EN
58.559 CVE seguite
797 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.559 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordinato dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2025-49666 HIGH 7.2 microsoft windows_server_2016 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to execute code over a network. 1,3% —
CVE-2025-47856 HIGH 7.2 fortinet fortivoice Two improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiVoice version 7.2.0, 7.0.0 through 7.0.6 and before 6.4.10 allows a privileged attacker to execute arbitrary code or comman 1,3% —
CVE-2025-4615 HIGH 7.2 paloaltonetworks pan-os An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and execute arbitrary commands. The security risk posed by this issu 0,8% —
CVE-2025-4231 HIGH 7.2 paloaltonetworks pan-os A command injection vulnerability in Palo Alto Networks PAN-OS® enables an authenticated administrative user to perform actions as the root user. The attacker must have network access to the management web interface and successfully authenticate to exploit th 1,0% —
CVE-2025-3944 HIGH 7.2 tridium niagara Incorrect Permission Assignment for Critical Resource vulnerability in Tridium Niagara Framework on QNX, Tridium Niagara Enterprise Security on QNX allows File Manipulation. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Ni 0,5% —
CVE-2025-36048 HIGH 7.2 ibm webmethods_integration IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15 could allow a privileged user to escalate their privileges when handling external entities due to execution with unnecessary privileges. 0,5% —
CVE-2025-31104 HIGH 7.2 fortinet fortiadc A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiADC 7.6.0 through 7.6.1, FortiADC 7.4.0 through 7.4.6, FortiADC 7.2.0 through 7.2.7, FortiADC 7.1.0 through 7.1.4, FortiADC 7.0 all vers 1,1% —
CVE-2025-30067 HIGH 7.2 apache kylin Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Kylin. If an attacker gets access to Kylin's system or project admin permission, the JDBC connection configuration maybe altered to execute arbitrary code from the remote. You a 0,9% —
CVE-2025-29793 HIGH 7.2 microsoft sharepoint_enterprise_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 23,6% —
CVE-2025-25254 HIGH 7.2 fortinet fortiweb An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiWeb version 7.6.2 and below, version 7.4.6 and below, 7.2 all versions, 7.0 all versions endpoint may allow an authenticated admin to access and mo 17,1% —
CVE-2025-24053 HIGH 7.2 microsoft dataverse Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network. 0,7% —
CVE-2025-21348 HIGH 7.2 microsoft sharepoint_server Microsoft SharePoint Server Remote Code Execution Vulnerability 1,8% —
CVE-2024-9474 HIGH 7.2 ransomware paloaltonetworks pan-os A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access are not impacted by this 94,7%
CVE-2024-8686 HIGH 7.2 paloaltonetworks pan-os A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as root on the firewall. 1,4% —
CVE-2024-54181 HIGH 7.2 ibm websphere_automation IBM WebSphere Automation 1.7.5 could allow a remote privileged user, who has authorized access to the swagger UI, to execute arbitrary code. Using specially crafted input, the user could exploit this vulnerability to execute arbitrary code on the system. 1,0% —
CVE-2024-54024 HIGH 7.2 fortinet fortiisolator An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiIsolator before version 2.4.6 allows a privileged attacker with super-admin profile and CLI access to execute unauthorized cod 1,2% —
CVE-2024-54018 HIGH 7.2 fortinet fortisandbox Multiple improper neutralization of special elements used in an OS Command vulnerabilities [CWE-78] in FortiSandbox before 4.4.5 allows a privileged attacker to execute unauthorized commands via crafted requests. 10,0% —
CVE-2024-52965 HIGH 7.2 fortinet fortios A missing critical step in authentication vulnerability [CWE-304] in Fortinet FortiOS version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 through 7.2.10, and before 7.0.16 & FortiProxy version 7.6.0 through 7.6.1, 7.4.0 through 7.4.8, 7.2.0 through 7.2.13 0,3% —
CVE-2024-52052 HIGH 7.2 wowza streaming_engine Wowza Streaming Engine below 4.9.1 permits an authenticated Streaming Engine Manager administrator to define a custom application property and poison a stream target for high-privilege remote code execution. 0,5% —
CVE-2024-50571 HIGH 7.2 fortinet fortianalyzer A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.2, FortiAnalyzer 7.4.0 through 7.4.5, FortiAnalyzer 7.2.0 through 7.2.9, FortiAnalyzer 7.0.0 through 7.0.13, FortiAnalyzer 6.4 all versions, FortiAnalyzer 6.2 all versions, 0,5% —
CVE-2024-50567 HIGH 7.2 fortinet fortiweb An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb 7.4.0 through 7.6.0 allows attacker to execute unauthorized code or commands via crafted input. 2,2% —
CVE-2024-50566 HIGH 7.2 fortinet fortimanager A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiManager Cloud 7.6.0 through 7.6.1, FortiManager Cloud 7.4.0 through 7.4.4, FortiManager Cloud 7.2.2 through 7.2.7, FortiManager 7.6.0 th 1,1% —
CVE-2024-49091 HIGH 7.2 microsoft windows_server_2012 Windows Domain Name Service Remote Code Execution Vulnerability 1,7% —
CVE-2024-49089 HIGH 7.2 microsoft windows_10_1507 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 2,1% —
CVE-2024-49042 HIGH 7.2 microsoft azure_database_for_postgresql_flexible_server Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability 1,2% —