JXPath is intended to be used and failed to contact the JXPath maintainers prior to requesting the CVE allocation. The CVE was then 1,3% —
CVE-2022-40159 MED 6.5 apache commons_jxpath ** DISPUTED ** This record was originally reported by the oss-fuzz project who failed to consider the security context in which JXPath is intended to be used and failed to contact the JXPath maintainers prior to requesting the CVE allocation. The CVE was then 1,3% —
CVE-2022-20748 MED 5.3 cisco secure_firewall_threat_defense A vulnerability in the local malware analysis process of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. This vulnerability is due to insufficien 1,3% —
CVE-2022-20675 MED 5.3 cisco asyncos A vulnerability in the TCP/IP stack of Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), and Cisco Secure Email and Web Manager, formerly Security Management Appliance, could allow an unauthenticated, remote attacker to crash the Simple 1,3% —
CVE-2020-4757 MED 6.4 ibm content_navigator IBM FileNet Content Manager and IBM Content Navigator 3.0.CD is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credenti 1,3% —
CVE-2017-6709 CRIT 9.8 cisco ultra_services_framework A vulnerability in the AutoVNF tool for the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to access administrative credentials for Cisco Elastic Services Controller (ESC) and Cisco OpenStack deployments in an affected system. T 1,3% —
CVE-2012-5032 MED 6.4 cisco ios The Flex-VPN load-balancing feature in the ipsec-ikev2 implementation in Cisco IOS before 15.1(1)SY3 does not require authentication, which allows remote attackers to trigger the forwarding of VPN traffic to an attacker-controlled destination, or the discardin 1,3% —
CVE-2008-2165 MED 4.3 cisco building_broadband_service_manager Cross-site scripting (XSS) vulnerability in AccessCodeStart.asp in Cisco Building Broadband Service Manager (BBSM) Captive Portal 5.3 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. 1,3% —
CVE-2026-8663 MED 6.0 rapid7 insightconnect_rpm OS Command Injection vulnerability in Rapid7 InsightConnect RPM Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the repo, key, or name parameters due to insufficient input sanitization in shell command construction. 1,3% —
CVE-2026-8659 MED 6.0 rapid7 insightconnect_sqlmap OS Command Injection vulnerability in Rapid7 InsightConnect SQLmap Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the api_host or api_port parameters during connection configuration due to insufficient input validation. 1,3% —
CVE-2026-8658 MED 6.0 rapid7 insightconnect_tcpdump OS Command Injection vulnerability in Rapid7 InsightConnect Tcpdump Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the options or filter parameters due to insufficient input sanitization in shell command construction. 1,3% —
CVE-2026-21248 HIGH 7.3 microsoft windows_10_1607 Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally. 1,3% —
CVE-2026-21244 HIGH 7.3 microsoft windows_10_1607 Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally. 1,3% —
CVE-2025-29804 HIGH 7.3 microsoft visual_studio_2022 Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally. 1,3% —