58.352 CVE seguite
790 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.352 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2002-2316 | MED 5.0 | cisco catos Cisco Catalyst 4000 series switches running CatOS 5.5.5, 6.3.5, and 7.1.2 do not always learn MAC addresses from a single initial packet, which causes unicast traffic to be broadcast across the switch and allows remote attackers to obtain sensitive network inf | 1,2% | — |
| CVE-2024-21399 | HIGH 8.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 1,2% | — |
| CVE-2018-0439 | HIGH 8.8 | cisco meeting_server A vulnerability in the web-based management interface of Cisco Meeting Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to | 1,2% | — |
| CVE-2018-0413 | HIGH 8.8 | cisco identity_services_engine_software A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnera | 1,2% | — |
| CVE-2023-41752 | HIGH 7.5 | apache traffic_server Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Traffic Server.This issue affects Apache Traffic Server: from 8.0.0 through 8.1.8, from 9.0.0 through 9.2.2. Users are recommended to upgrade to version 8.1.9 or 9.2.3, which f | 1,2% | — |
| CVE-2022-30148 | MED 5.5 | microsoft windows_10 Windows Desired State Configuration (DSC) Information Disclosure Vulnerability | 1,2% | — |
| CVE-2022-29114 | MED 5.5 | microsoft windows_10 Windows Print Spooler Information Disclosure Vulnerability | 1,2% | — |
| CVE-2022-0971 | HIGH 8.8 | google chrome Use after free in Blink Layout in Google Chrome on Android prior to 99.0.4844.74 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. | 1,2% | — |
| CVE-2019-17557 | MED 5.4 | apache syncope It was found that the Apache Syncope EndUser UI login page prio to 2.0.15 and 2.1.6 reflects the successMessage parameters. By this mean, a user accessing the Enduser UI could execute javascript code from URL query string. | 1,2% | — |
| CVE-2013-1222 | HIGH 7.8 | cisco unified_customer_voice_portal The Tomcat Web Management feature in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 does not properly configure Tomcat components, which allows remote attackers to launch arbitrary custom web applications via a crafted (1) HTTP or (2) HT | 1,2% | — |
| CVE-2024-43487 | MED 6.5 | microsoft windows_10_1507 Windows Mark of the Web Security Feature Bypass Vulnerability | 1,2% | — |
| CVE-2021-44879 | MED 5.5 | linux linux_kernel In gc_data_segment in fs/f2fs/gc.c in the Linux kernel before 5.16.3, special files are not considered, leading to a move_data_page NULL pointer dereference. | 1,2% | — |
| CVE-2021-31372 | HIGH 8.8 | juniper junos An Improper Input Validation vulnerability in J-Web of Juniper Networks Junos OS allows a locally authenticated J-Web attacker to escalate their privileges to root over the target device. This issue affects: Juniper Networks Junos OS All versions prior to 18.3 | 1,2% | — |
| CVE-2021-1648 | HIGH 7.8 | microsoft windows_10 Microsoft splwow64 Elevation of Privilege Vulnerability | 1,2% | — |
| CVE-2018-1009 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows improperly handles objects in memory and incorrectly maps kernel memory, aka "Microsoft DirectX Graphics Kernel Subsystem Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Wi | 1,2% | — |
| CVE-2018-0297 | MED 5.8 | cisco secure_firewall_threat_defense A vulnerability in the detection engine of Cisco Firepower Threat Defense software could allow an unauthenticated, remote attacker to bypass a configured Secure Sockets Layer (SSL) Access Control (AC) policy to block SSL traffic. The vulnerability is due to th | 1,2% | — |
| CVE-2023-46801 | HIGH 8.8 | apache linkis In Apache Linkis <= 1.5.0, data source management module, when adding Mysql data source, exists remote code execution vulnerability for java version < 1.8.0_241. The deserialization vulnerability exploited through jrmp can inject malicious files into the serv | 1,2% | — |
| CVE-2023-36766 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Information Disclosure Vulnerability | 1,2% | — |
| CVE-2023-31058 | HIGH 7.5 | apache inlong Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Attackers would bypass the 'autoDeserialize' option filtering by adding blanks. Users are advised to upgrad | 1,2% | — |
| CVE-2020-3596 | MED 5.9 | cisco expressway A vulnerability in the Session Initiation Protocol (SIP) of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The | 1,2% | — |
| CVE-2020-15603 | HIGH 7.5 | trendmicro antivirus\+_2020 An invalid memory read vulnerability in a Trend Micro Secuity 2020 (v16.0.0.1302 and below) consumer family of products' driver could allow an attacker to manipulate the specific driver to do a system call operation with an invalid address, resulting in a pote | 1,2% | — |
| CVE-2020-1455 | MED 5.3 | microsoft sql_server_management_studio A denial of service vulnerability exists when Microsoft SQL Server Management Studio (SSMS) improperly handles files. An attacker could exploit the vulnerability to trigger a denial of service. To exploit the vulnerability, an attacker would first require exec | 1,2% | — |
| CVE-2017-6749 | MED 5.4 | cisco web_security_appliance A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected | 1,2% | — |
| CVE-2017-5045 | MED 6.1 | debian debian_linux XSS Auditor in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed detection of a blocked iframe load, which allowed a remote attacker to brute force JavaScript variables via a crafted HTML page. | 1,2% | — |
| CVE-2017-3868 | MED 6.1 | cisco unified_computing_system_director A vulnerability in the web-based management interface of Cisco UCS Director could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. More Informat | 1,2% | — |