58.518 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.518 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2016-8413 | MED 4.7 | linux linux_kernel An information disclosure vulnerability in the Qualcomm camera driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Produ | 0,9% | — |
| CVE-2015-0596 | MED 6.8 | cisco webex_meetings_server Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuj67163. | 0,9% | — |
| CVE-2004-0554 | LOW 2.1 | avaya converged_communications_server Linux kernel 2.4.x and 2.6.x for x86 allows local users to cause a denial of service (system crash), possibly via an infinite loop that triggers a signal handler with a certain sequence of fsave and frstor instructions, as originally demonstrated using a "cras | 0,9% | — |
| CVE-2026-62916 | CRIT 9.1 | microsoft entra_id Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network. | 0,9% | — |
| CVE-2026-58630 | CRIT 10.0 | microsoft azure_app_service_for_linux Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network. | 0,9% | — |
| CVE-2026-42782 | HIGH 7.2 | apache syncope Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted code reaching a non-sandboxed execution path via the class sta | 0,9% | — |
| CVE-2026-33843 | CRIT 9.1 | microsoft entra_id Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network. | 0,9% | — |
| CVE-2024-30314 | HIGH 7.8 | adobe dreamweaver Dreamweaver Desktop versions 21.3 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. Exploitation of this issue doe | 0,9% | — |
| CVE-2023-51650 | HIGH 7.5 | apache hertzbeat Hertzbeat is an open source, real-time monitoring system. Prior to version 1.4.1, Spring Boot permission configuration issues caused unauthorized access vulnerabilities to three interfaces. This could result in disclosure of sensitive server information. Versi | 0,9% | — |
| CVE-2023-50380 | MED 6.5 | apache ambari XML External Entity injection in apache ambari versions <= 2.7.7, Users are recommended to upgrade to version 2.7.8, which fixes this issue. More Details: Oozie Workflow Scheduler had a vulnerability that allowed for root-level file reading and privilege esc | 0,9% | — |
| CVE-2022-29134 | MED 6.5 | microsoft windows_server Windows Clustered Shared Volume Information Disclosure Vulnerability | 0,9% | — |
| CVE-2022-29127 | MED 4.2 | microsoft windows_10 BitLocker Security Feature Bypass Vulnerability | 0,9% | — |
| CVE-2022-29123 | MED 6.5 | microsoft windows_server Windows Clustered Shared Volume Information Disclosure Vulnerability | 0,9% | — |
| CVE-2022-29122 | MED 6.5 | microsoft windows_server Windows Clustered Shared Volume Information Disclosure Vulnerability | 0,9% | — |
| CVE-2022-26930 | MED 5.5 | microsoft windows_10 Windows Remote Access Connection Manager Information Disclosure Vulnerability | 0,9% | — |
| CVE-2022-25108 | MED 5.5 | foxit pdf_editor Foxit PDF Reader and Editor before 11.2.1 and PhantomPDF before 10.1.7 allow a NULL pointer dereference during PDF parsing because the pointer is used without proper validation. | 0,9% | — |
| CVE-2022-22011 | MED 5.5 | microsoft windows_10 Windows Graphics Component Information Disclosure Vulnerability | 0,9% | — |
| CVE-2021-44168 | LOW 3.3 | fortinet fortios A download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3 may allow a local authenticated attacker to download arbitrary files on the device via specially crafted update packages. | 0,9% | |
| CVE-2021-42299 | MED 5.6 | microsoft surface_pro_3_firmware Microsoft Surface Pro 3 Security Feature Bypass Vulnerability | 0,9% | — |
| CVE-2018-17039 | MED 6.1 | 1234n minicms MiniCMS 1.10, when Internet Explorer is used, allows XSS via a crafted URI because $_SERVER['REQUEST_URI'] is mishandled. | 0,9% | — |
| CVE-2018-0363 | HIGH 8.8 | cisco unified_communications_manager_im_and_presence_service A vulnerability in the web-based management interface of Cisco Unified Communications Manager IM & Presence Service (formerly CUPS) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary acti | 0,9% | — |
| CVE-2017-5074 | HIGH 8.0 | google chrome A use after free in Chrome Apps in Google Chrome prior to 59.0.3071.86 for Windows allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page, related to Bluetooth. | 0,9% | — |
| CVE-2016-4558 | HIGH 7.0 | canonical ubuntu_linux The BPF subsystem in the Linux kernel before 4.5.5 mishandles reference counts, which allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted application on (1) a system with more than 32 Gb of m | 0,9% | — |
| CVE-2026-68763 | HIGH 7.5 | apache tomcat Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocation leak in the HTTP/2 backlog tracking when a stream is reset This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.39 throu | 0,9% | — |
| CVE-2026-65927 | HIGH 7.5 | apache tomcat Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag on the rewrite valves causes rewrite processing to restart at the second rule rather than the first rule. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1. | 0,9% | — |