58.639 CVE seguite
797 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.639 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2020-0822 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Language Pack Installer improperly handles file operations, aka 'Windows Language Pack Installer Elevation of Privilege Vulnerability'. | 0,7% | — |
| CVE-2014-7999 | HIGH 7.7 | cisco meraki_mr Cisco-Meraki MS, MR, and MX devices with firmware before 2014-09-24 allow remote authenticated users to install arbitrary firmware by leveraging unspecified HTTP handler access on the local network, aka Cisco-Meraki defect ID 00478565. | 0,7% | — |
| CVE-2026-73634 | HIGH 7.5 | apache struts Uncontrolled resource consumption vulnerability in Apache Struts. An application that exposes an endpoint collecting Content Security Policy violation reports reads the submitted report into memory without bounding how much it will accept, so a single request | 0,7% | — |
| CVE-2026-45177 | CRIT 9.1 | paloaltonetworks idira_secrets_manager_edge Idira Secrets Manager SaaS Edge versions prior to 1.8 exhibit improper access control within its internal authentication components. A remote, unauthenticated attacker could exploit this by submitting a specially crafted request. Under specific circumstances, | 0,7% | — |
| CVE-2026-24343 | HIGH 8.8 | apache hertzbeat Improper Neutralization of Data within XPath Expressions ('XPath Injection') vulnerability in Apache HertzBeat. This issue affects Apache HertzBeat: from 1.7.1 before 1.8.0. Users are recommended to upgrade to version 1.8.0, which fixes the issue. | 0,7% | — |
| CVE-2026-23661 | HIGH 7.5 | microsoft azure_iot_explorer Cleartext transmission of sensitive information in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. | 0,7% | — |
| CVE-2025-21419 | HIGH 7.1 | microsoft windows_10_1507 Windows Setup Files Cleanup Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2024-3841 | MED 6.1 | fedoraproject fedora Insufficient data validation in Browser Switcher in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to inject scripts or HTML into a privileged page via a malicious file. (Chromium security severity: Medium) | 0,7% | — |
| CVE-2024-38133 | HIGH 7.8 | microsoft windows_10_1809 Windows Kernel Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2024-26877 | CRIT 9.8 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: crypto: xilinx - call finalize with bh disabled When calling crypto_finalize_request, BH should be disabled to avoid triggering the following calltrace: ------------[ cut here ]-------- | 0,7% | — |
| CVE-2024-26253 | MED 6.8 | microsoft windows_10_1507 Windows rndismp6.sys Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2024-26252 | MED 6.8 | microsoft windows_10_1507 Windows rndismp6.sys Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2023-28248 | HIGH 7.8 | microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2022-38411 | HIGH 7.8 | adobe animate Adobe Animate version 21.0.11 (and earlier) and 22.0.7 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interacti | 0,7% | — |
| CVE-2022-38030 | MED 4.3 | microsoft windows_10 Windows USB Serial Driver Information Disclosure Vulnerability | 0,7% | — |
| CVE-2022-30213 | MED 5.5 | microsoft windows_10 Windows GDI+ Information Disclosure Vulnerability | 0,7% | — |
| CVE-2020-4658 | MED 6.1 | ibm sterling_file_gateway IBM Sterling File Gateway 2.2.0.0 through 6.0.3.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure wit | 0,7% | — |
| CVE-2020-4657 | MED 6.1 | ibm sterling_b2b_integrator IBM Sterling B2B Integrator 5.2.0.0 through 6.0.3.2 Standard Edition is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credent | 0,7% | — |
| CVE-2020-4183 | MED 6.1 | ibm security_guardium IBM Security Guardium 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | 0,7% | — |
| CVE-2019-4681 | MED 6.1 | ibm tivoli_netcool\/impact IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure wi | 0,7% | — |
| CVE-2007-1734 | HIGH 7.2 | linux linux_kernel The DCCP support in the do_dccp_getsockopt function in net/dccp/proto.c in Linux kernel 2.6.20 and later does not verify the upper bounds of the optlen value, which allows local users running on certain architectures to read kernel memory or cause a denial of | 0,7% | — |
| CVE-2026-20818 | MED 6.2 | microsoft windows_server_2016 Insertion of sensitive information into log file in Windows Kernel allows an unauthorized attacker to disclose information locally. | 0,7% | — |
| CVE-2025-47176 | HIGH 7.8 | microsoft 365_apps '.../...//' in Microsoft Office Outlook allows an authorized attacker to execute code locally. | 0,7% | — |
| CVE-2025-27733 | HIGH 7.8 | microsoft windows_10_1507 Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally. | 0,7% | — |
| CVE-2024-45324 | HIGH 7.2 | fortinet fortios A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.0 through 7.4.4, version 7.2.0 through 7.2.9, version 7.0.0 through 7.0.15 and before 6.4.15, FortiProxy version 7.4.0 through 7.4.6, version 7.2.0 through 7.2.12 and b | 0,7% | — |