58.387 CVE seguite
792 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.387 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più basso | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2024-6149 | MED 6.1 | citrix workspace Redirection of users to a vulnerable URL in Citrix Workspace app for HTML5 | 0,2% | — |
| CVE-2024-5913 | MED 6.1 | paloaltonetworks pan-os An improper input validation vulnerability in Palo Alto Networks PAN-OS software enables an attacker with the ability to tamper with the physical file system to elevate privileges. | 0,2% | — |
| CVE-2024-57878 | MED 6.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: arm64: ptrace: fix partial SETREGSET for NT_ARM_FPMR Currently fpmr_set() doesn't initialize the temporary 'fpmr' variable, and a SETREGSET call with a length of zero will leave this uniniti | 0,2% | — |
| CVE-2024-57877 | MED 6.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: arm64: ptrace: fix partial SETREGSET for NT_ARM_POE Currently poe_set() doesn't initialize the temporary 'ctrl' variable, and a SETREGSET call with a length of zero will leave this uninitial | 0,2% | — |
| CVE-2024-57874 | MED 6.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: arm64: ptrace: fix partial SETREGSET for NT_ARM_TAGGED_ADDR_CTRL Currently tagged_addr_ctrl_set() doesn't initialize the temporary 'ctrl' variable, and a SETREGSET call with a length of zero | 0,2% | — |
| CVE-2024-55541 | MED 6.1 | acronis cyber_protect Stored cross-site scripting (XSS) vulnerability due to missing origin validation in postMessage. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39169. | 0,3% | — |
| CVE-2024-5492 | MED 6.1 | citrix netscaler_application_delivery_controller Open redirect vulnerability allows a remote unauthenticated attacker to redirect users to arbitrary websites in NetScaler ADC and NetScaler Gateway | 0,6% | — |
| CVE-2024-54138 | MED 6.1 | microsoft nugetgallery NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability related to its handling of autolinks in Markdown content. While the platform properly filters out JavaScript from standard links, it does not adequately | 0,4% | — |
| CVE-2024-52318 | MED 6.1 | apache tomcat Incorrect object recycling and reuse vulnerability in Apache Tomcat. This issue affects Apache Tomcat: 11.0.0, 10.1.31, 9.0.96. Users are recommended to upgrade to version 11.0.1, 10.1.32 or 9.0.97, which fixes the issue. | 1,7% | — |
| CVE-2024-49349 | MED 6.1 | ibm financial_transaction_manager_for_multiplatform IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.1 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the inten | 0,2% | — |
| CVE-2024-45031 | MED 6.1 | apache syncope When editing objects in the Syncope Console, incomplete HTML tags could be used to bypass HTML sanitization. This made it possible to inject stored XSS payloads which would trigger for other users during ordinary usage of the application. XSS payloads could al | 0,7% | — |
| CVE-2024-44088 | MED 6.1 | apache geode Malicious script injection ('Cross-site Scripting') vulnerability in Apache Geode web-api (REST). This vulnerability allows an attacker that tricks a logged-in user into clicking a specially-crafted link to execute code on the returned page, which could lead t | 0,7% | — |
| CVE-2024-42423 | MED 6.1 | citrix workspace Citrix Workspace App version 23.9.0.24.4 on Dell ThinOS 2311 contains an Incorrect Authorization vulnerability when Citrix CEB is enabled for WebLogin. A local unauthenticated user with low privileges may potentially exploit this vulnerability to bypass existi | 0,2% | — |
| CVE-2024-41937 | MED 6.1 | apache airflow Apache Airflow, versions before 2.10.0, have a vulnerability that allows the developer of a malicious provider to execute a cross-site scripting attack when clicking on a provider documentation link. This would require the provider to be installed on the web s | 1,7% | — |
| CVE-2024-41177 | MED 6.1 | apache zeppelin Incomplete Blacklist to Cross-Site Scripting vulnerability in Apache Zeppelin. This issue affects Apache Zeppelin: before 0.12.0. Users are recommended to upgrade to version 0.12.0, which fixes the issue. | 0,6% | — |
| CVE-2024-3841 | MED 6.1 | fedoraproject fedora Insufficient data validation in Browser Switcher in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to inject scripts or HTML into a privileged page via a malicious file. (Chromium security severity: Medium) | 0,7% | — |
| CVE-2024-38208 | MED 6.1 | microsoft edge Microsoft Edge for Android Spoofing Vulnerability | 0,4% | — |
| CVE-2024-38156 | MED 6.1 | microsoft edge Microsoft Edge (Chromium-based) Spoofing Vulnerability | 0,4% | — |
| CVE-2024-37304 | MED 6.1 | microsoft nugetgallery NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability related to its handling of autolinks in Markdown content. While the platform properly filters out JavaScript from standard links, it does not adequately | 0,7% | — |
| CVE-2024-33604 | MED 6.1 | f5 big-ip_access_policy_manager A reflected cross-site scripting (XSS) vulnerability exist in undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Tec | 0,3% | — |
| CVE-2024-31868 | MED 6.1 | apache zeppelin Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin. The attackers can modify helium.json and exposure XSS attacks to normal users. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1. Users are recommended to upgrade to version | 1,3% | — |
| CVE-2024-30059 | MED 6.1 | microsoft intune_mobile_application_management Microsoft Intune for Android Mobile Application Management Tampering Vulnerability | 0,6% | — |
| CVE-2024-27136 | MED 6.1 | apache jspwiki XSS in Upload page in Apache JSPWiki 2.12.1 and priors allows the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.12.2 or later. | 60,8% | — |
| CVE-2024-25709 | MED 6.1 | esri portal_for_arcgis There is a stored Cross‑Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS versions 11.2 and below that may allow a remote, authenticated attacker to create a crafted link that can be saved as a new location when moving an existing item, which could | 0,4% | — |
| CVE-2024-25698 | MED 6.1 | esri portal_for_arcgis There is a reflected cross site scripting vulnerability in the home application in Esri Portal for ArcGIS 11.1 and below on Windows and Linux that allows a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute a | 0,4% | — |