58.535 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.535 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2022-23292 | LOW 3.7 | microsoft on-premises_data_gateway Microsoft Power BI Spoofing Vulnerability | 0,8% | — |
| CVE-2026-21516 | HIGH 8.8 | microsoft github_copilot Improper neutralization of special elements used in a command ('command injection') in Github Copilot allows an unauthorized attacker to execute code over a network. | 0,8% | — |
| CVE-2025-21394 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 0,8% | — |
| CVE-2025-21392 | HIGH 7.8 | microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability | 0,8% | — |
| CVE-2025-21390 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 0,8% | — |
| CVE-2025-21386 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 0,8% | — |
| CVE-2024-26690 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: stmmac: protect updates of 64-bit statistics counters As explained by a comment in <linux/u64_stats_sync.h>, write side of struct u64_stats_sync must ensure mutual exclusion, or one seq | 0,8% | — |
| CVE-2024-0193 | HIGH 7.8 | linux linux_kernel A use-after-free flaw was found in the netfilter subsystem of the Linux kernel. If the catchall element is garbage-collected when the pipapo set is removed, the element can be deactivated twice. This can cause a use-after-free issue on an NFT_CHAIN object or N | 0,8% | — |
| CVE-2023-47706 | MED 6.6 | ibm security_guardium_key_lifecycle_manager IBM Security Guardium Key Lifecycle Manager 4.3 could allow an authenticated user to upload files of a dangerous file type. IBM X-Force ID: 271341. | 0,8% | — |
| CVE-2021-3048 | MED 5.9 | paloaltonetworks pan-os Certain invalid URL entries contained in an External Dynamic List (EDL) cause the Device Server daemon (devsrvr) to stop responding. This condition causes subsequent commits on the firewall to fail and prevents administrators from performing commits and config | 0,8% | — |
| CVE-2020-3548 | MED 5.3 | cisco email_security_appliance A vulnerability in the Transport Layer Security (TLS) protocol implementation of Cisco AsyncOS software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause high CPU usage on an affected device, resulting | 0,8% | — |
| CVE-2020-3311 | MED 6.1 | cisco secure_firewall_management_center A vulnerability in the web interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerability is due to improper input validation of HTTP request parameter | 0,8% | — |
| CVE-2020-3178 | MED 6.1 | cisco content_security_management_appliance Multiple vulnerabilities in the web-based GUI of Cisco AsyncOS Software for Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerabilities are due to improper in | 0,8% | — |
| CVE-2017-6543 | HIGH 7.3 | tenable appliance Tenable Nessus before 6.10.2 (as used alone or in Tenable Appliance before 4.5.0) was found to contain a flaw that allowed a remote, authenticated attacker to upload a crafted file that could be written to anywhere on the system. This could be used to subseque | 0,8% | — |
| CVE-2025-21344 | HIGH 7.8 | microsoft sharepoint_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 0,8% | — |
| CVE-2022-24493 | MED 5.5 | microsoft windows_10 Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability | 0,8% | — |
| CVE-2021-31371 | MED 5.3 | juniper junos Juniper Networks Junos OS uses the 128.0.0.0/2 subnet for internal communications between the RE and PFEs. It was discovered that packets utilizing these IP addresses may egress an QFX5000 Series switch, leaking configuration information such as heartbeats, ke | 0,8% | — |
| CVE-2020-26062 | MED 5.3 | cisco unified_computing_system A vulnerability in Cisco Integrated Management Controller could allow an unauthenticated, remote attacker to enumerate valid usernames within the vulnerable application. The vulnerability is due to differences in authentication responses sent back from t | 0,8% | — |
| CVE-2019-1415 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations.To exploit the vulnerability, an attacker would require unprivileged execution on the victim system, aka 'Windows Ins | 0,8% | — |
| CVE-2017-4917 | CRIT 9.8 | vmware vsphere_data_protection VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x locally stores vCenter Server credentials using reversible encryption. This issue may allow plaintext credentials to be obtained. | 0,8% | — |
| CVE-2026-9135 | CRIT 9.9 | langflow langflow IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulnerability in the Policies component's ToolGuard integration that bypasses the allow_custom_components=false secur | 0,8% | — |
| CVE-2026-47303 | HIGH 8.8 | microsoft .net Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network. | 0,8% | — |
| CVE-2024-41159 | HIGH 7.1 | microsoft onenote A library injection vulnerability exists in Microsoft OneNote 16.83 for macOS. A specially crafted library can leverage OneNote's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger | 0,8% | — |
| CVE-2024-30065 | MED 5.5 | microsoft windows_10_1507 Windows Themes Denial of Service Vulnerability | 0,8% | — |
| CVE-2024-20693 | HIGH 7.8 | microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability | 0,8% | — |