EN
56.713 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia

CVE Tracker

56.713 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordinato dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2026-0284 CRIT 9.9 paloaltonetworks pan-os An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to inject malicious XML content, potentially leading to information disclosure or corrupt 0,5%
CVE-2025-64663 CRIT 9.9 microsoft azure_language Custom Question Answering Elevation of Privilege Vulnerability 0,7%
CVE-2025-55315 CRIT 9.9 microsoft asp.net_core Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network. 65,8%
CVE-2025-49747 CRIT 9.9 microsoft azure_machine_learning Missing authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network. 0,7%
CVE-2025-49746 CRIT 9.9 microsoft azure_machine_learning Improper authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network. 0,7%
CVE-2025-49708 CRIT 9.9 microsoft windows_10_1809 Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges over a network. 1,2%
CVE-2025-30390 CRIT 9.9 microsoft azure_machine_learning Improper authorization in Azure allows an authorized attacker to elevate privileges over a network. 0,9%
CVE-2025-29972 CRIT 9.9 microsoft azure_storage_resource_provider Server-side request forgery (ssrf) in Azure Storage Resource Provider allows an authorized attacker to perform spoofing over a network. 3,2%
CVE-2025-29827 CRIT 9.9 microsoft azure_automation Improper authorization in Azure Automation allows an authorized attacker to elevate privileges over a network. 1,6%
CVE-2025-21415 CRIT 9.9 microsoft azure_ai_face_service Authentication bypass by spoofing in Azure AI Face Service allows an authorized attacker to elevate privileges over a network. 0,9%
CVE-2025-20333 CRIT 9.9 cisco adaptive_security_appliance_software A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker to execute arbitrary code on an affected device. 70,7%
CVE-2025-20286 CRIT 9.9 cisco identity_services_engine A vulnerability in Amazon Web Services (AWS), Microsoft Azure, and Oracle Cloud Infrastructure (OCI) cloud deployments of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to access sensitive data, execute limited administrat 1,1%
CVE-2025-20156 CRIT 9.9 cisco meeting_management A vulnerability in the REST API of Cisco Meeting Management could allow a remote, authenticated attacker with low privileges to elevate privileges to administrator on an affected device. This vulnerability exists because proper authorization is not enforced 1,2%
CVE-2025-20124 CRIT 9.9 cisco identity_services_engine A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands as the root user on an affected device. This vulnerability is due to insecure deserialization of user-supplied Java byte streams by the affect 18,5%
CVE-2025-13032 CRIT 9.9 avast antivirus Double fetch in sandbox kernel driver in Avast/AVG Antivirus <25.3  on windows allows local attacker to escalate privelages via pool overflow. 0,2%
CVE-2024-45387 CRIT 9.9 apache traffic_control An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with role "admin", "federation", "operations", "portal", or "steering" to execute arbitrary SQL against the database by sending a specially-craf 41,5%
CVE-2024-43602 CRIT 9.9 microsoft azure_cyclecloud Azure CycleCloud Remote Code Execution Vulnerability 2,3%
CVE-2024-25693 CRIT 9.9 esri portal_for_arcgis There is a path traversal in Esri Portal for ArcGIS versions <= 11.2. Successful exploitation may allow a remote, authenticated attacker to traverse the file system to access files or execute code outside of the intended directory.  1,3%
CVE-2024-23538 CRIT 9.9 apache fineract Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Fineract.This issue affects Apache Fineract: <1.8.5. Users are recommended to upgrade to version 1.8.5 or 1.9.0, which fix the issue. 1,3%
CVE-2024-20432 CRIT 9.9 cisco nexus_dashboard_fabric_controller A vulnerability in the REST API and web UI of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, low-privileged, remote attacker to perform a command injection attack against an affected device. &nbsp; This vulnerability is due to i 1,1%
CVE-2024-20424 CRIT 9.9 cisco secure_firewall_management_center A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operat 0,9%
CVE-2024-20329 CRIT 9.9 cisco adaptive_security_appliance_software A vulnerability in the SSH subsystem of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker to execute operating system commands as root. This vulnerability is due to insufficient validation of user input. An attac 1,2%
CVE-2024-20253 CRIT 9.9 cisco unified_communications_manager A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to the improper processing of user-provide 2,4%
CVE-2023-41373 CRIT 9.9 f5 big-ip_access_policy_manager A directory traversal vulnerability exists in the BIG-IP Configuration Utility that may allow an authenticated attacker to execute commands on the BIG-IP system. For BIG-IP system running in Appliance mode, a successful exploit can allow the attacker to cross 2,4%
CVE-2023-40714 CRIT 9.9 fortinet fortisiem A relative path traversal in Fortinet FortiSIEM versions 7.0.0, 6.7.0 through 6.7.2, 6.6.0 through 6.6.3, 6.5.1, 6.5.0 allows attacker to escalate privilege via uploading certain GUI elements 0,6%