58.560 CVE seguite
797 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.560 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2025-4615 | HIGH 7.2 | paloaltonetworks pan-os An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and execute arbitrary commands. The security risk posed by this issu | 0,8% | — |
| CVE-2024-38198 | HIGH 7.5 | microsoft windows_10_1507 Windows Print Spooler Elevation of Privilege Vulnerability | 0,8% | — |
| CVE-2024-38056 | MED 5.5 | microsoft windows_10_1507 Microsoft Windows Codecs Library Information Disclosure Vulnerability | 0,8% | — |
| CVE-2024-38055 | MED 5.5 | microsoft windows_10_1507 Microsoft Windows Codecs Library Information Disclosure Vulnerability | 0,8% | — |
| CVE-2023-44158 | HIGH 7.5 | acronis cyber_protect Sensitive information disclosure due to insufficient token field masking. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979. | 0,8% | — |
| CVE-2022-44687 | HIGH 7.8 | microsoft raw_image_extension Raw Image Extension Remote Code Execution Vulnerability | 0,8% | — |
| CVE-2022-44668 | HIGH 7.8 | microsoft windows_10 Windows Media Remote Code Execution Vulnerability | 0,8% | — |
| CVE-2022-44667 | HIGH 7.8 | microsoft windows_10 Windows Media Remote Code Execution Vulnerability | 0,8% | — |
| CVE-2022-41064 | MED 5.8 | microsoft .net_framework .NET Framework Information Disclosure Vulnerability | 0,8% | — |
| CVE-2022-23263 | HIGH 7.7 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 0,8% | — |
| CVE-2021-47013 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net:emac/emac-mac: Fix a use after free in emac_mac_tx_buf_send In emac_mac_tx_buf_send, it calls emac_tx_fill_tpd(..,skb,..). If some error happens in emac_tx_fill_tpd(), the skb will be fr | 0,8% | — |
| CVE-2021-3045 | MED 4.9 | paloaltonetworks pan-os An OS command argument injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator to read any arbitrary file from the file system. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.19; PAN-OS 9.0 | 0,8% | — |
| CVE-2021-26890 | HIGH 7.8 | microsoft windows_10 Application Virtualization Remote Code Execution Vulnerability | 0,8% | — |
| CVE-2021-26442 | HIGH 7.0 | microsoft windows_10 Windows HTTP.sys Elevation of Privilege Vulnerability | 0,8% | — |
| CVE-2020-3384 | HIGH 8.2 | cisco data_center_network_manager A vulnerability in specific REST API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to inject arbitrary commands on the underlying operating system with the privileges of the logged-in user. The vulnerabilit | 0,8% | — |
| CVE-2020-1660 | HIGH 8.3 | juniper junos When DNS filtering is enabled on Juniper Networks Junos MX Series with one of the following cards MS-PIC, MS-MIC or MS-MPC, an incoming stream of packets processed by the Multiservices PIC Management Daemon (mspmand) process, responsible for managing "URL Filt | 0,8% | — |
| CVE-2018-0208 | MED 5.4 | cisco email_encryption A vulnerability in the web-based management interface of the (cloud based) Cisco Registered Envelope Service could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of th | 0,8% | — |
| CVE-2026-87701 | CRIT 9.6 | microsoft azure_cosmos_db Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a network. | 0,8% | — |
| CVE-2026-62764 | MED 6.5 | apache accumulo Improper Handling of Insufficient Privileges vulnerability in Apache Accumulo. An authenticated, but low-privileged user without system permissions may issue a remote command to gracefully shutdown system components (compaction-coordinator, compactor, gc, mana | 0,8% | — |
| CVE-2026-34538 | MED 6.5 | apache airflow Apache Airflow versions 3.0.0 through 3.1.8 DagRun wait endpoint returns XCom result values even to users who only have DAG Run read permissions, such as the Viewer role.This behavior conflicts with the FAB RBAC model, which treats XCom as a separate protected | 0,8% | — |
| CVE-2026-34020 | HIGH 7.5 | apache openmeetings Use of GET Request Method With Sensitive Query Strings vulnerability in Apache OpenMeetings. The REST login endpoint uses HTTP GET method with username and password passed as query parameters. Please check references regarding possible impact This issue aff | 0,8% | — |
| CVE-2026-28811 | HIGH 7.5 | apache jspwiki Debug Messages Revealing Unnecessary Information in Apache JSPWiki up to 2.12.3. Users are recommended to upgrade to version 2.12.4, which fixes this issue. | 0,8% | — |
| CVE-2024-49996 | CRIT 9.4 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: cifs: Fix buffer overflow when parsing NFS reparse points ReparseDataLength is sum of the InodeType size and DataBuffer size. So to get DataBuffer size it is needed to subtract InodeType's s | 0,8% | — |
| CVE-2023-20034 | HIGH 7.5 | cisco sd-wan Vulnerability in the Elasticsearch database used in the of Cisco SD-WAN vManage software could allow an unauthenticated, remote attacker to access the Elasticsearch configuration database of an affected device with the privileges of the elasticsearch user. | 0,8% | — |
| CVE-2022-45412 | HIGH 8.8 | mozilla firefox When resolving a symlink such as <code>file:///proc/self/fd/1</code>, an error message may be produced where the symlink was resolved to a string containing unitialized memory in the buffer. <br>*This bug only affects Thunderbird on Unix-based operated systems | 0,8% | — |