58.535 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.535 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2023-33146 | HIGH 7.8 | microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability | 0,8% | — |
| CVE-2023-30268 | CRIT 9.8 | cltphp cltphp CLTPHP <=6.0 is vulnerable to Improper Input Validation. | 0,8% | — |
| CVE-2022-3623 | MED 5.0 | debian debian_linux A vulnerability was found in Linux Kernel. It has been declared as problematic. Affected by this vulnerability is the function follow_page_pte of the file mm/gup.c of the component BPF. The manipulation leads to race condition. The attack can be launched remot | 0,8% | — |
| CVE-2022-20786 | MED 5.4 | cisco unified_communications_manager_im_and_presence_service A vulnerability in the web-based management interface of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerabili | 0,8% | — |
| CVE-2018-5803 | MED 5.5 | debian debian_linux In the Linux Kernel before version 4.15.8, 4.14.25, 4.9.87, 4.4.121, 4.1.51, and 3.2.102, an error in the "_sctp_make_chunk()" function (net/sctp/sm_make_chunk.c) when handling SCTP packets length can be exploited to cause a kernel crash. | 0,8% | — |
| CVE-2018-0215 | MED 6.3 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnera | 0,8% | — |
| CVE-2017-8561 | HIGH 7.0 | microsoft windows_10 Windows kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability due to the way it handles objects in memory, aka "Windows Ke | 0,8% | — |
| CVE-2017-6794 | MED 6.7 | cisco meeting_server A vulnerability in the CLI command-parsing code of Cisco Meeting Server could allow an authenticated, local attacker to perform command injection and escalate their privileges to root. The attacker must first authenticate to the application with valid administ | 0,8% | — |
| CVE-2026-85887 | HIGH 7.7 | microsoft 365_copilot Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose information over a network. | 0,8% | — |
| CVE-2026-69855 | HIGH 7.7 | microsoft azure_copilot Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network. | 0,8% | — |
| CVE-2026-69683 | MED 6.5 | microsoft sharepoint_server Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. | 0,8% | — |
| CVE-2026-69297 | MED 6.5 | microsoft windows_10_1607 Storing passwords in a recoverable format in Windows DHCP Server allows an authorized attacker to disclose information over a network. | 0,8% | — |
| CVE-2026-65806 | MED 6.5 | microsoft azure_cyclecloud Missing authorization in Azure CycleCloud allows an authorized attacker to disclose information over a network. | 0,8% | — |
| CVE-2026-56185 | MED 6.5 | microsoft windows_admin_center Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network. | 0,8% | — |
| CVE-2026-40375 | MED 6.5 | microsoft dynamics_365_business_central_2024 Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network. | 0,8% | — |
| CVE-2025-49214 | HIGH 8.8 | trendmicro trend_micro_endpoint_encryption An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a post-authentication remote code execution on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged c | 0,8% | — |
| CVE-2024-31391 | MED 6.5 | apache solr_operator Insertion of Sensitive Information into Log File vulnerability in the Apache Solr Operator. This issue affects all versions of the Apache Solr Operator from 0.3.0 through 0.8.0. When asked to bootstrap Solr security, the operator will enable basic authentica | 0,8% | — |
| CVE-2023-28505 | HIGH 8.8 | rocketsoftware unidata Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a buffer overflow in an API function, where a string is copied into a caller-provided buffer without checking the lengt | 0,8% | — |
| CVE-2023-27873 | MED 6.5 | ibm aspera_faspex IBM Aspera Faspex 4.4.2 could allow a remote authenticated attacker to obtain sensitive credential information using specially crafted XML input. IBM X-Force ID: 249654. | 0,8% | — |
| CVE-2022-2778 | CRIT 9.8 | octopus octopus_server In affected versions of Octopus Deploy it is possible to bypass rate limiting on login using null bytes. | 0,8% | — |
| CVE-2021-47023 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: marvell: prestera: fix port event handling on init For some reason there might be a crash during ports creation if port events are handling at the same time because fw may send initial | 0,8% | — |
| CVE-2021-38939 | MED 5.3 | ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.3, 7.4, and 7.5 stores potentially sensitive information in log files that could be read by an user with access to creating domains. IBM X-Force ID: 211037. | 0,8% | — |
| CVE-2021-1481 | MED 4.3 | cisco catalyst_sd-wan_manager A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct Cypher query language injection attacks on an affected system. This vulnerability is due to insufficient input | 0,8% | — |
| CVE-2020-6643 | MED 5.4 | fortinet fortiisolator An improper neutralization of input vulnerability in the URL Description in Fortinet FortiIsolator version 1.2.2 allows a remote authenticated attacker to perform a cross site scripting attack (XSS). | 0,8% | — |
| CVE-2020-3579 | MED 6.1 | cisco catalyst_sd-wan_manager A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability exists because the web-base | 0,8% | — |