58.586 CVE seguite
797 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.586 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2023-23487 | MED 4.3 | ibm db2 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to insufficient audit logging. IBM X-Force ID: 245918. | 0,8% | — |
| CVE-2022-22048 | MED 6.1 | microsoft windows_10 BitLocker Security Feature Bypass Vulnerability | 0,8% | — |
| CVE-2021-31972 | MED 5.5 | microsoft windows_10 Event Tracing for Windows Information Disclosure Vulnerability | 0,8% | — |
| CVE-2021-31960 | MED 5.5 | microsoft windows_10 Windows Bind Filter Driver Information Disclosure Vulnerability | 0,8% | — |
| CVE-2021-31191 | MED 5.5 | microsoft windows_10 Windows Projected File System FS Filter Driver Information Disclosure Vulnerability | 0,8% | — |
| CVE-2021-28479 | MED 5.5 | microsoft windows_10 Windows CSC Service Information Disclosure Vulnerability | 0,8% | — |
| CVE-2021-28446 | HIGH 7.1 | microsoft windows_10 Windows Portmapping Information Disclosure Vulnerability | 0,8% | — |
| CVE-2021-28441 | MED 6.5 | microsoft windows_10 Windows Hyper-V Information Disclosure Vulnerability | 0,8% | — |
| CVE-2021-28437 | MED 5.5 | microsoft windows_10 Windows Installer Information Disclosure Vulnerability | 0,8% | — |
| CVE-2021-28435 | MED 5.5 | microsoft windows_10 Windows Event Tracing Information Disclosure Vulnerability | 0,8% | — |
| CVE-2021-28318 | MED 5.5 | microsoft windows_10 Windows GDI+ Information Disclosure Vulnerability | 0,8% | — |
| CVE-2021-21140 | MED 6.8 | google chrome Uninitialized use in USB in Google Chrome prior to 88.0.4324.96 allowed a local attacker to potentially perform out of bounds memory access via via a USB device. | 0,8% | — |
| CVE-2020-3353 | MED 5.9 | cisco identity_services_engine A vulnerability in the syslog processing engine of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a race condition that may oc | 0,8% | — |
| CVE-2020-1685 | MED 5.8 | juniper junos When configuring stateless firewall filters in Juniper Networks EX4600 and QFX 5000 Series devices using Virtual Extensible LAN protocol (VXLAN), the discard action will fail to discard traffic under certain conditions. Given a firewall filter configuration si | 0,8% | — |
| CVE-2020-1405 | HIGH 7.1 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions, aka 'Windows Mobile Device Management Diagnostics Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-13 | 0,8% | — |
| CVE-2026-57988 | HIGH 7.1 | microsoft edge_chromium Relative path traversal in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0,8% | — |
| CVE-2026-45455 | LOW 3.3 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | 0,8% | — |
| CVE-2026-40961 | HIGH 7.2 | apache airflow A bug in the login redirect route in Apache Airflow allowed authenticated users to craft URLs that bypassed the `is_safe_url` check, enabling redirection from a trusted Airflow domain to an attacker-controlled origin. Users are advised to upgrade to `apache-ai | 0,8% | — |
| CVE-2025-54057 | MED 6.1 | apache skywalking Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache SkyWalking. This issue affects Apache SkyWalking: <= 10.2.0. Users are recommended to upgrade to version 10.3.0, which fixes the issue. | 0,8% | — |
| CVE-2025-21327 | MED 6.6 | microsoft windows_10_1507 Windows Digital Media Elevation of Privilege Vulnerability | 0,8% | — |
| CVE-2025-21265 | MED 6.6 | microsoft windows_10_1507 Windows Digital Media Elevation of Privilege Vulnerability | 0,8% | — |
| CVE-2025-21263 | MED 6.6 | microsoft windows_10_1507 Windows Digital Media Elevation of Privilege Vulnerability | 0,8% | — |
| CVE-2025-21261 | MED 6.6 | microsoft windows_10_1507 Windows Digital Media Elevation of Privilege Vulnerability | 0,8% | — |
| CVE-2024-27026 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: vmxnet3: Fix missing reserved tailroom Use rbi->len instead of rcd->len for non-dataring packet. Found issue: XDP_WARN: xdp_update_frame_from_buff(line:278): Driver BUG: missing reserved | 0,8% | — |
| CVE-2023-36866 | HIGH 7.8 | microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability | 0,8% | — |