EN
58.568 CVE seguite
797 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.568 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più alto In KEV dal, ordina dal più alto
CVE-2024-56196 MED 6.3 apache traffic_server Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.0 through 10.0.3. Users are recommended to upgrade to version 10.0.4, which fixes the issue. 0,8% —
CVE-2024-56195 MED 6.3 apache traffic_server Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.8, from 10.0.0 through 10.0.3. Users are recommended to upgrade to version 9.2.9 or 10.0.4, which fixes the issue. 0,8% —
CVE-2024-30102 HIGH 7.3 microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability 0,8% —
CVE-2022-48666 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: scsi: core: Fix a use-after-free There are two .exit_cmd_priv implementations. Both implementations use resources associated with the SCSI host. Make sure that these resources are still avai 0,8% —
CVE-2022-30135 HIGH 7.8 microsoft windows_7 Windows Media Center Elevation of Privilege Vulnerability 0,8% —
CVE-2021-47245 HIGH 8.2 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: synproxy: Fix out of bounds when parsing TCP options The TCP option parser in synproxy (synproxy_parse_options) could read one byte out of bounds. When the length is 1, the execut 0,8% —
CVE-2021-38662 MED 5.5 microsoft windows_10 Windows Fast FAT File System Driver Information Disclosure Vulnerability 0,8% —
CVE-2020-1146 MED 6.6 microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Microsoft Store Runtime improperly handles memory.</p> <p>To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially craf 0,8% —
CVE-2020-1130 MED 6.6 microsoft visual_studio <p>An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector improperly handles data operations. An attacker who successfully exploited this vulnerability could run processes in an elevated context.</p> <p>An attacker could exp 0,8% —
CVE-2019-7960 HIGH 7.8 adobe animate_cc Adobe Animate CC versions 19.2.1 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to privilege escalation. 0,8% —
CVE-2017-4926 MED 5.4 vmware vcenter_server VMware vCenter Server (6.5 prior to 6.5 U1) contains a vulnerability that may allow for stored cross-site scripting (XSS). An attacker with VC user privileges can inject malicious java-scripts which will get executed when other VC users access the page. 0,8% —
CVE-2006-5757 LOW 1.2 linux linux_kernel Race condition in the __find_get_block_slow function in the ISO9660 filesystem in Linux 2.6.18 and possibly other versions allows local users to cause a denial of service (infinite loop) by mounting a crafted ISO9660 filesystem containing malformed data struct 0,8% —
CVE-2026-66906 CRIT 9.1 apache camel Relative path traversal vulnerability in Apache Camel Azure Storage Blob component. This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The camel-azure-storage-blob component can download an Az 0,8% —
CVE-2026-50627 CRIT 9.1 apache cxf The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued for one Resource Server to be successfully replayed against a completely different Resource Server, leading to 0,8% —
CVE-2025-50168 HIGH 7.8 microsoft windows_11_22h2 Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. 0,8% —
CVE-2024-49766 MED 5.3 palletsprojects werkzeug Werkzeug is a Web Server Gateway Interface web application library. On Python < 3.11 on Windows, os.path.isabs() does not catch UNC paths like //server/share. Werkzeug's safe_join() relies on this check, and so can produce a path that is not safe, potentially 0,8% —
CVE-2023-0575 HIGH 7.2 yugabyte yugabytedb External Control of Critical State Data, Improper Control of Generation of Code ('Code Injection') vulnerability in YugaByte, Inc. Yugabyte DB on Windows, Linux, MacOS, iOS (DevopsBase.Java:execCommand, TableManager.Java:runCommand modules) allows API Manipula 0,8% —
CVE-2022-43285 HIGH 7.5 f5 njs Nginx NJS v0.7.4 was discovered to contain a segmentation violation in njs_promise_reaction_job. NOTE: the vendor disputes the significance of this report because NJS does not operate on untrusted input. 0,8% —
CVE-2022-35757 HIGH 7.3 microsoft windows_10_1809 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability 0,8% —
CVE-2022-30226 HIGH 7.1 microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability 0,8% —
CVE-2022-22022 HIGH 7.1 microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability 0,8% —
CVE-2021-1702 HIGH 7.8 microsoft windows_10 Windows Remote Procedure Call Runtime Elevation of Privilege Vulnerability 0,8% —
CVE-2021-1693 HIGH 7.8 microsoft windows_10 Windows CSC Service Elevation of Privilege Vulnerability 0,8% —
CVE-2021-1655 HIGH 7.8 microsoft windows_10 Windows CSC Service Elevation of Privilege Vulnerability 0,8% —
CVE-2021-1654 HIGH 7.8 microsoft windows_10 Windows CSC Service Elevation of Privilege Vulnerability 0,8% —