58.507 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.507 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2020-1381 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1382. | 1,0% | — |
| CVE-2020-1253 | MED 6.7 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1207, CVE-2020-1247, CVE-2020-1251, | 1,0% | — |
| CVE-2013-5563 | MED 4.3 | cisco security_monitoring_analysis_and_response_system Cross-site scripting (XSS) vulnerability in Query/NewQueryResult.jsp in Cisco Security Monitoring, Analysis and Response System (CS-MARS) allows remote attackers to inject arbitrary web script or HTML via the isnowLatency parameter, aka Bug ID CSCul16173. | 1,0% | — |
| CVE-2024-49038 | CRIT 9.3 | microsoft copilot_studio Improper neutralization of input during web page generation ('Cross-site Scripting') in Copilot Studio by an unauthorized attacker leads to elevation of privilege over a network. | 1,0% | — |
| CVE-2024-27388 | CRIT 9.8 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: SUNRPC: fix some memleaks in gssx_dec_option_array The creds and oa->data need to be freed in the error-handling paths after their allocation. So this patch add these deallocations in the co | 1,0% | — |
| CVE-2020-3318 | CRIT 9.8 | cisco secure_firewall_management_center Multiple vulnerabilities in Cisco Firepower Management Center (FMC) Software and Cisco Firepower User Agent Software could allow an attacker to access a sensitive part of an affected system with a high-privileged account. For more information about these vulne | 1,0% | — |
| CVE-2020-0686 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0683. | 1,0% | — |
| CVE-2019-1768 | MED 6.7 | cisco nx-os A vulnerability in the implementation of a specific CLI command for Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to cause a buffer overflow condition or perform command injection. This could allow the attacke | 1,0% | — |
| CVE-2019-1767 | MED 6.7 | cisco nx-os A vulnerability in the implementation of a specific CLI command for Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to cause a buffer overflow condition or perform command injection. This could allow the attacke | 1,0% | — |
| CVE-2015-0675 | HIGH 8.3 | cisco adaptive_security_appliance_software The failover ipsec implementation in Cisco Adaptive Security Appliance (ASA) Software 9.1 before 9.1(6), 9.2 before 9.2(3.3), and 9.3 before 9.3(3) does not properly validate failover communication messages, which allows remote attackers to reconfigure an ASA | 1,0% | — |
| CVE-2014-2851 | MED 6.9 | debian debian_linux Integer overflow in the ping_init_sock function in net/ipv4/ping.c in the Linux kernel through 3.14.1 allows local users to cause a denial of service (use-after-free and system crash) or possibly gain privileges via a crafted application that leverages an impr | 1,0% | — |
| CVE-2012-0957 | MED 4.9 | linux linux_kernel The override_release function in kernel/sys.c in the Linux kernel before 3.4.16 allows local users to obtain sensitive information from kernel stack memory via a uname system call in conjunction with a UNAME26 personality. | 1,0% | — |
| CVE-2008-0009 | LOW 2.1 | linux linux_kernel The vmsplice_to_user function in fs/splice.c in the Linux kernel 2.6.22 through 2.6.24 does not validate a certain userspace pointer before dereference, which might allow local users to access arbitrary kernel memory locations. | 1,0% | — |
| CVE-2004-1333 | LOW 2.1 | linux linux_kernel Integer overflow in the vc_resize function in the Linux kernel 2.4 and 2.6 before 2.6.10 allows local users to cause a denial of service (kernel crash) via a short new screen value, which leads to a buffer overflow. | 1,0% | — |
| CVE-2026-65811 | HIGH 8.8 | microsoft power_bi_report_server Improper input validation in Power BI allows an authorized attacker to execute code over a network. | 1,0% | — |
| CVE-2026-54120 | CRIT 9.9 | microsoft surface_management_services Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network. | 1,0% | — |
| CVE-2026-40411 | CRIT 9.9 | microsoft azure_virtual_network_gateway Improper input validation in Azure Virtual Network Gateway allows an authorized attacker to execute code over a network. | 1,0% | — |
| CVE-2026-26115 | HIGH 8.8 | microsoft sql_server_2016 Improper validation of specified type of input in SQL Server allows an authorized attacker to elevate privileges over a network. | 1,0% | — |
| CVE-2026-21229 | HIGH 8.0 | microsoft power_bi_report_server Improper input validation in Power BI allows an authorized attacker to execute code over a network. | 1,0% | — |
| CVE-2022-47502 | HIGH 7.8 | apache openoffice Apache OpenOffice documents can contain links that call internal macros with arbitrary arguments. Several URI Schemes are defined for this purpose. Links can be activated by clicks, or by automatic document events. The execution of such links must be subjec | 1,0% | — |
| CVE-2022-43286 | CRIT 9.8 | f5 njs Nginx NJS v0.7.2 was discovered to contain a heap-use-after-free bug caused by illegal memory copy in the function njs_json_parse_iterator_call at njs_json.c. | 1,0% | — |
| CVE-2022-22177 | MED 5.3 | juniper junos A release of illegal memory vulnerability in the snmpd daemon of Juniper Networks Junos OS, Junos OS Evolved allows an attacker to halt the snmpd daemon causing a sustained Denial of Service (DoS) to the service until it is manually restarted. This issue impac | 1,0% | — |
| CVE-2021-34491 | MED 5.5 | microsoft windows_10 Win32k Information Disclosure Vulnerability | 1,0% | — |
| CVE-2021-24006 | MED 6.3 | fortinet fortimanager An improper access control vulnerability in FortiManager versions 6.4.0 to 6.4.3 may allow an authenticated attacker with a restricted user profile to access the SD-WAN Orchestrator panel via directly visiting its URL. | 1,0% | — |
| CVE-2021-1417 | CRIT 9.9 | cisco jabber Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system with elevated privileges, access sensitive information, | 1,0% | — |