EN
58.586 CVE seguite
797 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.586 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più alto In KEV dal, ordina dal più alto
CVE-2022-28859 MED 6.5 f5 big-ip_access_policy_manager On F5 BIG-IP 15.1.x versions prior to 15.1.5.1 and 14.1.x versions prior to 14.1.4.6, when installing Net HSM, the scripts (nethsm-safenet-install.sh and nethsm-thales-install.sh) expose the Net HSM partition password. Note: Software versions which have reache 0,8% —
CVE-2021-27195 MED 5.9 netop vision_pro Improper Authorization vulnerability in Netop Vision Pro up to and including to 9.7.1 allows an attacker to replay network traffic. 0,8% —
CVE-2021-22047 MED 5.3 vmware spring_data_rest In Spring Data REST versions 3.4.0 - 3.4.13, 3.5.0 - 3.5.5, and older unsupported versions, HTTP resources implemented by custom controllers using a configured base API path and a controller type-level request mapping are additionally exposed under URIs that c 0,8% —
CVE-2016-8475 MED 4.7 linux linux_kernel An information disclosure vulnerability in the HTC input driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: An 0,8% —
CVE-2016-8474 MED 4.7 linux linux_kernel An information disclosure vulnerability in the STMicroelectronics driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Pr 0,8% —
CVE-2016-8473 MED 4.7 linux linux_kernel An information disclosure vulnerability in the STMicroelectronics driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Pr 0,8% —
CVE-2016-8469 MED 4.7 linux linux_kernel An information disclosure vulnerability in the camera driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Andro 0,8% —
CVE-2015-3006 MED 6.5 juniper junos On the QFX3500 and QFX3600 platforms, the number of bytes collected from the RANDOM_INTERRUPT entropy source when the device boots up is insufficient, possibly leading to weak or duplicate SSH keys or self-signed SSL/TLS certificates. Entropy increases after t 0,8% —
CVE-2000-0227 LOW 2.1 linux linux_kernel The Linux 2.2.x kernel does not restrict the number of Unix domain sockets as defined by the wmem_max parameter, which allows local users to cause a denial of service by requesting a large number of sockets. 0,8% —
CVE-2022-41098 MED 5.5 microsoft windows_10 Windows GDI+ Information Disclosure Vulnerability 0,8% —
CVE-2022-30162 MED 5.5 microsoft windows_10 Windows Kernel Information Disclosure Vulnerability 0,8% —
CVE-2019-6695 CRIT 9.8 fortinet fortimanager Lack of root file system integrity checking in Fortinet FortiManager VM application images of 6.2.0, 6.0.6 and below may allow an attacker to implant third-party programs by recreating the image through specific methods. 0,8% —
CVE-2016-1090 HIGH 7.8 adobe acrobat Untrusted search path vulnerability in Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allows local users to gain privilege 0,8% —
CVE-2016-1087 HIGH 7.8 adobe acrobat Untrusted search path vulnerability in Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allows local users to gain privilege 0,8% —
CVE-2026-73019 MED 4.3 microsoft windows_10_1607 Improper resolution of path equivalence in Windows URL Moniker allows an unauthorized attacker to bypass a security feature over a network. 0,8% —
CVE-2026-23571 MED 6.8 teamviewer digital_employee_experience A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-RunPkgStatusRequest instruction. Improper input validation allows authenticated attackers with actioner privilege to run elevated arbitrary com 0,8% —
CVE-2025-49713 HIGH 8.8 microsoft edge_chromium Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. 0,8% —
CVE-2025-25001 MED 4.3 microsoft edge Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. 0,8% —
CVE-2024-49031 HIGH 7.8 microsoft 365_apps Microsoft Office Graphics Remote Code Execution Vulnerability 0,8% —
CVE-2024-49030 HIGH 7.8 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 0,8% —
CVE-2024-49029 HIGH 7.8 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 0,8% —
CVE-2024-49028 HIGH 7.8 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 0,8% —
CVE-2024-49027 HIGH 7.8 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 0,8% —
CVE-2024-49021 HIGH 7.8 microsoft sql_server_2016 Microsoft SQL Server Remote Code Execution Vulnerability 0,8% —
CVE-2022-45934 HIGH 7.8 debian debian_linux An issue was discovered in the Linux kernel through 6.0.10. l2cap_config_req in net/bluetooth/l2cap_core.c has an integer wraparound via L2CAP_CONF_REQ packets. 0,8% —