EN
58.560 CVE seguite
797 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.560 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più alto In KEV dal, ordina dal più alto
CVE-2026-33844 CRIT 9.0 microsoft azure_managed_instance_for_apache_cassandra Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network. 0,8% —
CVE-2025-25069 MED 6.5 apache kvrocks A Cross-Protocol Scripting vulnerability is found in Apache Kvrocks. Since Kvrocks didn't detect if "Host:" or "POST" appears in RESP requests, a valid HTTP request can also be sent to Kvrocks as a valid RESP request and trigger some database operations, whi 0,8% —
CVE-2024-43542 MED 6.5 microsoft windows_10_1809 Windows Mobile Broadband Driver Denial of Service Vulnerability 0,8% —
CVE-2024-43540 MED 6.5 microsoft windows_10_1809 Windows Mobile Broadband Driver Denial of Service Vulnerability 0,8% —
CVE-2024-43538 MED 6.5 microsoft windows_10_1809 Windows Mobile Broadband Driver Denial of Service Vulnerability 0,8% —
CVE-2024-43537 MED 6.5 microsoft windows_10_1809 Windows Mobile Broadband Driver Denial of Service Vulnerability 0,8% —
CVE-2023-21749 HIGH 7.8 microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability 0,8% —
CVE-2022-44692 HIGH 7.8 microsoft 365_apps Microsoft Office Graphics Remote Code Execution Vulnerability 0,8% —
CVE-2022-33631 HIGH 7.3 microsoft 365_apps Microsoft Excel Security Feature Bypass Vulnerability 0,8% —
CVE-2021-28309 MED 5.5 microsoft windows_10 Windows Kernel Information Disclosure Vulnerability 0,8% —
CVE-2021-27093 MED 5.5 microsoft windows_10 Windows Kernel Information Disclosure Vulnerability 0,8% —
CVE-2021-26417 MED 5.5 microsoft windows_10 Windows Overlay Filter Information Disclosure Vulnerability 0,8% —
CVE-2020-3267 HIGH 7.1 cisco unified_contact_center_express A vulnerability in the API subsystem of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to change the availability state of any agent. The vulnerability is due to insufficient authorization enforcement on an aff 0,8% —
CVE-2020-16922 MED 5.3 microsoft windows_10 <p>A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could bypass security features and load improperly signed files.</p> <p>In an attack scenario, an attacker could by 0,8% —
CVE-2013-6698 MED 4.3 cisco wireless_lan_controller The web interface on Cisco Wireless LAN Controller (WLC) devices does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "c 0,8% —
CVE-2026-44615 MED 6.5 apache zeppelin Path traversal vulnerability in Apache Zeppelin. When FileSystemNotebookRepo is configured, an authenticated attacker with permission to rename a note, or access to folder operations, could supply traversal segments in note or folder paths.                   Z 0,8% —
CVE-2025-59200 HIGH 7.7 microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Data Sharing Service Client allows an unauthorized attacker to perform spoofing locally. 0,8% —
CVE-2024-24860 MED 4.6 linux linux_kernel A race condition was found in the Linux kernel's bluetooth device driver in {min,max}_key_size_set() function. This can result in a null pointer dereference issue, possibly leading to a kernel panic or denial of service issue. 0,8% —
CVE-2024-20254 CRIT 9.6 cisco expressway Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to conduct cross-site request forgery (CSRF) attacks that perform arbitrary actions on an affected devic 0,8% —
CVE-2023-35373 MED 5.3 microsoft mono Mono Authenticode Validation Spoofing Vulnerability 0,8% —
CVE-2021-28972 MED 6.7 fedoraproject fedora In drivers/pci/hotplug/rpadlpar_sysfs.c in the Linux kernel through 5.11.8, the RPA PCI Hotplug driver has a user-tolerable buffer overflow when writing a new device name to the driver from userspace, allowing userspace to write data to the kernel stack frame 0,8% —
CVE-2021-1440 MED 6.8 cisco ios_xr A vulnerability in the implementation of the Resource Public Key Infrastructure (RPKI) feature of Cisco&nbsp;IOS XR Software could allow an unauthenticated, remote attacker to cause the Border Gateway Protocol (BGP) process to crash, resulting in a denial of s 0,8% —
CVE-2020-3522 MED 6.3 cisco data_center_network_manager A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to bypass authorization on an affected device and access sensitive information that is related to the devic 0,8% —
CVE-2019-7221 HIGH 7.8 canonical ubuntu_linux The KVM implementation in the Linux kernel through 4.20.5 has a Use-after-Free. 0,8% —
CVE-2019-6627 MED 5.9 f5 ssl_orchestrator On F5 SSL Orchestrator 14.1.0-14.1.0.5, on rare occasions, specific to a certain race condition, TMM may restart when SSL Forward Proxy enforces the bypass action for an SSL Orchestrator transparent virtual server with SNAT enabled. 0,8% —