58.458 CVE seguite
793 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.458 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2024-38220 | CRIT 9.0 | microsoft azure_stack_hub Azure Stack Hub Elevation of Privilege Vulnerability | 1,0% | — |
| CVE-2024-29736 | CRIT 9.1 | apache cxf A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform SSRF style attacks on REST webservices. The attack only applies if a custom stylesheet parameter is configured. | 1,0% | — |
| CVE-2013-3437 | MED 6.5 | cisco unified_operations_manager SQL injection vulnerability in the management application in Cisco Unified Operations Manager allows remote authenticated users to execute arbitrary SQL commands via an entry field, aka Bug ID CSCud80179. | 1,0% | — |
| CVE-2009-4916 | MED 4.0 | cisco asa_5580 Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote authenticated users to cause a denial of service (console hang) via a login action during failover replication, aka Bug ID CSCsq | 1,0% | — |
| CVE-2009-3002 | MED 4.9 | canonical ubuntu_linux The Linux kernel before 2.6.31-rc7 does not initialize certain data structures within getname functions, which allows local users to read the contents of some kernel memory locations by calling getsockname on (1) an AF_APPLETALK socket, related to the atalk_ge | 1,0% | — |
| CVE-2026-48334 | CRIT 9.3 | adobe illustrator Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session. Exploitation of this is | 1,0% | — |
| CVE-2025-49677 | HIGH 7.0 | microsoft windows_11_22h2 Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. | 1,0% | — |
| CVE-2021-47384 | MED 5.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: hwmon: (w83793) Fix NULL pointer dereference by removing unnecessary structure field If driver read tmp value sufficient for (tmp & 0x08) && (!(tmp & 0x80)) && ((tmp & 0x7) == ((tmp >> 4) & | 1,0% | — |
| CVE-2020-6644 | HIGH 8.1 | fortinet fortideceptor An insufficient session expiration vulnerability in FortiDeceptor 3.0.0 and below allows an attacker to reuse the unexpired admin user session IDs to gain admin privileges, should the attacker be able to obtain that session ID via other, hypothetical attacks. | 1,0% | — |
| CVE-2020-3232 | HIGH 7.7 | cisco ios_xe A vulnerability in the Simple Network Management Protocol (SNMP) implementation in Cisco ASR 920 Series Aggregation Services Router model ASR920-12SZ-IM could allow an authenticated, remote attacker to cause the device to reload. The vulnerability is due to in | 1,0% | — |
| CVE-2026-72989 | HIGH 7.5 | microsoft windows_10_1809 Use of uninitialized resource in Windows Failover Cluster allows an unauthorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2026-72932 | HIGH 7.5 | microsoft windows_10_1607 Buffer over-read in Windows Message Queuing Queue Manager allows an unauthorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2026-71330 | HIGH 7.5 | microsoft windows_10_1607 Exposure of sensitive system information to an unauthorized control sphere in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2026-69519 | HIGH 8.6 | microsoft azure_stack_hci Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2026-69443 | HIGH 7.5 | microsoft windows_10_1809 Out-of-bounds read in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2026-50470 | HIGH 7.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2026-50463 | HIGH 7.5 | microsoft windows_10_1809 Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2026-47633 | HIGH 7.5 | microsoft cost_management Exposure of sensitive information to an unauthorized actor in Cost Management Interactive Experiences allows an unauthorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2026-45639 | HIGH 7.5 | microsoft remote_desktop_client Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2026-42908 | HIGH 7.5 | microsoft windows_10_1607 Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2026-40406 | HIGH 7.5 | microsoft windows_10_1607 Use after free in Windows TCP/IP allows an unauthorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2026-33111 | HIGH 7.5 | microsoft copilot_chat Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2026-26164 | HIGH 7.5 | microsoft 365_copilot_chat Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2026-26129 | HIGH 7.5 | microsoft 365_copilot_chat Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2023-44206 | CRIT 9.1 | acronis cyber_protect Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979. | 1,0% | — |