58.507 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.507 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2018-5525 | MED 4.3 | f5 big-ip_access_policy_manager A local file vulnerability exists in the F5 BIG-IP Configuration utility on versions 13.0.0, 12.1.0-12.1.2, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1 that exposes files containing F5-provided data only and do not include any configuration data, proxied traffic | 1,0% | — |
| CVE-2017-0462 | HIGH 7.0 | linux linux_kernel An elevation of privilege vulnerability in the Qualcomm Seemp driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. | 1,0% | — |
| CVE-2008-3761 | MED 4.9 | vmware vmware_workstation hcmon.sys in VMware Workstation 6.5.1 and earlier, VMware Player 2.5.1 and earlier, VMware ACE 2.5.1 and earlier, and VMware Server 1.0.x before 1.0.9 build 156507 and 2.0.x before 2.0.1 build 156745 uses the METHOD_NEITHER communication method for IOCTLs, whi | 1,0% | — |
| CVE-2026-85917 | HIGH 7.5 | microsoft foundry Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network. | 1,0% | — |
| CVE-2026-69395 | MED 6.5 | microsoft windows_10_1607 Use of externally-controlled format string in Active Directory Certificate Services (AD CS) allows an authorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2026-68791 | HIGH 8.6 | microsoft azure_machine_learning Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2026-67630 | MED 6.5 | microsoft sql_server_2017 Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2026-67629 | MED 6.5 | microsoft sql_server_2017 Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2026-67624 | MED 6.5 | microsoft sql_server_2019 Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2026-49297 | HIGH 8.1 | apache apache-airflow-providers-google Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator` joined GCS object names returned by the bucket listing API directly to a destination filesystem path without normalisation or containment check. A user with w | 1,0% | — |
| CVE-2025-50151 | HIGH 8.8 | apache jena File access paths in configuration files uploaded by users with administrator access are not validated. This issue affects Apache Jena version up to 5.4.0. Users are recommended to upgrade to version 5.5.0, which does not allow arbitrary configuration upload | 1,0% | — |
| CVE-2025-29840 | HIGH 8.8 | microsoft windows_10_1507 Stack-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network. | 1,0% | — |
| CVE-2024-29057 | MED 4.3 | microsoft edge Microsoft Edge (Chromium-based) Spoofing Vulnerability | 1,0% | — |
| CVE-2024-22275 | MED 4.9 | vmware cloud_foundation The vCenter Server contains a partial file read vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to partially read arbitrary files containing sensitive data. | 1,0% | — |
| CVE-2023-37936 | CRIT 9.8 | fortinet fortiswitch A use of hard-coded cryptographic key in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.7 and 6.4.0 through 6.4.13 and 6.2.0 through 6.2.7 and 6.0.0 through 6.0.7 allows attacker to execute unauthorized code or commands via cr | 1,0% | — |
| CVE-2023-36393 | HIGH 7.8 | microsoft windows_10_1507 Windows User Interface Application Core Remote Code Execution Vulnerability | 1,0% | — |
| CVE-2022-43869 | MED 6.5 | ibm elastic_storage_system IBM Spectrum Scale (5.1.0.0 through 5.1.2.8 and 5.1.3.0 through 5.1.5.1) and IBM Elastic Storage System (6.1.0.0 through 6.1.2.4 and 6.1.3.0 through 6.1.4.1) could allow an authenticated user to cause a denial of service through the GUI using a format string a | 1,0% | — |
| CVE-2021-22038 | HIGH 8.8 | vmware installbuilder On Windows, the uninstaller binary copies itself to a fixed temporary location, which is then executed (the originally called uninstaller exits, so it does not block the installation directory). This temporary location is not randomized and does not restrict a | 1,0% | — |
| CVE-2021-22003 | HIGH 7.5 | vmware cloud_foundation VMware Workspace ONE Access and Identity Manager, unintentionally provide a login interface on port 7443. A malicious actor with network access to port 7443 may attempt user enumeration or brute force the login endpoint, which may or may not be practical based | 1,0% | — |
| CVE-2020-8950 | HIGH 7.8 | amd user_experience_program The AUEPLauncher service in Radeon AMD User Experience Program Launcher through 1.0.0.1 on Windows allows elevation of privilege by placing a crafted file in %PROGRAMDATA%\AMD\PPC\upload and then creating a symbolic link in %PROGRAMDATA%\AMD\PPC\temp that poin | 1,0% | — |
| CVE-2019-20096 | MED 5.5 | canonical ubuntu_linux In the Linux kernel before 5.1, there is a memory leak in __feat_register_sp() in net/dccp/feat.c, which may cause denial of service, aka CID-1d3ff0950e2b. | 1,0% | — |
| CVE-2019-17655 | MED 5.3 | fortinet fortios A cleartext storage in a file or on disk (CWE-313) vulnerability in FortiOS SSL VPN 6.2.0 through 6.2.2, 6.0.9 and earlier and FortiProxy 2.0.0, 1.2.9 and earlier may allow an attacker to retrieve a logged-in SSL VPN user's credentials should that attacker be | 1,0% | — |
| CVE-2019-10084 | HIGH 7.5 | apache impala In Apache Impala 2.7.0 to 3.2.0, an authenticated user with access to the IDs of active Impala queries or sessions can interact with those sessions or queries via a specially-constructed request and thereby potentially bypass authorization and audit mechanisms | 1,0% | — |
| CVE-2011-1576 | MED 5.7 | linux linux_kernel The Generic Receive Offload (GRO) implementation in the Linux kernel 2.6.18 on Red Hat Enterprise Linux 5 and 2.6.32 on Red Hat Enterprise Linux 6, as used in Red Hat Enterprise Virtualization (RHEV) Hypervisor and other products, allows remote attackers to ca | 1,0% | — |
| CVE-2024-26257 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 1,0% | — |