58.559 CVE seguite
797 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.559 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-48207 | CRIT 9.8 | apache fory Deserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass documented DeserializationPolicy validation hooks during reduce-state restoration and global-name resolution. An application is vulnerable if it deserializes attack | 0,8% | — |
| CVE-2026-41635 | CRIT 9.8 | apache mina Apache MINA's AbstractIoBuffer.resolveClass() contains two branches, one of them (for static classes or primitive types) does not check the class at all, bypassing the classname allowlist and allowing arbitrary code to be executed. The fix checks if the cl | 0,8% | — |
| CVE-2025-49674 | HIGH 8.8 | microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | 0,8% | — |
| CVE-2024-56128 | MED 5.3 | apache kafka Incorrect Implementation of Authentication Algorithm in Apache Kafka's SCRAM implementation. Issue Summary: Apache Kafka's implementation of the Salted Challenge Response Authentication Mechanism (SCRAM) did not fully adhere to the requirements of RFC 5802 [1 | 0,8% | — |
| CVE-2024-33899 | HIGH 7.1 | rarlab winrar RARLAB WinRAR before 7.00, on Linux and UNIX platforms, allows attackers to spoof the screen output, or cause a denial of service, via ANSI escape sequences. | 0,8% | — |
| CVE-2024-30371 | HIGH 7.8 | foxit pdf_editor Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that | 0,8% | — |
| CVE-2024-30367 | HIGH 7.8 | foxit pdf_editor Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that | 0,8% | — |
| CVE-2024-30365 | HIGH 7.8 | foxit pdf_editor Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that | 0,8% | — |
| CVE-2023-28304 | HIGH 7.8 | microsoft odbc Microsoft ODBC and OLE DB Remote Code Execution Vulnerability | 0,8% | — |
| CVE-2023-28284 | MED 4.3 | microsoft edge Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | 0,8% | — |
| CVE-2022-31708 | MED 4.9 | vmware vrealize_operations vRealize Operations (vROps) contains a broken access control vulnerability. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 4.4. | 0,8% | — |
| CVE-2021-43244 | MED 6.5 | microsoft windows_10 Windows Kernel Information Disclosure Vulnerability | 0,8% | — |
| CVE-2021-1130 | MED 4.8 | cisco catalyst_center A vulnerability in the web-based management interface of Cisco DNA Center software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. The vulnerability exists beca | 0,8% | — |
| CVE-2020-0786 | HIGH 7.1 | microsoft windows_10 A denial of service vulnerability exists when the Windows Tile Object Service improperly handles hard links, aka 'Windows Tile Object Service Denial of Service Vulnerability'. | 0,8% | — |
| CVE-2019-13631 | MED 6.8 | linux linux_kernel In parse_hid_report_descriptor in drivers/input/tablet/gtco.c in the Linux kernel through 5.2.1, a malicious USB device can send an HID report that triggers an out-of-bounds write during generation of debugging messages. | 0,8% | — |
| CVE-2018-0221 | MED 6.7 | cisco identity_services_engine A vulnerability in specific CLI commands for the Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to perform command injection to the underlying operating system or cause a hang or disconnect of the user session. The attacker n | 0,8% | — |
| CVE-2014-9326 | MED 4.3 | f5 big-ip_access_policy_manager The automatic signature update functionality in the (1) Phone Home feature in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, GTM, and Link Controller 11.5.0 through 11.6.0, ASM 10.0.0 through 11.6.0, and PEM 11.3.0 through 11.6.0 and the (2) Call Home feature in ASM | 0,8% | — |
| CVE-2012-4084 | MED 6.8 | cisco unified_computing_system Cross-site request forgery (CSRF) vulnerability in the web-management interface in the fabric interconnect (FI) component in Cisco Unified Computing System (UCS) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCtg20755. | 0,8% | — |
| CVE-2025-53792 | CRIT 9.1 | microsoft azure_portal Azure Portal Elevation of Privilege Vulnerability | 0,8% | — |
| CVE-2025-27729 | HIGH 7.8 | microsoft windows_10_21h2 Use after free in Windows Shell allows an unauthorized attacker to execute code locally. | 0,8% | — |
| CVE-2025-20234 | MED 5.3 | cisco secure_endpoint A vulnerability in Universal Disk Format (UDF) processing of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a memory overread during UDF file scanning. | 0,8% | — |
| CVE-2024-20259 | HIGH 8.6 | cisco ios_xe A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to a crafte | 0,8% | — |
| CVE-2022-34711 | HIGH 7.8 | microsoft windows_10 Windows Defender Credential Guard Elevation of Privilege Vulnerability | 0,8% | — |
| CVE-2022-28708 | MED 5.9 | f5 big-ip_access_policy_manager On F5 BIG-IP 16.1.x versions prior to 16.1.2.2 and 15.1.x versions prior to 15.1.5.1, when a BIG-IP DNS resolver-enabled, HTTP-Explicit or SOCKS profile is configured on a virtual server, an undisclosed DNS response can cause the Traffic Management Microkernel | 0,8% | — |
| CVE-2022-28049 | MED 5.5 | f5 njs NGINX NJS 0.7.2 was discovered to contain a NULL pointer dereference via the component njs_vmcode_array at /src/njs_vmcode.c. | 0,8% | — |