58.507 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.507 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2024-21330 | HIGH 7.8 | microsoft azure_automation Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability | 1,0% | — |
| CVE-2022-31707 | HIGH 7.2 | vmware vrealize_operations vRealize Operations (vROps) contains a privilege escalation vulnerability. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 7.2. | 1,0% | — |
| CVE-2021-23009 | HIGH 7.5 | f5 big-ip_access_policy_manager On BIG-IP version 16.0.x before 16.0.1.1 and 15.1.x before 15.1.3, malformed HTTP/2 requests may cause an infinite loop which causes a Denial of Service for Data Plane traffic. TMM takes the configured HA action when the TMM process is aborted. There is no con | 1,0% | — |
| CVE-2020-4299 | MED 4.3 | ibm sterling_file_gateway IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.3.1 could expose sensitive information to a user through a specially crafted HTTP request. IBM X-Force ID: 176606. | 1,0% | — |
| CVE-2017-2318 | MED 6.5 | juniper northstar_controller A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an authenticated malicious user to read log files which will compromise the integrity of the system, or provide elevation of privileges. | 1,0% | — |
| CVE-2026-85885 | CRIT 9.9 | microsoft 365_copilot Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network. | 1,0% | — |
| CVE-2026-77908 | HIGH 8.8 | microsoft dynamics_365 Improper control of generation of code ('code injection') in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network. | 1,0% | — |
| CVE-2026-69716 | HIGH 8.8 | microsoft sharepoint_server Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | 1,0% | — |
| CVE-2026-68789 | CRIT 9.9 | microsoft azure_sql_database Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network. | 1,0% | — |
| CVE-2026-68782 | CRIT 9.9 | microsoft azure_sql_database Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network. | 1,0% | — |
| CVE-2026-67370 | HIGH 8.8 | microsoft sql_server_2017 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | 1,0% | — |
| CVE-2026-66820 | HIGH 8.8 | microsoft sql_server_2017 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | 1,0% | — |
| CVE-2026-66819 | HIGH 8.8 | microsoft sql_server_2017 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | 1,0% | — |
| CVE-2026-56197 | HIGH 8.8 | microsoft windows_admin_center Improper neutralization of special elements used in a command ('command injection') in Windows Admin Center allows an authorized attacker to execute code over a network. | 1,0% | — |
| CVE-2026-47295 | HIGH 8.8 | microsoft sql_server_2016 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | 1,0% | — |
| CVE-2026-42898 | CRIT 9.9 | microsoft dynamics_365 Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network. | 1,0% | — |
| CVE-2026-33006 | MED 4.8 | apache http_server A timing attack against mod_auth_digest in Apache HTTP Server 2.4.66 allows a bypass of Digest authentication by a remote attacker. Users are recommended to upgrade to version 2.4.67, which fixes this issue. | 1,0% | — |
| CVE-2026-26116 | HIGH 8.8 | microsoft sql_server_2016 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | 1,0% | — |
| CVE-2023-38522 | HIGH 7.5 | apache traffic_server Apache Traffic Server accepts characters that are not allowed for HTTP field names and forwards malformed requests to origin servers. This can be utilized for request smuggling and may also lead cache poisoning if the origin servers are vulnerable. This issue | 1,0% | — |
| CVE-2023-36593 | HIGH 7.8 | microsoft windows_10 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 1,0% | — |
| CVE-2023-21796 | HIGH 8.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 1,0% | — |
| CVE-2023-21775 | HIGH 8.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 1,0% | — |
| CVE-2021-47348 | CRIT 9.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Avoid HDCP over-read and corruption Instead of reading the desired 5 bytes of the actual target field, the code was reading 8. This could result in a corrupted value if the | 1,0% | — |
| CVE-2021-40128 | MED 5.3 | cisco webex_meetings A vulnerability in the account activation feature of Cisco Webex Meetings could allow an unauthenticated, remote attacker to send an account activation email with an activation link that points to an arbitrary domain. This vulnerability is due to insufficient | 1,0% | — |
| CVE-2009-3621 | MED 5.5 | canonical ubuntu_linux net/unix/af_unix.c in the Linux kernel 2.6.31.4 and earlier allows local users to cause a denial of service (system hang) by creating an abstract-namespace AF_UNIX listening socket, performing a shutdown operation on this socket, and then performing a series o | 1,0% | — |