58.412 CVE seguite
792 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.412 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2023-29352 | MED 6.5 | microsoft remote_desktop_client Windows Remote Desktop Security Feature Bypass Vulnerability | 1,2% | — |
| CVE-2021-31353 | HIGH 7.5 | juniper junos An Improper Handling of Exceptional Conditions vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows an attacker to inject a specific BGP update, causing the routing protocol daemon (RPD) to crash and restart, leading to a Denial of Service (D | 1,2% | — |
| CVE-2017-5075 | MED 4.3 | google chrome Inappropriate implementation in CSP reporting in Blink in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to obtain the value of url fragments via a crafted HTML page. | 1,2% | — |
| CVE-2016-4927 | HIGH 8.1 | juniper junos_space Insufficient validation of SSH keys in Junos Space before 15.2R2 allows man-in-the-middle (MITM) type of attacks while a Space device is communicating with managed devices. | 1,2% | — |
| CVE-1999-0824 | MED 4.6 | microsoft windows_nt A Windows NT user can use SUBST to map a drive letter to a folder, which is not unmapped after the user logs off, potentially allowing that user to modify the location of folders accessed by later users. | 1,2% | — |
| CVE-1999-0384 | MED 4.6 | microsoft office The Forms 2.0 ActiveX control (included with Visual Basic for Applications 5.0) can be used to read text from a user's clipboard when the user accesses documents with ActiveX content. | 1,2% | — |
| CVE-2026-75723 | CRIT 10.0 | adobe campaign Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this | 1,2% | — |
| CVE-2026-48286 | CRIT 10.0 | adobe campaign Adobe Campaign Classic (ACC) versions 7.4.3 build 9396 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user inter | 1,2% | — |
| CVE-2025-24994 | HIGH 7.3 | microsoft windows_11_22h2 Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally. | 1,2% | — |
| CVE-2023-38430 | CRIT 9.1 | linux linux_kernel An issue was discovered in the Linux kernel before 6.3.9. ksmbd does not validate the SMB request protocol ID, leading to an out-of-bounds read. | 1,2% | — |
| CVE-2021-47378 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvme-rdma: destroy cm id before destroy qp to avoid use after free We should always destroy cm_id before destroy qp to avoid to get cma event after qp was destroyed, which may lead to use af | 1,2% | — |
| CVE-2021-35245 | HIGH 8.4 | solarwinds serv-u When a user has admin rights in Serv-U Console, the user can move, create and delete any files are able to be accessed on the Serv-U host machine. | 1,2% | — |
| CVE-2017-9487 | MED 5.9 | cisco dpc3939_firmware The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) and DPC3941T (firmware version DPC3941_2.5s3_PROD_sey) devices allows remote attackers to discover a WAN IPv6 IP address by leveraging knowledge of the CM MAC a | 1,2% | — |
| CVE-2013-1283 | MED 6.9 | microsoft windows_7 Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows loca | 1,2% | — |
| CVE-2011-1647 | MED 5.0 | cisco rvs4000 The web management interface on the Cisco RVS4000 Gigabit Security Router with software 1.x before 1.3.3.4 and 2.x before 2.0.2.7, and the WRVS4400N Gigabit Security Router with software before 2.0.2.1, allows remote attackers to read the private key for the a | 1,2% | — |
| CVE-2026-67587 | HIGH 8.8 | apache airflow Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the stored callback path. Because `SyncCallback` is itself an Airflow class it passes the default `allowed_deserializati | 1,2% | — |
| CVE-2025-61795 | MED 5.3 | apache tomcat Improper Resource Shutdown or Release vulnerability in Apache Tomcat. If an error occurred (including exceeding limits) during the processing of a multipart upload, temporary copies of the uploaded parts written to disc were not cleaned up immediately but lef | 1,2% | — |
| CVE-2024-43574 | HIGH 8.3 | microsoft windows_10_21h2 Microsoft Speech Application Programming Interface (SAPI) Remote Code Execution Vulnerability | 1,2% | — |
| CVE-2023-28290 | MED 5.3 | microsoft remote_desktop_app Microsoft Remote Desktop app for Windows Information Disclosure Vulnerability | 1,2% | — |
| CVE-2022-30175 | HIGH 7.8 | microsoft azure_real_time_operating_system_guix_studio Azure RTOS GUIX Studio Remote Code Execution Vulnerability | 1,2% | — |
| CVE-2021-26431 | HIGH 7.8 | microsoft windows_10 Windows Recovery Environment Agent Elevation of Privilege Vulnerability | 1,2% | — |
| CVE-2021-26097 | HIGH 8.8 | fortinet fortisandbox An improper neutralization of special elements used in an OS Command vulnerability in FortiSandbox 3.2.0 through 3.2.2, 3.1.0 through 3.1.4, and 3.0.0 through 3.0.6 may allow an authenticated attacker with access to the web GUI to execute unauthorized code or | 1,2% | — |
| CVE-2020-29478 | HIGH 7.5 | broadcom ca_service_catalog CA Service Catalog 17.2 and 17.3 contain a vulnerability in the default configuration of the Setup Utility that may allow a remote attacker to cause a denial of service condition. | 1,2% | — |
| CVE-2020-1398 | MED 6.8 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows Lockscreen fails to properly handle Ease of Access dialog.An attacker who successfully exploited the vulnerability could execute commands with elevated permissions.The security update addresses the vu | 1,2% | — |
| CVE-2019-1065 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, | 1,2% | — |