EN
58.444 CVE seguite
792 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.444 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più alto In KEV dal, ordina dal più alto
CVE-2026-35435 HIGH 8.6 microsoft azure_ai_foundry Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network. 1,1% —
CVE-2026-27784 HIGH 7.8 f5 nginx_open_source The 32-bit implementation of NGINX Open Source has a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to over-read or over-write NGINX worker memory resulting in its termination, using a specially crafted MP4 file. The issue only 1,1% —
CVE-2026-26150 HIGH 8.6 microsoft purview_ediscovery Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network. 1,1% —
CVE-2026-26138 HIGH 8.6 microsoft purview Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network. 1,1% —
CVE-2026-26125 HIGH 8.6 microsoft payment_orchestrator_service Payment Orchestrator Service Elevation of Privilege Vulnerability 1,1% —
CVE-2023-21548 HIGH 8.1 microsoft windows_10_1607 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability 1,1% —
CVE-2023-21535 HIGH 8.1 microsoft windows_10_1607 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability 1,1% —
CVE-2021-31368 HIGH 7.5 juniper junos An Uncontrolled Resource Consumption vulnerability in the kernel of Juniper Networks JUNOS OS allows an unauthenticated network based attacker to cause 100% CPU load and the device to become unresponsive by sending a flood of traffic to the out-of-band managem 1,1% —
CVE-2021-26889 HIGH 7.8 microsoft windows_10 Windows Update Stack Elevation of Privilege Vulnerability 1,1% —
CVE-2021-1133 MED 4.6 cisco data_center_network_manager Multiple vulnerabilities in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For more information about these vulnerabilities, see the 1,1% —
CVE-2019-0892 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. 1,1% —
CVE-2019-0766 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in Windows AppX Deployment Server that allows file creation in arbitrary locations. To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Elevation of Privilege 1,1% —
CVE-2019-0696 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. 1,1% —
CVE-2018-8441 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists due to an integer overflow in Windows Subsystem for Linux, aka "Windows Subsystem for Linux Elevation of Privilege Vulnerability." This affects Windows 10, Windows 10 Servers. 1,1% —
CVE-2018-7636 MED 6.1 paloaltonetworks pan-os The URL filtering "continue page" hosted by PAN-OS 8.0.10 and earlier may allow an attacker to inject arbitrary JavaScript or HTML via specially crafted URLs. 1,1% —
CVE-2017-8466 HIGH 7.8 microsoft windows_10 Windows Cursor in Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and Windows Server 2016 allows improper elevation of privilege, aka "Windows Cursor Elevation of Privilege Vulnerability". 1,1% —
CVE-2013-6694 MED 4.3 cisco ios The IPSec implementation in Cisco IOS allows remote attackers to cause a denial of service (MTU change and tunnel-session drop) via crafted ICMP packets, aka Bug ID CSCul29918. 1,1% —
CVE-2013-5555 MED 4.3 cisco unified_communications_manager Cisco Unified Communications Manager (aka CUCM or Unified CM) allows remote attackers to cause a denial of service (service restart) via a crafted SIP message, aka Bug ID CSCub54349. 1,1% —
CVE-2012-5786 MED 5.8 apache cxf The wsdl_first_https sample code in distribution/src/main/release/samples/wsdl_first_https/src/main/ in Apache CXF before 2.7.0 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.50 1,1% —
CVE-2010-1244 MED 6.8 apache activemq Cross-site request forgery (CSRF) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote attackers to hijack the authentication of unspecified victims for requests that create queues via the JMSDestination parameter in a queue 1,1% —
CVE-2023-42790 HIGH 8.1 fortinet fortios A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4.0 through 6.4.14, FortiOS 6.2.0 through 6.2.15, FortiProxy 7.4.0, FortiProxy 7.2.0 through 7.2.6, FortiP 1,1% —
CVE-2021-42296 HIGH 7.8 microsoft 365_apps Microsoft Word Remote Code Execution Vulnerability 1,1% —
CVE-2019-9116 HIGH 7.8 sublimetext sublime_text_3 DLL hijacking is possible in Sublime Text 3 version 3.1.1 build 3176 on 32-bit Windows platforms because a Trojan horse api-ms-win-core-fibers-l1-1-1.dll or api-ms-win-core-localization-l1-2-1.dll file may be loaded if a victim uses sublime_text.exe to open a 1,1% —
CVE-2013-5096 MED 4.0 juniper junos_space Juniper Junos Space before 13.1R1.6, as used on the JA1500 appliance and in other contexts, does not properly implement role-based access control, which allows remote authenticated users to modify the configuration by leveraging the read-only privilege, aka PR 1,1% —
CVE-2026-48560 MED 5.4 microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 1,1% —