EN
58.560 CVE seguite
797 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.560 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più alto In KEV dal, ordina dal più alto
CVE-2024-41145 HIGH 7.1 microsoft teams A library injection vulnerability exists in the WebView.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission bypass. A malicious applicati 0,8% —
CVE-2024-30362 HIGH 7.8 foxit pdf_editor Foxit PDF Reader PDF File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability 0,8% —
CVE-2022-20867 MED 5.4 cisco asyncos A vulnerability in web-based management interface of the of Cisco Email Security Appliance and Cisco Secure Email and Web Manager could allow an authenticated, remote attacker to conduct SQL injection attacks as root on an affected system. The attacker must ha 0,8% —
CVE-2020-27725 MED 4.3 f5 big-ip_domain_name_system In version 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2 of BIG-IP DNS, GTM, and Link Controller, zxfrd leaks memory when listing DNS zones. Zones can be listed via TMSH, iControl or SNMP; only users with access to those 0,8% —
CVE-2026-71559 HIGH 7.5 apache fory Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying crafted data containing malformed type metadata, which triggers an uncaught panic. This issue affects Apache F 0,8% —
CVE-2026-26120 MED 6.5 microsoft bing Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to perform tampering over a network. 0,8% —
CVE-2024-41048 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: skmsg: Skip zero length skb in sk_msg_recvmsg When running BPF selftests (./test_progs -t sockmap_basic) on a Loongarch platform, the following kernel panic occurs: [...] Oops[#1]: CP 0,8% —
CVE-2023-21567 MED 5.6 microsoft visual_studio_2017 Visual Studio Denial of Service Vulnerability 0,8% —
CVE-2022-31246 MED 5.5 electrum electrum paymentrequest.py in Electrum before 4.2.2 allows a file:// URL in the r parameter of a payment request (e.g., within QR code data). On Windows, this can lead to capture of credentials over SMB. On Linux and UNIX, it can lead to a denial of service by specifyi 0,8% —
CVE-2022-23447 HIGH 7.5 fortinet fortiextender_firmware An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiExtender management interface 7.0.0 through 7.0.3, 4.2.0 through 4.2.4, 4.1.1 through 4.1.8, 4.0.0 through 4.0.2, 3.3.0 through 3.3.2, 3.2.1 throu 0,8% —
CVE-2021-1703 HIGH 7.8 microsoft windows_10 Windows Event Logging Service Elevation of Privilege Vulnerability 0,8% —
CVE-2021-1650 HIGH 7.8 microsoft windows_10 Windows Runtime C++ Template Library Elevation of Privilege Vulnerability 0,8% —
CVE-2017-7374 HIGH 7.8 linux linux_kernel Use-after-free vulnerability in fs/crypto/ in the Linux kernel before 4.10.7 allows local users to cause a denial of service (NULL pointer dereference) or possibly gain privileges by revoking keyring keys being used for ext4, f2fs, or ubifs encryption, causing 0,8% —
CVE-2026-70340 HIGH 8.1 microsoft azure_cyclecloud Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network. 0,8% —
CVE-2026-69555 CRIT 10.0 microsoft azure_arc Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network. 0,8% —
CVE-2026-69502 CRIT 10.0 microsoft azure_sql_database Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. 0,8% —
CVE-2026-65667 CRIT 10.0 microsoft teams Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network. 0,8% —
CVE-2026-64878 CRIT 9.9 tenable security_center Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resulting in remote code execution as a low-privileged OS user via the Analysis REST endpoint. 0,8% —
CVE-2026-63508 CRIT 10.0 microsoft planetary_computer Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network. 0,8% —
CVE-2026-41613 HIGH 8.8 microsoft visual_studio_code Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. 0,8% —
CVE-2026-41103 CRIT 9.1 microsoft confluence_saml_sso Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an unauthorized attacker to elevate privileges over a network. 0,8% —
CVE-2024-45626 MED 6.5 apache james_server Apache James server JMAP HTML to text plain implementation in versions below 3.8.2 and 3.7.6 is subject to unbounded memory consumption that can result in a denial of service. Users are recommended to upgrade to version 3.7.6 and 3.8.2, which fix this issue. 0,8% —
CVE-2023-37931 HIGH 8.8 fortinet fortivoice An improper neutralization of special elements used in an sql command ('sql injection') vulnerability [CWE-88] in FortiVoice Entreprise version 7.0.0 through 7.0.1 and before 6.4.8 allows an authenticated attacker to perform a blind sql injection attack via se 0,8% —
CVE-2022-41051 HIGH 7.8 microsoft azure_rtos_guix_studio Azure RTOS GUIX Studio Remote Code Execution Vulnerability 0,8% —
CVE-2022-30594 HIGH 7.8 debian debian_linux The Linux kernel before 5.17.2 mishandles seccomp permissions. The PTRACE_SEIZE code path allows attackers to bypass intended restrictions on setting the PT_SUSPEND_SECCOMP flag. 0,8% —