58.559 CVE seguite
797 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.559 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2025-49666 | HIGH 7.2 | microsoft windows_server_2016 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to execute code over a network. | 1,3% | — |
| CVE-2025-47856 | HIGH 7.2 | fortinet fortivoice Two improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiVoice version 7.2.0, 7.0.0 through 7.0.6 and before 6.4.10 allows a privileged attacker to execute arbitrary code or comman | 1,3% | — |
| CVE-2025-4615 | HIGH 7.2 | paloaltonetworks pan-os An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and execute arbitrary commands. The security risk posed by this issu | 0,8% | — |
| CVE-2025-4231 | HIGH 7.2 | paloaltonetworks pan-os A command injection vulnerability in Palo Alto Networks PAN-OS® enables an authenticated administrative user to perform actions as the root user. The attacker must have network access to the management web interface and successfully authenticate to exploit th | 1,0% | — |
| CVE-2025-3944 | HIGH 7.2 | tridium niagara Incorrect Permission Assignment for Critical Resource vulnerability in Tridium Niagara Framework on QNX, Tridium Niagara Enterprise Security on QNX allows File Manipulation. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Ni | 0,5% | — |
| CVE-2025-36048 | HIGH 7.2 | ibm webmethods_integration IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15 could allow a privileged user to escalate their privileges when handling external entities due to execution with unnecessary privileges. | 0,5% | — |
| CVE-2025-31104 | HIGH 7.2 | fortinet fortiadc A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiADC 7.6.0 through 7.6.1, FortiADC 7.4.0 through 7.4.6, FortiADC 7.2.0 through 7.2.7, FortiADC 7.1.0 through 7.1.4, FortiADC 7.0 all vers | 1,1% | — |
| CVE-2025-30067 | HIGH 7.2 | apache kylin Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Kylin. If an attacker gets access to Kylin's system or project admin permission, the JDBC connection configuration maybe altered to execute arbitrary code from the remote. You a | 0,9% | — |
| CVE-2025-29793 | HIGH 7.2 | microsoft sharepoint_enterprise_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 23,6% | — |
| CVE-2025-25254 | HIGH 7.2 | fortinet fortiweb An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiWeb version 7.6.2 and below, version 7.4.6 and below, 7.2 all versions, 7.0 all versions endpoint may allow an authenticated admin to access and mo | 17,1% | — |
| CVE-2025-24053 | HIGH 7.2 | microsoft dataverse Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network. | 0,7% | — |
| CVE-2025-21348 | HIGH 7.2 | microsoft sharepoint_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 1,8% | — |
| CVE-2024-9474 | HIGH 7.2 | ransomware paloaltonetworks pan-os A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access are not impacted by this | 94,7% | |
| CVE-2024-8686 | HIGH 7.2 | paloaltonetworks pan-os A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as root on the firewall. | 1,4% | — |
| CVE-2024-54181 | HIGH 7.2 | ibm websphere_automation IBM WebSphere Automation 1.7.5 could allow a remote privileged user, who has authorized access to the swagger UI, to execute arbitrary code. Using specially crafted input, the user could exploit this vulnerability to execute arbitrary code on the system. | 1,0% | — |
| CVE-2024-54024 | HIGH 7.2 | fortinet fortiisolator An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiIsolator before version 2.4.6 allows a privileged attacker with super-admin profile and CLI access to execute unauthorized cod | 1,2% | — |
| CVE-2024-54018 | HIGH 7.2 | fortinet fortisandbox Multiple improper neutralization of special elements used in an OS Command vulnerabilities [CWE-78] in FortiSandbox before 4.4.5 allows a privileged attacker to execute unauthorized commands via crafted requests. | 10,0% | — |
| CVE-2024-52965 | HIGH 7.2 | fortinet fortios A missing critical step in authentication vulnerability [CWE-304] in Fortinet FortiOS version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 through 7.2.10, and before 7.0.16 & FortiProxy version 7.6.0 through 7.6.1, 7.4.0 through 7.4.8, 7.2.0 through 7.2.13 | 0,3% | — |
| CVE-2024-52052 | HIGH 7.2 | wowza streaming_engine Wowza Streaming Engine below 4.9.1 permits an authenticated Streaming Engine Manager administrator to define a custom application property and poison a stream target for high-privilege remote code execution. | 0,5% | — |
| CVE-2024-50571 | HIGH 7.2 | fortinet fortianalyzer A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.2, FortiAnalyzer 7.4.0 through 7.4.5, FortiAnalyzer 7.2.0 through 7.2.9, FortiAnalyzer 7.0.0 through 7.0.13, FortiAnalyzer 6.4 all versions, FortiAnalyzer 6.2 all versions, | 0,5% | — |
| CVE-2024-50567 | HIGH 7.2 | fortinet fortiweb An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb 7.4.0 through 7.6.0 allows attacker to execute unauthorized code or commands via crafted input. | 2,2% | — |
| CVE-2024-50566 | HIGH 7.2 | fortinet fortimanager A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiManager Cloud 7.6.0 through 7.6.1, FortiManager Cloud 7.4.0 through 7.4.4, FortiManager Cloud 7.2.2 through 7.2.7, FortiManager 7.6.0 th | 1,1% | — |
| CVE-2024-49091 | HIGH 7.2 | microsoft windows_server_2012 Windows Domain Name Service Remote Code Execution Vulnerability | 1,7% | — |
| CVE-2024-49089 | HIGH 7.2 | microsoft windows_10_1507 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 2,1% | — |
| CVE-2024-49042 | HIGH 7.2 | microsoft azure_database_for_postgresql_flexible_server Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability | 1,2% | — |