58.507 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.507 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2025-27018 | MED 6.3 | apache apache-airflow-providers-mysql Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow MySQL Provider. When user triggered a DAG with dump_sql or load_sql functions they could pass a table parameter from a UI, that could cause SQ | 0,9% | — |
| CVE-2025-26866 | HIGH 8.8 | apache hugegraph A remote code execution vulnerability exists where a malicious Raft node can exploit insecure Hessian deserialization within the PD store. The fix enforces IP-based authentication to restrict cluster membership and implements a strict class whitelist to harden | 0,9% | — |
| CVE-2021-26427 | CRIT 9.0 | microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 0,9% | — |
| CVE-2021-0260 | HIGH 7.3 | juniper junos An improper authorization vulnerability in the Simple Network Management Protocol daemon (snmpd) service of Juniper Networks Junos OS leads an unauthenticated attacker being able to perform SNMP read actions, an Exposure of System Data to an Unauthorized Contr | 0,9% | — |
| CVE-2020-4274 | MED 5.4 | ibm qradar_security_information_and_event_manager IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow an authenticated user to access data and perform unauthorized actions due to inadequate permission checks. IBM X-ForceID: 175980. | 0,9% | — |
| CVE-2020-26084 | MED 6.5 | cisco edge_fog_fabric A vulnerability in the REST API of Cisco Edge Fog Fabric could allow an authenticated, remote attacker to access files outside of their authorization sphere on an affected device. The vulnerability is due to incorrect authorization enforcement on an affected s | 0,9% | — |
| CVE-2017-12310 | HIGH 7.5 | cisco spark_hybrid_calendar_service A vulnerability in the auto discovery phase of Cisco Spark Hybrid Calendar Service could allow an unauthenticated, remote attacker to view sensitive information in the unencrypted headers of an HTTP method request. The attacker could use this information to co | 0,9% | — |
| CVE-2025-25006 | MED 5.3 | microsoft exchange_server Improper handling of additional special element in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | 0,9% | — |
| CVE-2024-29060 | MED 6.7 | microsoft visual_studio_2017 Visual Studio Elevation of Privilege Vulnerability | 0,9% | — |
| CVE-2023-52654 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: io_uring/af_unix: disable sending io_uring over sockets File reference cycles have caused lots of problems for io_uring in the past, and it still doesn't work exactly right and races with un | 0,9% | — |
| CVE-2023-44152 | CRIT 9.1 | acronis cyber_protect Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 35979. | 0,9% | — |
| CVE-2023-20219 | HIGH 7.2 | cisco secure_firewall_management_center Multiple vulnerabilities in the web management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. The attacker would need valid device cr | 0,9% | — |
| CVE-2021-43238 | HIGH 7.8 | microsoft windows_10 Windows Remote Access Elevation of Privilege Vulnerability | 0,9% | — |
| CVE-2020-36639 | MED 4.3 | alliedmods amx_mod_x A vulnerability has been found in AlliedModders AMX Mod X on Windows and classified as critical. This vulnerability affects the function cmdVoteMap of the file plugins/adminvote.sma of the component Console Command Handler. The manipulation of the argument amx | 0,9% | — |
| CVE-2020-29605 | MED 4.3 | mantisbt mantisbt An issue was discovered in MantisBT before 2.24.4. Due to insufficient access-level checks, any logged-in user allowed to perform Group Actions can get access to the Summary fields of private Issues via bug_arr[]= in a crafted bug_actiongroup_page.php URL. (Th | 0,9% | — |
| CVE-2020-1998 | MED 5.4 | paloaltonetworks pan-os An improper authorization vulnerability in PAN-OS that mistakenly uses the permissions of local linux users instead of the intended SAML permissions of the account when the username is shared for the purposes of SSO authentication. This can result in authentic | 0,9% | — |
| CVE-2020-1392 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Delivery Optimization service improperly handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1388, CVE-2020-1394, CVE-2020-1395. | 0,9% | — |
| CVE-2006-5990 | MED 4.0 | vmware virtualcenter VMWare VirtualCenter client 2.x before 2.0.1 Patch 1 (Build 33643) and 1.4.x before 1.4.1 Patch 1 (Build 33425), when server certificate verification is enabled, does not verify the server's X.509 certificate when creating an SSL session, which allows remote m | 0,9% | — |
| CVE-2026-49845 | CRIT 9.8 | apache hive SQL injection in Hive Metastore direct SQL partition-name resolution in Apache Hive before 4.2.1 on all platforms allows authenticated users with access to Hive Metastore APIs to read, modify, or affect unintended partition metadata (including statistics updat | 0,9% | — |
| CVE-2026-48345 | HIGH 8.2 | adobe animate Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user intera | 0,9% | — |
| CVE-2025-21756 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: vsock: Keep the binding until socket destruction Preserve sockets bindings; this includes both resulting from an explicit bind() and those implicitly bound through autobind during connect(). | 0,9% | — |
| CVE-2024-43587 | MED 5.9 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 0,9% | — |
| CVE-2023-49619 | LOW 3.1 | apache answer Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Answer. This issue affects Apache Answer: through 1.2.0. Under normal circumstances, a user can only bookmark a question once, and will only i | 0,9% | — |
| CVE-2022-22710 | MED 5.5 | microsoft windows_10 Windows Common Log File System Driver Denial of Service Vulnerability | 0,9% | — |
| CVE-2022-2013 | HIGH 7.5 | octopus octopus_deploy In Octopus Server after version 2022.1.1495 and before 2022.1.2647 if private spaces were enabled via the experimental feature flag all new users would have access to the Script Console within their private space. | 0,9% | — |