58.507 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.507 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2025-21415 | CRIT 9.9 | microsoft azure_ai_face_service Authentication bypass by spoofing in Azure AI Face Service allows an authorized attacker to elevate privileges over a network. | 0,9% | — |
| CVE-2025-21354 | HIGH 8.4 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 0,9% | — |
| CVE-2024-49093 | HIGH 8.8 | microsoft windows_11_24h2 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability | 0,9% | — |
| CVE-2022-33871 | MED 6.6 | fortinet fortiweb A stack-based buffer overflow vulnerability [CWE-121] in FortiWeb version 7.0.1 and earlier, 6.4 all versions, version 6.3.19 and earlier may allow a privileged attacker to execute arbitrary code or commands via specifically crafted CLI `execute backup-local r | 0,9% | — |
| CVE-2021-41013 | MED 5.3 | fortinet fortiweb An improper access control vulnerability [CWE-284] in FortiWeb versions 6.4.1 and below and 6.3.15 and below in the Report Browse section of Log & Report may allow an unauthorized and unauthenticated user to access the Log reports via their URLs. | 0,9% | — |
| CVE-2021-1418 | CRIT 9.9 | cisco jabber Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system with elevated privileges, access sensitive information, | 0,9% | — |
| CVE-2020-16902 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior.</p> <p>A locally authenticated attacker could run arbitrary code with elevat | 0,9% | — |
| CVE-2019-17070 | MED 6.1 | lqd liquid_speech_balloon The liquid-speech-balloon (aka LIQUID SPEECH BALLOON) plugin before 1.0.7 for WordPress allows XSS with Internet Explorer. | 0,9% | — |
| CVE-2017-6772 | MED 4.3 | cisco elastic_services_controller A vulnerability in Cisco Elastic Services Controller (ESC) could allow an authenticated, remote attacker to view sensitive information. The vulnerability is due to insufficient protection of sensitive data. An attacker could exploit this vulnerability by authe | 0,9% | — |
| CVE-2017-3889 | MED 6.1 | cisco registered_envelope_service A vulnerability in the web interface of the Cisco Registered Envelope Service could allow an unauthenticated, remote attacker to redirect a user to a undesired web page, aka an Open Redirect. This vulnerability affects the Cisco Registered Envelope cloud-based | 0,9% | — |
| CVE-2017-3871 | MED 4.3 | cisco prime_optical A RADIUS Secret Disclosure vulnerability in the web network management interface of Cisco Prime Optical for Service Providers could allow an authenticated, remote attacker to disclose sensitive information in the configuration generated for a device. The attac | 0,9% | — |
| CVE-2026-70324 | HIGH 8.8 | microsoft sharepoint_server Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | 0,9% | — |
| CVE-2026-64921 | HIGH 8.8 | microsoft sharepoint_server Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | 0,9% | — |
| CVE-2026-62827 | HIGH 8.8 | microsoft sharepoint_server Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | 0,9% | — |
| CVE-2026-58277 | HIGH 8.8 | microsoft sharepoint_server Improper authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | 0,9% | — |
| CVE-2026-55052 | HIGH 8.8 | microsoft sharepoint_server Missing authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | 0,9% | — |
| CVE-2026-34032 | MED 5.3 | apache http_server Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue. | 0,9% | — |
| CVE-2026-33857 | MED 5.3 | apache http_server Out-of-bounds Read vulnerability in mod_proxy_ajp of Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue. | 0,9% | — |
| CVE-2024-38204 | HIGH 7.5 | microsoft azure_functions Improper access control in Imagine Cup allows an authorized attacker to elevate privileges over a network. | 0,9% | — |
| CVE-2023-52340 | HIGH 7.5 | linux linux_kernel The IPv6 implementation in the Linux kernel before 6.3 has a net/ipv6/route.c max_size threshold that can be consumed easily, e.g., leading to a denial of service (network is unreachable errors) when IPv6 packets are sent in a loop via a raw socket. | 0,9% | — |
| CVE-2023-29542 | CRIT 9.8 | mozilla firefox A newline in a filename could have been used to bypass the file extension security mechanisms that replace malicious file extensions such as .lnk with .download. This could have led to accidental execution of malicious code. *This bug only affects Firefox an | 0,9% | — |
| CVE-2021-34510 | HIGH 7.8 | microsoft windows_10 Windows Storage Spaces Controller Elevation of Privilege Vulnerability | 0,9% | — |
| CVE-2021-22919 | HIGH 7.5 | citrix application_delivery_controller_firmware A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known as NetScaler Gateway), and Citrix SD-WAN WANOP Edition models 4000-WO, 4100-WO, 5000-WO, and 5100-WO. These vulnerabilities, if exploited, co | 0,9% | — |
| CVE-2021-20412 | HIGH 7.5 | ibm security_verify_information_queue IBM Security Verify Information Queue 1.0.6 and 1.0.7 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM | 0,9% | — |
| CVE-2021-1286 | MED 6.5 | cisco data_center_network_manager Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow a remote attacker with network-operator privileges to conduct a cross-site scripting (XSS) attack or a reflected file download (RFD) attack a | 0,9% | — |