58.507 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.507 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2022-24455 | HIGH 7.8 | microsoft windows_10 Windows CD-ROM Driver Elevation of Privilege Vulnerability | 0,9% | — |
| CVE-2021-22036 | MED 6.5 | vmware vrealize_automation VMware vRealize Orchestrator ((8.x prior to 8.6) contains an open redirect vulnerability due to improper path handling. A malicious actor may be able to redirect victim to an attacker controlled domain due to improper path handling in vRealize Orchestrator lea | 0,9% | — |
| CVE-2021-1420 | MED 4.7 | cisco webex_meetings A vulnerability in certain web pages of Cisco Webex Meetings could allow an unauthenticated, remote attacker to modify a web page in the context of a user's browser. The vulnerability is due to improper checks on parameter values in affected pages. An attacker | 0,9% | — |
| CVE-2020-1598 | MED 6.1 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code with elevated system privileges. | 0,9% | — |
| CVE-2018-0393 | MED 6.5 | cisco mobility_services_engine_3310_firmware A Read-Only User Effect Change vulnerability in the Policy Builder interface of Cisco Policy Suite could allow an authenticated, remote attacker to make policy changes in the Policy Builder interface. The vulnerability is due to insufficient authorization cont | 0,9% | — |
| CVE-2013-6684 | MED 6.8 | cisco wireless_lan_controller The web framework on Cisco Wireless LAN Controller (WLC) devices does not properly validate configuration parameters, which allows remote authenticated users to cause a denial of service via a crafted HTTP request, aka Bug ID CSCuh81011. | 0,9% | — |
| CVE-2026-62825 | CRIT 10.0 | microsoft azure_key_vault Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network. | 0,9% | — |
| CVE-2026-58275 | CRIT 10.0 | microsoft azure_dns Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network. | 0,9% | — |
| CVE-2026-48567 | CRIT 10.0 | microsoft azure_horizondb Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network. | 0,9% | — |
| CVE-2024-38219 | MED 6.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 0,9% | — |
| CVE-2024-26167 | MED 4.3 | microsoft edge Microsoft Edge for Android Spoofing Vulnerability | 0,9% | — |
| CVE-2023-24903 | HIGH 8.1 | microsoft windows_10_1507 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | 0,9% | — |
| CVE-2021-43205 | MED 4.3 | fortinet forticlient An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClient for Linux version 7.0.2 and below, 6.4.7 and below and 6.2.9 and below may allow an unauthenticated attacker to access the confighandler webserver via external | 0,9% | — |
| CVE-2021-39085 | CRIT 9.8 | ibm sterling_b2b_integrator IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, ad | 0,9% | — |
| CVE-2021-1729 | HIGH 7.1 | microsoft windows_10 Windows Update Stack Setup Elevation of Privilege Vulnerability | 0,9% | — |
| CVE-2021-0278 | HIGH 8.8 | juniper junos An Improper Input Validation vulnerability in J-Web of Juniper Networks Junos OS allows a locally authenticated attacker to escalate their privileges to root over the target device. junos:18.3R3-S5 junos:18.4R3-S9 junos:19.1R3-S6 junos:19.3R2-S6 junos:19.3R3-S | 0,9% | — |
| CVE-2017-6664 | HIGH 7.5 | cisco ios_xe A vulnerability in the Autonomic Networking feature of Cisco IOS XE Software could allow an unauthenticated, remote, autonomic node to access the Autonomic Networking infrastructure of an affected system, after the certificate for the autonomic node has been r | 0,9% | — |
| CVE-2009-1556 | LOW 3.5 | cisco wvc54gca img/main.cgi on the Cisco Linksys WVC54GCA wireless video camera with firmware 1.00R22 and 1.00R24 allows remote authenticated users to read arbitrary files in img/ via a filename in the next_file parameter, as demonstrated by reading .htpasswd to obtain the a | 0,9% | — |
| CVE-2026-72950 | HIGH 8.8 | microsoft windows_10_1607 Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine | 0,9% | — |
| CVE-2026-58076 | HIGH 8.8 | apache airflow Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized blob and instantiating it with arguments from the same blob, with no restriction on what could be imported. An operator's | 0,9% | — |
| CVE-2026-24307 | CRIT 9.3 | microsoft 365_copilot Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network. | 0,9% | — |
| CVE-2026-20927 | MED 5.3 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to deny service over a network. | 0,9% | — |
| CVE-2024-38216 | HIGH 8.2 | microsoft azure_stack_hub Azure Stack Hub Elevation of Privilege Vulnerability | 0,9% | — |
| CVE-2024-36896 | CRIT 9.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: USB: core: Fix access violation during port device removal Testing with KASAN and syzkaller revealed a bug in port.c:disable_store(): usb_hub_to_struct_hub() can return NULL if the hub that | 0,9% | — |
| CVE-2023-28507 | CRIT 9.8 | rocketsoftware unidata Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a memory-exhaustion issue, where a decompression routine will allocate increasing amounts of memory until all system me | 0,9% | — |