58.586 CVE seguite
797 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.586 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2023-36428 | MED 5.5 | microsoft windows_10_1507 Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability | 0,8% | — |
| CVE-2023-36406 | MED 5.5 | microsoft windows_11_21h2 Windows Hyper-V Information Disclosure Vulnerability | 0,8% | — |
| CVE-2023-28240 | HIGH 8.8 | microsoft windows_server_2008 Windows Network Load Balancing Remote Code Execution Vulnerability | 0,8% | — |
| CVE-2022-37424 | MED 6.5 | opennebula opennebula Files or Directories Accessible to External Parties vulnerability in OpenNebula on Linux allows File Discovery. | 0,8% | — |
| CVE-2021-47274 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tracing: Correct the length check which causes memory corruption We've suffered from severe kernel crashes due to memory corruption on our production environment, like, Call Trace: [1640542 | 0,8% | — |
| CVE-2020-0854 | HIGH 7.1 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions, aka 'Windows Mobile Device Management Diagnostics Elevation of Privilege Vulnerability'. | 0,8% | — |
| CVE-2019-19927 | MED 6.0 | linux linux_kernel In the Linux kernel 5.0.0-rc7 (as distributed in ubuntu/linux.git on kernel.ubuntu.com), mounting a crafted f2fs filesystem image and performing some operations can lead to slab-out-of-bounds read access in ttm_put_pages in drivers/gpu/drm/ttm/ttm_page_alloc.c | 0,8% | — |
| CVE-2018-9186 | MED 6.1 | fortinet fortiauthenticator A cross-site scripting (XSS) vulnerability in Fortinet FortiAuthenticator in versions 4.0.0 to before 5.3.0 "CSRF validation failure" page allows attacker to execute unauthorized script code via inject malicious scripts in HTTP referer header. | 0,8% | — |
| CVE-2026-52914 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: batman-adv: fix fragment reassembly length accounting batman-adv keeps a running payload length for queued fragments and uses it to validate a fragment chain before reassembly. That account | 0,8% | — |
| CVE-2026-49169 | HIGH 8.0 | microsoft windows_server_2025 Use after free in DNS Server allows an authorized attacker to execute code over a network. | 0,8% | — |
| CVE-2025-53378 | HIGH 7.6 | trendmicro worry-free_business_security_services A missing authentication vulnerability in Trend Micro Worry-Free Business Security Services (WFBSS) agent could have allowed an unauthenticated attacker to remotely take control of the agent on affected installations. Also note: this vulnerability only affe | 0,8% | — |
| CVE-2024-44940 | HIGH 7.5 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: fou: remove warn in gue_gro_receive on unsupported protocol Drop the WARN_ON_ONCE inn gue_gro_receive if the encapsulated type is not known or does not have a GRO handler. Such a packet is | 0,8% | — |
| CVE-2024-20451 | HIGH 7.5 | cisco spa_301_firmware Multiple vulnerabilities in the web-based management interface of Cisco Small Business SPA300 Series IP Phones and Cisco Small Business SPA500 Series IP Phones could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly. | 0,8% | — |
| CVE-2023-41677 | HIGH 7.5 | fortinet fortios A insufficiently protected credentials in Fortinet FortiProxy 7.4.0, 7.2.0 through 7.2.6, 7.0.0 through 7.0.12, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7, Fortinet FortiOS 7.4.0 through 7.4.1, 7.2.0 through 7.2.6, 7.0 | 0,8% | — |
| CVE-2023-35389 | MED 6.5 | microsoft dynamics_365 Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability | 0,8% | — |
| CVE-2022-33875 | MED 5.4 | fortinet fortiadc An improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability in Fortinet FortiADC version 7.1.0, version 7.0.0 through 7.0.2 and version 6.2.4 and below allows an authenticated attacker to execute unauthorized code or c | 0,8% | — |
| CVE-2026-63071 | CRIT 9.8 | apache syncope Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted code bypassing the Groovy security sandbox. This issue affect | 0,8% | — |
| CVE-2026-42778 | CRIT 9.8 | apache mina The fix for CVE-2026-41409 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of classes allowed to be des | 0,8% | — |
| CVE-2026-41409 | CRIT 9.8 | apache mina The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of classes allowed to be deserialized was applied too late after a static initializer in a class to be read might already have been executed. Aff | 0,8% | — |
| CVE-2026-23662 | HIGH 7.5 | microsoft azure_iot_explorer Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. | 0,8% | — |
| CVE-2025-29803 | HIGH 7.3 | microsoft sql_server_management_studio Uncontrolled search path element in Visual Studio Tools for Applications and SQL Server Management Studio allows an authorized attacker to elevate privileges locally. | 0,8% | — |
| CVE-2024-38139 | HIGH 8.7 | microsoft dataverse Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network. | 0,8% | — |
| CVE-2024-25090 | MED 5.4 | apache roller Insufficient input validation and sanitation in Profile name & screenname, Bookmark name & description and blogroll name features in all versions of Apache Roller on all platforms allows an authenticated user to perform an XSS attack. Mitigation: if you do not | 0,8% | — |
| CVE-2024-21340 | MED 4.6 | microsoft windows_10_1507 Windows Kernel Information Disclosure Vulnerability | 0,8% | — |
| CVE-2022-27486 | MED 6.6 | fortinet fortiddos A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiDDoS version 5.5.0 through 5.5.1, 5.4.2 through 5.4.0, 5.3.0 through 5.3.1, 5.2.0, 5.1.0, 5.0.0, 4.7.0, 4.6.0 and 4.5.0 and FortiDDoS-F version 6.3.0 | 0,8% | — |