58.568 CVE seguite
797 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.568 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2021-1653 | HIGH 7.8 | microsoft windows_10 Windows CSC Service Elevation of Privilege Vulnerability | 0,8% | — |
| CVE-2021-1652 | HIGH 7.8 | microsoft windows_10 Windows CSC Service Elevation of Privilege Vulnerability | 0,8% | — |
| CVE-2021-1649 | HIGH 7.8 | microsoft windows_10 Active Template Library Elevation of Privilege Vulnerability | 0,8% | — |
| CVE-2021-1646 | MED 6.6 | microsoft windows_10 Windows WLAN Service Elevation of Privilege Vulnerability | 0,8% | — |
| CVE-2019-12400 | MED 5.5 | apache santuario_xml_security_for_java In version 2.0.3 Apache Santuario XML Security for Java, a caching mechanism was introduced to speed up creating new XML documents using a static pool of DocumentBuilders. However, if some untrusted code can register a malicious implementation with the thread | 0,8% | — |
| CVE-2001-0316 | MED 4.6 | linux linux_kernel Linux kernel 2.4 and 2.2 allows local users to read kernel memory and possibly gain privileges via a negative argument to the sysctl call. | 0,8% | — |
| CVE-2026-65905 | CRIT 9.8 | apache tomcat Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize requests have been made, a client makes a DIGEST authenticated request with a nonceCount on the upper boundary of the replay window then that | 0,8% | — |
| CVE-2026-55970 | MED 6.5 | apache thrift Buffer Over-read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. | 0,8% | — |
| CVE-2026-43465 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: RX, Fix XDP multi-buf frag counting for striding RQ XDP multi-buf programs can modify the layout of the XDP buffer when the program calls bpf_xdp_pull_data() or bpf_xdp_adjust_tai | 0,8% | — |
| CVE-2025-22039 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix overflow in dacloffset bounds check The dacloffset field was originally typed as int and used in an unchecked addition, which could overflow and bypass the existing bounds check i | 0,8% | — |
| CVE-2024-47659 | CRIT 9.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smack: tcp: ipv4, fix incorrect labeling Currently, Smack mirrors the label of incoming tcp/ipv4 connections: when a label 'foo' connects to a label 'bar' with tcp/ipv4, 'foo' always gets 'f | 0,8% | — |
| CVE-2024-29063 | HIGH 7.3 | microsoft azure_ai_search Azure AI Search Information Disclosure Vulnerability | 0,8% | — |
| CVE-2023-25734 | HIGH 8.1 | mozilla firefox After downloading a Windows <code>.url</code> shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system. This also had the potential to leak NTLM credentials to the resou | 0,8% | — |
| CVE-2023-21806 | HIGH 8.2 | microsoft power_bi_report_server Power BI Report Server Spoofing Vulnerability | 0,8% | — |
| CVE-2023-20100 | MED 6.8 | cisco ios_xe A vulnerability in the access point (AP) joining process of the Control and Provisioning of Wireless Access Points (CAPWAP) protocol of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, remote attacker to cause a denial | 0,8% | — |
| CVE-2020-1434 | MED 5.3 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Sync Host Service handles objects in memory, aka 'Windows Sync Host Service Elevation of Privilege Vulnerability'. | 0,8% | — |
| CVE-2019-11345 | MED 6.1 | citrix citrix_sd-wan_center Citrix SD-WAN Center 10.2.x before 10.2.1 and NetScaler SD-WAN Center 10.0.x before 10.0.7 allow XSS. | 0,8% | — |
| CVE-2015-4259 | MED 4.3 | cisco unified_computing_system The Integrated Management Controller on Cisco Unified Computing System (UCS) C servers with software 1.5(3) and 1.6(0.16) has a default SSL certificate, which makes it easier for man-in-the-middle attackers to bypass cryptographic protection mechanisms by leve | 0,8% | — |
| CVE-2014-0049 | HIGH 7.4 | linux linux_kernel Buffer overflow in the complete_emulated_mmio function in arch/x86/kvm/x86.c in the Linux kernel before 3.13.6 allows guest OS users to execute arbitrary code on the host OS by leveraging a loop that triggers an invalid memory copy affecting certain cancel_wor | 0,8% | — |
| CVE-2026-68074 | HIGH 7.5 | apache qpid_broker-j A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes th | 0,8% | — |
| CVE-2026-68073 | HIGH 7.5 | apache qpid_broker-j A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the iss | 0,8% | — |
| CVE-2026-68060 | HIGH 7.5 | apache qpid_broker-j A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fix | 0,8% | — |
| CVE-2026-67590 | HIGH 7.5 | apache qpid_protonj2 A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue | 0,8% | — |
| CVE-2026-67589 | HIGH 7.5 | apache qpid_protonj2 A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes | 0,8% | — |
| CVE-2026-67588 | HIGH 7.5 | apache qpid_protonj2 A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the | 0,8% | — |