EN
58.559 CVE seguite
797 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.559 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più alto In KEV dal, ordina dal più alto
CVE-2026-48207 CRIT 9.8 apache fory Deserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass documented DeserializationPolicy validation hooks during reduce-state restoration and global-name resolution. An application is vulnerable if it deserializes attack 0,8% —
CVE-2026-41635 CRIT 9.8 apache mina Apache MINA's AbstractIoBuffer.resolveClass() contains two branches, one of them (for static classes or primitive types) does not check the class at all, bypassing the classname allowlist and allowing arbitrary code to be executed. The fix checks if the cl 0,8% —
CVE-2025-49674 HIGH 8.8 microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. 0,8% —
CVE-2024-56128 MED 5.3 apache kafka Incorrect Implementation of Authentication Algorithm in Apache Kafka's SCRAM implementation. Issue Summary: Apache Kafka's implementation of the Salted Challenge Response Authentication Mechanism (SCRAM) did not fully adhere to the requirements of RFC 5802 [1 0,8% —
CVE-2024-33899 HIGH 7.1 rarlab winrar RARLAB WinRAR before 7.00, on Linux and UNIX platforms, allows attackers to spoof the screen output, or cause a denial of service, via ANSI escape sequences. 0,8% —
CVE-2024-30371 HIGH 7.8 foxit pdf_editor Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that 0,8% —
CVE-2024-30367 HIGH 7.8 foxit pdf_editor Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that 0,8% —
CVE-2024-30365 HIGH 7.8 foxit pdf_editor Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that 0,8% —
CVE-2023-28304 HIGH 7.8 microsoft odbc Microsoft ODBC and OLE DB Remote Code Execution Vulnerability 0,8% —
CVE-2023-28284 MED 4.3 microsoft edge Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability 0,8% —
CVE-2022-31708 MED 4.9 vmware vrealize_operations vRealize Operations (vROps) contains a broken access control vulnerability. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 4.4. 0,8% —
CVE-2021-43244 MED 6.5 microsoft windows_10 Windows Kernel Information Disclosure Vulnerability 0,8% —
CVE-2021-1130 MED 4.8 cisco catalyst_center A vulnerability in the web-based management interface of Cisco DNA Center software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. The vulnerability exists beca 0,8% —
CVE-2020-0786 HIGH 7.1 microsoft windows_10 A denial of service vulnerability exists when the Windows Tile Object Service improperly handles hard links, aka 'Windows Tile Object Service Denial of Service Vulnerability'. 0,8% —
CVE-2019-13631 MED 6.8 linux linux_kernel In parse_hid_report_descriptor in drivers/input/tablet/gtco.c in the Linux kernel through 5.2.1, a malicious USB device can send an HID report that triggers an out-of-bounds write during generation of debugging messages. 0,8% —
CVE-2018-0221 MED 6.7 cisco identity_services_engine A vulnerability in specific CLI commands for the Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to perform command injection to the underlying operating system or cause a hang or disconnect of the user session. The attacker n 0,8% —
CVE-2014-9326 MED 4.3 f5 big-ip_access_policy_manager The automatic signature update functionality in the (1) Phone Home feature in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, GTM, and Link Controller 11.5.0 through 11.6.0, ASM 10.0.0 through 11.6.0, and PEM 11.3.0 through 11.6.0 and the (2) Call Home feature in ASM 0,8% —
CVE-2012-4084 MED 6.8 cisco unified_computing_system Cross-site request forgery (CSRF) vulnerability in the web-management interface in the fabric interconnect (FI) component in Cisco Unified Computing System (UCS) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCtg20755. 0,8% —
CVE-2025-53792 CRIT 9.1 microsoft azure_portal Azure Portal Elevation of Privilege Vulnerability 0,8% —
CVE-2025-27729 HIGH 7.8 microsoft windows_10_21h2 Use after free in Windows Shell allows an unauthorized attacker to execute code locally. 0,8% —
CVE-2025-20234 MED 5.3 cisco secure_endpoint A vulnerability in Universal Disk Format (UDF) processing of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a memory overread during UDF file scanning. 0,8% —
CVE-2024-20259 HIGH 8.6 cisco ios_xe A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to a crafte 0,8% —
CVE-2022-34711 HIGH 7.8 microsoft windows_10 Windows Defender Credential Guard Elevation of Privilege Vulnerability 0,8% —
CVE-2022-28708 MED 5.9 f5 big-ip_access_policy_manager On F5 BIG-IP 16.1.x versions prior to 16.1.2.2 and 15.1.x versions prior to 15.1.5.1, when a BIG-IP DNS resolver-enabled, HTTP-Explicit or SOCKS profile is configured on a virtual server, an undisclosed DNS response can cause the Traffic Management Microkernel 0,8% —
CVE-2022-28049 MED 5.5 f5 njs NGINX NJS 0.7.2 was discovered to contain a NULL pointer dereference via the component njs_vmcode_array at /src/njs_vmcode.c. 0,8% —