EN
58.352 CVE seguite
790 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.352 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più alto In KEV dal, ordina dal più alto
CVE-2002-2316 MED 5.0 cisco catos Cisco Catalyst 4000 series switches running CatOS 5.5.5, 6.3.5, and 7.1.2 do not always learn MAC addresses from a single initial packet, which causes unicast traffic to be broadcast across the switch and allows remote attackers to obtain sensitive network inf 1,2% —
CVE-2024-21399 HIGH 8.3 microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability 1,2% —
CVE-2018-0439 HIGH 8.8 cisco meeting_server A vulnerability in the web-based management interface of Cisco Meeting Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to 1,2% —
CVE-2018-0413 HIGH 8.8 cisco identity_services_engine_software A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnera 1,2% —
CVE-2023-41752 HIGH 7.5 apache traffic_server Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Traffic Server.This issue affects Apache Traffic Server: from 8.0.0 through 8.1.8, from 9.0.0 through 9.2.2. Users are recommended to upgrade to version 8.1.9 or 9.2.3, which f 1,2% —
CVE-2022-30148 MED 5.5 microsoft windows_10 Windows Desired State Configuration (DSC) Information Disclosure Vulnerability 1,2% —
CVE-2022-29114 MED 5.5 microsoft windows_10 Windows Print Spooler Information Disclosure Vulnerability 1,2% —
CVE-2022-0971 HIGH 8.8 google chrome Use after free in Blink Layout in Google Chrome on Android prior to 99.0.4844.74 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. 1,2% —
CVE-2019-17557 MED 5.4 apache syncope It was found that the Apache Syncope EndUser UI login page prio to 2.0.15 and 2.1.6 reflects the successMessage parameters. By this mean, a user accessing the Enduser UI could execute javascript code from URL query string. 1,2% —
CVE-2013-1222 HIGH 7.8 cisco unified_customer_voice_portal The Tomcat Web Management feature in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 does not properly configure Tomcat components, which allows remote attackers to launch arbitrary custom web applications via a crafted (1) HTTP or (2) HT 1,2% —
CVE-2024-43487 MED 6.5 microsoft windows_10_1507 Windows Mark of the Web Security Feature Bypass Vulnerability 1,2% —
CVE-2021-44879 MED 5.5 linux linux_kernel In gc_data_segment in fs/f2fs/gc.c in the Linux kernel before 5.16.3, special files are not considered, leading to a move_data_page NULL pointer dereference. 1,2% —
CVE-2021-31372 HIGH 8.8 juniper junos An Improper Input Validation vulnerability in J-Web of Juniper Networks Junos OS allows a locally authenticated J-Web attacker to escalate their privileges to root over the target device. This issue affects: Juniper Networks Junos OS All versions prior to 18.3 1,2% —
CVE-2021-1648 HIGH 7.8 microsoft windows_10 Microsoft splwow64 Elevation of Privilege Vulnerability 1,2% —
CVE-2018-1009 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when Windows improperly handles objects in memory and incorrectly maps kernel memory, aka "Microsoft DirectX Graphics Kernel Subsystem Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Wi 1,2% —
CVE-2018-0297 MED 5.8 cisco secure_firewall_threat_defense A vulnerability in the detection engine of Cisco Firepower Threat Defense software could allow an unauthenticated, remote attacker to bypass a configured Secure Sockets Layer (SSL) Access Control (AC) policy to block SSL traffic. The vulnerability is due to th 1,2% —
CVE-2023-46801 HIGH 8.8 apache linkis In Apache Linkis <= 1.5.0, data source management module, when adding Mysql data source, exists remote code execution vulnerability for java version < 1.8.0_241. The deserialization vulnerability exploited through jrmp can inject malicious files into the serv 1,2% —
CVE-2023-36766 HIGH 7.8 microsoft 365_apps Microsoft Excel Information Disclosure Vulnerability 1,2% —
CVE-2023-31058 HIGH 7.5 apache inlong Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Attackers would bypass the 'autoDeserialize' option filtering by adding blanks. Users are advised to upgrad 1,2% —
CVE-2020-3596 MED 5.9 cisco expressway A vulnerability in the Session Initiation Protocol (SIP) of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The 1,2% —
CVE-2020-15603 HIGH 7.5 trendmicro antivirus\+_2020 An invalid memory read vulnerability in a Trend Micro Secuity 2020 (v16.0.0.1302 and below) consumer family of products' driver could allow an attacker to manipulate the specific driver to do a system call operation with an invalid address, resulting in a pote 1,2% —
CVE-2020-1455 MED 5.3 microsoft sql_server_management_studio A denial of service vulnerability exists when Microsoft SQL Server Management Studio (SSMS) improperly handles files. An attacker could exploit the vulnerability to trigger a denial of service. To exploit the vulnerability, an attacker would first require exec 1,2% —
CVE-2017-6749 MED 5.4 cisco web_security_appliance A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected 1,2% —
CVE-2017-5045 MED 6.1 debian debian_linux XSS Auditor in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed detection of a blocked iframe load, which allowed a remote attacker to brute force JavaScript variables via a crafted HTML page. 1,2% —
CVE-2017-3868 MED 6.1 cisco unified_computing_system_director A vulnerability in the web-based management interface of Cisco UCS Director could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. More Informat 1,2% —