EN
58.507 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.507 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più alto In KEV dal, ordina dal più alto
CVE-2025-27018 MED 6.3 apache apache-airflow-providers-mysql Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow MySQL Provider. When user triggered a DAG with dump_sql or load_sql functions they could pass a table parameter from a UI, that could cause SQ 0,9% —
CVE-2025-26866 HIGH 8.8 apache hugegraph A remote code execution vulnerability exists where a malicious Raft node can exploit insecure Hessian deserialization within the PD store. The fix enforces IP-based authentication to restrict cluster membership and implements a strict class whitelist to harden 0,9% —
CVE-2021-26427 CRIT 9.0 microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability 0,9% —
CVE-2021-0260 HIGH 7.3 juniper junos An improper authorization vulnerability in the Simple Network Management Protocol daemon (snmpd) service of Juniper Networks Junos OS leads an unauthenticated attacker being able to perform SNMP read actions, an Exposure of System Data to an Unauthorized Contr 0,9% —
CVE-2020-4274 MED 5.4 ibm qradar_security_information_and_event_manager IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow an authenticated user to access data and perform unauthorized actions due to inadequate permission checks. IBM X-ForceID: 175980. 0,9% —
CVE-2020-26084 MED 6.5 cisco edge_fog_fabric A vulnerability in the REST API of Cisco Edge Fog Fabric could allow an authenticated, remote attacker to access files outside of their authorization sphere on an affected device. The vulnerability is due to incorrect authorization enforcement on an affected s 0,9% —
CVE-2017-12310 HIGH 7.5 cisco spark_hybrid_calendar_service A vulnerability in the auto discovery phase of Cisco Spark Hybrid Calendar Service could allow an unauthenticated, remote attacker to view sensitive information in the unencrypted headers of an HTTP method request. The attacker could use this information to co 0,9% —
CVE-2025-25006 MED 5.3 microsoft exchange_server Improper handling of additional special element in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. 0,9% —
CVE-2024-29060 MED 6.7 microsoft visual_studio_2017 Visual Studio Elevation of Privilege Vulnerability 0,9% —
CVE-2023-52654 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: io_uring/af_unix: disable sending io_uring over sockets File reference cycles have caused lots of problems for io_uring in the past, and it still doesn't work exactly right and races with un 0,9% —
CVE-2023-44152 CRIT 9.1 acronis cyber_protect Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 35979. 0,9% —
CVE-2023-20219 HIGH 7.2 cisco secure_firewall_management_center Multiple vulnerabilities in the web management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. The attacker would need valid device cr 0,9% —
CVE-2021-43238 HIGH 7.8 microsoft windows_10 Windows Remote Access Elevation of Privilege Vulnerability 0,9% —
CVE-2020-36639 MED 4.3 alliedmods amx_mod_x A vulnerability has been found in AlliedModders AMX Mod X on Windows and classified as critical. This vulnerability affects the function cmdVoteMap of the file plugins/adminvote.sma of the component Console Command Handler. The manipulation of the argument amx 0,9% —
CVE-2020-29605 MED 4.3 mantisbt mantisbt An issue was discovered in MantisBT before 2.24.4. Due to insufficient access-level checks, any logged-in user allowed to perform Group Actions can get access to the Summary fields of private Issues via bug_arr[]= in a crafted bug_actiongroup_page.php URL. (Th 0,9% —
CVE-2020-1998 MED 5.4 paloaltonetworks pan-os An improper authorization vulnerability in PAN-OS that mistakenly uses the permissions of local linux users instead of the intended SAML permissions of the account when the username is shared for the purposes of SSO authentication. This can result in authentic 0,9% —
CVE-2020-1392 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Delivery Optimization service improperly handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1388, CVE-2020-1394, CVE-2020-1395. 0,9% —
CVE-2006-5990 MED 4.0 vmware virtualcenter VMWare VirtualCenter client 2.x before 2.0.1 Patch 1 (Build 33643) and 1.4.x before 1.4.1 Patch 1 (Build 33425), when server certificate verification is enabled, does not verify the server's X.509 certificate when creating an SSL session, which allows remote m 0,9% —
CVE-2026-49845 CRIT 9.8 apache hive SQL injection in Hive Metastore direct SQL partition-name resolution in Apache Hive before 4.2.1 on all platforms allows authenticated users with access to Hive Metastore APIs to read, modify, or affect unintended partition metadata (including statistics updat 0,9% —
CVE-2026-48345 HIGH 8.2 adobe animate Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user intera 0,9% —
CVE-2025-21756 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: vsock: Keep the binding until socket destruction Preserve sockets bindings; this includes both resulting from an explicit bind() and those implicitly bound through autobind during connect(). 0,9% —
CVE-2024-43587 MED 5.9 microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability 0,9% —
CVE-2023-49619 LOW 3.1 apache answer Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Answer. This issue affects Apache Answer: through 1.2.0. Under normal circumstances, a user can only bookmark a question once, and will only i 0,9% —
CVE-2022-22710 MED 5.5 microsoft windows_10 Windows Common Log File System Driver Denial of Service Vulnerability 0,9% —
CVE-2022-2013 HIGH 7.5 octopus octopus_deploy In Octopus Server after version 2022.1.1495 and before 2022.1.2647 if private spaces were enabled via the experimental feature flag all new users would have access to the Script Console within their private space. 0,9% —