58.560 CVE seguite
797 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.560 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2022-29062 | MED 6.3 | fortinet fortisoar Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiSOAR before 7.2.1 allows an authenticated attacker to write to the underlying filesystem with nginx permissions via crafted HTTP requests. | 0,8% | — |
| CVE-2021-33751 | HIGH 7.0 | microsoft windows_10 Windows Storage Spaces Controller Elevation of Privilege Vulnerability | 0,8% | — |
| CVE-2021-31952 | HIGH 7.8 | microsoft windows_10 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | 0,8% | — |
| CVE-2021-1351 | MED 6.1 | cisco webex_meetings A vulnerability in the web-based interface of Cisco Webex Meetings could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface of the affected service. The vulnerability is due to ins | 0,8% | — |
| CVE-2020-5879 | HIGH 7.5 | f5 big-ip_application_security_manager On BIG-IP ASM 11.6.1-11.6.5.1, under certain configurations, the BIG-IP system sends data plane traffic to back-end servers unencrypted, even when a Server SSL profile is applied. | 0,8% | — |
| CVE-2020-1272 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior.A locally authenticated attacker could run arbitrary code with elevated system p | 0,8% | — |
| CVE-2020-1204 | HIGH 7.1 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions, aka 'Windows Mobile Device Management Diagnostics Elevation of Privilege Vulnerability'. | 0,8% | — |
| CVE-2020-0900 | MED 5.5 | microsoft visual_studio_2015 An elevation of privilege vulnerability exists when the Visual Studio Extension Installer Service improperly handles file operations, aka 'Visual Studio Extension Installer Service Elevation of Privilege Vulnerability'. | 0,8% | — |
| CVE-2020-0899 | MED 5.5 | microsoft visual_studio_2017 An elevation of privilege vulnerability exists when Microsoft Visual Studio updater service improperly handles file permissions, aka 'Microsoft Visual Studio Elevation of Privilege Vulnerability'. | 0,8% | — |
| CVE-2019-0015 | MED 5.4 | juniper junos A vulnerability in the SRX Series Service Gateway allows deleted dynamic VPN users to establish dynamic VPN connections until the device is rebooted. A deleted dynamic VPN connection should be immediately disallowed from establishing new VPN connections. Due t | 0,8% | — |
| CVE-2026-76186 | CRIT 9.1 | apache apache-airflow-providers-keycloak Apache Airflow Keycloak provider: from Airflow 3.3 the Keycloak auth manager takes a user's identity from the signed Airflow session token but takes the Keycloak access and refresh tokens used for every authorization decision from separate, unauthenticated coo | 0,8% | — |
| CVE-2026-45172 | HIGH 8.8 | paloaltonetworks idira_privileged_session_manager_for_ssh Due to incomplete input validation in Idira Privileged Session Manager for SSH (PSMP) versions prior to 15.0.2, 14.6.3, 14.2.5, and 14.0.6, an authenticated, low-privileged user could potentially execute arbitrary commands on the PSMP host. CyberArk Security B | 0,8% | — |
| CVE-2026-20926 | HIGH 7.5 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network. | 0,8% | — |
| CVE-2026-20919 | HIGH 7.5 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network. | 0,8% | — |
| CVE-2024-50302 | MED 5.5 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since the report buffer is used by all kinds of drivers in various ways, let's zero-initialize it during allocation to make sure that it can't be | 0,8% | |
| CVE-2024-42004 | HIGH 7.1 | microsoft teams A library injection vulnerability exists in Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission bypass. A malicious application could inject a library and | 0,8% | — |
| CVE-2023-52511 | MED 5.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: spi: sun6i: reduce DMA RX transfer width to single byte Through empirical testing it has been determined that sometimes RX SPI transfers with DMA enabled return corrupted data. This is down | 0,8% | — |
| CVE-2023-27987 | CRIT 9.1 | apache linkis In Apache Linkis <=1.3.1, due to the default token generated by Linkis Gateway deployment being too simple, it is easy for attackers to obtain the default token for the attack. Generation rules should add random values. We recommend users upgrade the vers | 0,8% | — |
| CVE-2022-35846 | HIGH 8.1 | fortinet fortitester An improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiTester Telnet port 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated attacker to guess the credentials of an admin user via a | 0,8% | — |
| CVE-2022-20959 | MED 6.1 | cisco identity_services_engine A vulnerability in the External RESTful Services (ERS) API of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This | 0,8% | — |
| CVE-2017-12274 | MED 6.5 | cisco aironet_1562_firmware A vulnerability in Extensible Authentication Protocol (EAP) ingress frame processing for the Cisco Aironet 1560, 2800, and 3800 Series Access Points could allow an unauthenticated, Layer 2 radio frequency (RF) adjacent attacker to cause the Access Point (AP) t | 0,8% | — |
| CVE-2006-3592 | MED 4.6 | cisco unified_callmanager Unspecified vulnerability in the command line interface (CLI) in Cisco Unified CallManager (CUCM) 5.0(1) through 5.0(3a) allows local users to execute arbitrary commands with elevated privileges via unspecified vectors, involving "certain CLI commands," aka bu | 0,8% | — |
| CVE-2026-86465 | MED 6.5 | apache apache-airflow-providers-akeyless Apache Airflow Akeyless provider: the Akeyless secrets backend's team-scope guard can be bypassed with a user-controlled key. In a multi-team deployment, a Dag author scoped to one team can supply a Variable key containing a path separator that causes the back | 0,8% | — |
| CVE-2025-62562 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code locally. | 0,8% | — |
| CVE-2024-43847 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix invalid memory access while processing fragmented packets The monitor ring and the reo reinject ring share the same ring mask index. When the driver receives an interrupt f | 0,8% | — |