EN
58.535 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.535 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più alto In KEV dal, ordina dal più alto
CVE-2022-23292 LOW 3.7 microsoft on-premises_data_gateway Microsoft Power BI Spoofing Vulnerability 0,8% —
CVE-2026-21516 HIGH 8.8 microsoft github_copilot Improper neutralization of special elements used in a command ('command injection') in Github Copilot allows an unauthorized attacker to execute code over a network. 0,8% —
CVE-2025-21394 HIGH 7.8 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 0,8% —
CVE-2025-21392 HIGH 7.8 microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability 0,8% —
CVE-2025-21390 HIGH 7.8 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 0,8% —
CVE-2025-21386 HIGH 7.8 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 0,8% —
CVE-2024-26690 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: stmmac: protect updates of 64-bit statistics counters As explained by a comment in <linux/u64_stats_sync.h>, write side of struct u64_stats_sync must ensure mutual exclusion, or one seq 0,8% —
CVE-2024-0193 HIGH 7.8 linux linux_kernel A use-after-free flaw was found in the netfilter subsystem of the Linux kernel. If the catchall element is garbage-collected when the pipapo set is removed, the element can be deactivated twice. This can cause a use-after-free issue on an NFT_CHAIN object or N 0,8% —
CVE-2023-47706 MED 6.6 ibm security_guardium_key_lifecycle_manager IBM Security Guardium Key Lifecycle Manager 4.3 could allow an authenticated user to upload files of a dangerous file type. IBM X-Force ID: 271341. 0,8% —
CVE-2021-3048 MED 5.9 paloaltonetworks pan-os Certain invalid URL entries contained in an External Dynamic List (EDL) cause the Device Server daemon (devsrvr) to stop responding. This condition causes subsequent commits on the firewall to fail and prevents administrators from performing commits and config 0,8% —
CVE-2020-3548 MED 5.3 cisco email_security_appliance A vulnerability in the Transport Layer Security (TLS) protocol implementation of Cisco&nbsp;AsyncOS software for Cisco&nbsp;Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause high CPU usage on an affected device, resulting 0,8% —
CVE-2020-3311 MED 6.1 cisco secure_firewall_management_center A vulnerability in the web interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerability is due to improper input validation of HTTP request parameter 0,8% —
CVE-2020-3178 MED 6.1 cisco content_security_management_appliance Multiple vulnerabilities in the web-based GUI of Cisco AsyncOS Software for Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerabilities are due to improper in 0,8% —
CVE-2017-6543 HIGH 7.3 tenable appliance Tenable Nessus before 6.10.2 (as used alone or in Tenable Appliance before 4.5.0) was found to contain a flaw that allowed a remote, authenticated attacker to upload a crafted file that could be written to anywhere on the system. This could be used to subseque 0,8% —
CVE-2025-21344 HIGH 7.8 microsoft sharepoint_server Microsoft SharePoint Server Remote Code Execution Vulnerability 0,8% —
CVE-2022-24493 MED 5.5 microsoft windows_10 Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability 0,8% —
CVE-2021-31371 MED 5.3 juniper junos Juniper Networks Junos OS uses the 128.0.0.0/2 subnet for internal communications between the RE and PFEs. It was discovered that packets utilizing these IP addresses may egress an QFX5000 Series switch, leaking configuration information such as heartbeats, ke 0,8% —
CVE-2020-26062 MED 5.3 cisco unified_computing_system A vulnerability in Cisco&nbsp;Integrated Management Controller could allow an unauthenticated, remote attacker to enumerate valid usernames within the vulnerable application. The vulnerability is due to differences in authentication responses sent back from t 0,8% —
CVE-2019-1415 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations.To exploit the vulnerability, an attacker would require unprivileged execution on the victim system, aka 'Windows Ins 0,8% —
CVE-2017-4917 CRIT 9.8 vmware vsphere_data_protection VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x locally stores vCenter Server credentials using reversible encryption. This issue may allow plaintext credentials to be obtained. 0,8% —
CVE-2026-9135 CRIT 9.9 langflow langflow IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulnerability in the Policies component's ToolGuard integration that bypasses the allow_custom_components=false secur 0,8% —
CVE-2026-47303 HIGH 8.8 microsoft .net Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network. 0,8% —
CVE-2024-41159 HIGH 7.1 microsoft onenote A library injection vulnerability exists in Microsoft OneNote 16.83 for macOS. A specially crafted library can leverage OneNote's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger 0,8% —
CVE-2024-30065 MED 5.5 microsoft windows_10_1507 Windows Themes Denial of Service Vulnerability 0,8% —
CVE-2024-20693 HIGH 7.8 microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability 0,8% —