58.639 CVE seguite
797 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.639 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2022-0023 | MED 5.9 | paloaltonetworks pan-os An improper handling of exceptional conditions vulnerability exists in the DNS proxy feature of Palo Alto Networks PAN-OS software that enables a meddler-in-the-middle (MITM) to send specifically crafted traffic to the firewall that causes the service to resta | 0,7% | — |
| CVE-2021-41343 | MED 5.5 | microsoft windows_10 Windows Fast FAT File System Driver Information Disclosure Vulnerability | 0,7% | — |
| CVE-2021-41336 | MED 5.5 | microsoft windows_11 Windows Kernel Information Disclosure Vulnerability | 0,7% | — |
| CVE-2021-40475 | MED 5.5 | microsoft windows_10 Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability | 0,7% | — |
| CVE-2021-40472 | MED 5.5 | microsoft 365_apps Microsoft Excel Information Disclosure Vulnerability | 0,7% | — |
| CVE-2021-40468 | MED 5.5 | microsoft windows_10 Windows Bind Filter Driver Information Disclosure Vulnerability | 0,7% | — |
| CVE-2021-38663 | MED 5.5 | microsoft windows_10 Windows exFAT File System Information Disclosure Vulnerability | 0,7% | — |
| CVE-2020-2044 | LOW 3.3 | paloaltonetworks pan-os An information exposure through log file vulnerability where an administrator's password or other sensitive information may be logged in cleartext while using the CLI in Palo Alto Networks PAN-OS software. The opcmdhistory.log file was introduced to track oper | 0,7% | — |
| CVE-2020-2043 | LOW 3.3 | paloaltonetworks pan-os An information exposure through log file vulnerability where sensitive fields are recorded in the configuration log without masking on Palo Alto Networks PAN-OS software when the after-change-detail custom syslog field is enabled for configuration logs and the | 0,7% | — |
| CVE-2019-20357 | HIGH 7.8 | trendmicro antivirus_\+_security_2019 A Persistent Arbitrary Code Execution vulnerability exists in the Trend Micro Security 2020 (v160 and 2019 (v15) consumer familiy of products which could potentially allow an attacker the ability to create a malicious program to escalate privileges and attain | 0,7% | — |
| CVE-2013-0160 | LOW 2.1 | linux linux_kernel The Linux kernel through 3.7.9 allows local users to obtain sensitive information about keystroke timing by using the inotify API on the /dev/ptmx device. | 0,7% | — |
| CVE-2026-58182 | HIGH 8.6 | apache traffic_server The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per-instance state. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommende | 0,7% | — |
| CVE-2026-42934 | MED 4.8 | f5 dos NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When charset, source_charset, and charset_map and proxy_pass with disabled buffering ("off") directives are configured, unauthenticated attackers can send requests tha | 0,7% | — |
| CVE-2026-3087 | HIGH 7.5 | python python If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then the archive will be extracted outside the target directory which is different than other operating systems. Only Windows is affected by this v | 0,7% | — |
| CVE-2026-22444 | HIGH 7.1 | apache solr The "create core" API of Apache Solr 8.6 through 9.10.0 lacks sufficient input validation on some API parameters, which can cause Solr to check the existence of and attempt to read file-system paths that should be disallowed by Solr's "allowPaths" security se | 0,7% | — |
| CVE-2026-20274 | CRIT 9.8 | cisco ios_xr As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple inte | 0,7% | — |
| CVE-2024-40957 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: seg6: fix parameter passing when calling NF_HOOK() in End.DX4 and End.DX6 behaviors input_action_end_dx4() and input_action_end_dx6() are called NF_HOOK() for PREROUTING hook, in PREROUTING | 0,7% | — |
| CVE-2024-29064 | MED 6.2 | microsoft windows_10_1507 Windows Hyper-V Denial of Service Vulnerability | 0,7% | — |
| CVE-2024-26241 | HIGH 7.8 | microsoft windows_10_1507 Win32k Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2024-20351 | HIGH 8.6 | cisco secure_firewall_threat_defense A vulnerability in the TCP/IP traffic handling function of the Snort Detection Engine of Cisco Firepower Threat Defense (FTD) Software and Cisco FirePOWER Services could allow an unauthenticated, remote attacker to cause legitimate network traffic to be droppe | 0,7% | — |
| CVE-2023-52741 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: cifs: Fix use-after-free in rdata->read_into_pages() When the network status is unstable, use-after-free may occur when read data from the server. BUG: KASAN: use-after-free in readpages_ | 0,7% | — |
| CVE-2023-20061 | MED 6.5 | cisco packaged_contact_center_enterprise Multiple vulnerabilities in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to collect sensitive information or perform a server-side request forgery (SSRF) attack on an affected system. Cisco plans to release software updates t | 0,7% | — |
| CVE-2022-21905 | MED 4.6 | microsoft windows_10 Windows Hyper-V Security Feature Bypass Vulnerability | 0,7% | — |
| CVE-2021-41374 | MED 6.7 | microsoft azure_sphere Azure Sphere Information Disclosure Vulnerability | 0,7% | — |
| CVE-2020-26068 | MED 5.5 | cisco roomos A vulnerability in the xAPI service of Cisco Telepresence CE Software and Cisco RoomOS Software could allow an authenticated, remote attacker to generate an access token for an affected device. The vulnerability is due to insufficient access authorization. An | 0,7% | — |