EN
58.639 CVE seguite
797 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.639 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più alto In KEV dal, ordina dal più alto
CVE-2020-0822 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Language Pack Installer improperly handles file operations, aka 'Windows Language Pack Installer Elevation of Privilege Vulnerability'. 0,7% —
CVE-2014-7999 HIGH 7.7 cisco meraki_mr Cisco-Meraki MS, MR, and MX devices with firmware before 2014-09-24 allow remote authenticated users to install arbitrary firmware by leveraging unspecified HTTP handler access on the local network, aka Cisco-Meraki defect ID 00478565. 0,7% —
CVE-2026-73634 HIGH 7.5 apache struts Uncontrolled resource consumption vulnerability in Apache Struts. An application that exposes an endpoint collecting Content Security Policy violation reports reads the submitted report into memory without bounding how much it will accept, so a single request 0,7% —
CVE-2026-45177 CRIT 9.1 paloaltonetworks idira_secrets_manager_edge Idira Secrets Manager SaaS Edge versions prior to 1.8 exhibit improper access control within its internal authentication components. A remote, unauthenticated attacker could exploit this by submitting a specially crafted request. Under specific circumstances, 0,7% —
CVE-2026-24343 HIGH 8.8 apache hertzbeat Improper Neutralization of Data within XPath Expressions ('XPath Injection') vulnerability in Apache HertzBeat. This issue affects Apache HertzBeat: from 1.7.1 before 1.8.0. Users are recommended to upgrade to version 1.8.0, which fixes the issue. 0,7% —
CVE-2026-23661 HIGH 7.5 microsoft azure_iot_explorer Cleartext transmission of sensitive information in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. 0,7% —
CVE-2025-21419 HIGH 7.1 microsoft windows_10_1507 Windows Setup Files Cleanup Elevation of Privilege Vulnerability 0,7% —
CVE-2024-3841 MED 6.1 fedoraproject fedora Insufficient data validation in Browser Switcher in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to inject scripts or HTML into a privileged page via a malicious file. (Chromium security severity: Medium) 0,7% —
CVE-2024-38133 HIGH 7.8 microsoft windows_10_1809 Windows Kernel Elevation of Privilege Vulnerability 0,7% —
CVE-2024-26877 CRIT 9.8 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: crypto: xilinx - call finalize with bh disabled When calling crypto_finalize_request, BH should be disabled to avoid triggering the following calltrace: ------------[ cut here ]-------- 0,7% —
CVE-2024-26253 MED 6.8 microsoft windows_10_1507 Windows rndismp6.sys Remote Code Execution Vulnerability 0,7% —
CVE-2024-26252 MED 6.8 microsoft windows_10_1507 Windows rndismp6.sys Remote Code Execution Vulnerability 0,7% —
CVE-2023-28248 HIGH 7.8 microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability 0,7% —
CVE-2022-38411 HIGH 7.8 adobe animate Adobe Animate version 21.0.11 (and earlier) and 22.0.7 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interacti 0,7% —
CVE-2022-38030 MED 4.3 microsoft windows_10 Windows USB Serial Driver Information Disclosure Vulnerability 0,7% —
CVE-2022-30213 MED 5.5 microsoft windows_10 Windows GDI+ Information Disclosure Vulnerability 0,7% —
CVE-2020-4658 MED 6.1 ibm sterling_file_gateway IBM Sterling File Gateway 2.2.0.0 through 6.0.3.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure wit 0,7% —
CVE-2020-4657 MED 6.1 ibm sterling_b2b_integrator IBM Sterling B2B Integrator 5.2.0.0 through 6.0.3.2 Standard Edition is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credent 0,7% —
CVE-2020-4183 MED 6.1 ibm security_guardium IBM Security Guardium 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. 0,7% —
CVE-2019-4681 MED 6.1 ibm tivoli_netcool\/impact IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure wi 0,7% —
CVE-2007-1734 HIGH 7.2 linux linux_kernel The DCCP support in the do_dccp_getsockopt function in net/dccp/proto.c in Linux kernel 2.6.20 and later does not verify the upper bounds of the optlen value, which allows local users running on certain architectures to read kernel memory or cause a denial of 0,7% —
CVE-2026-20818 MED 6.2 microsoft windows_server_2016 Insertion of sensitive information into log file in Windows Kernel allows an unauthorized attacker to disclose information locally. 0,7% —
CVE-2025-47176 HIGH 7.8 microsoft 365_apps '.../...//' in Microsoft Office Outlook allows an authorized attacker to execute code locally. 0,7% —
CVE-2025-27733 HIGH 7.8 microsoft windows_10_1507 Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally. 0,7% —
CVE-2024-45324 HIGH 7.2 fortinet fortios A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.0 through 7.4.4, version 7.2.0 through 7.2.9, version 7.0.0 through 7.0.15 and before 6.4.15, FortiProxy version 7.4.0 through 7.4.6, version 7.2.0 through 7.2.12 and b 0,7% —