58.639 CVE seguite
797 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.639 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-69219 | ND | The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1, src/main/java/com/rabbitmq/client/impl/ValueReader.java uses ValueReader.readBytes to accept a wire-declared contentLength | 0,7% | — |
| CVE-2026-63512 | MED 6.5 | microsoft sharepoint_server Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network. | 0,7% | — |
| CVE-2026-24656 | LOW 3.7 | apache karaf_decanter Deserialization of Untrusted Data vulnerability in Apache Karaf Decanter. The Decanter log socket collector exposes the port 4560, without authentication. If the collector exposes allowed classes property, this configuration can be bypassed. It means that th | 0,7% | — |
| CVE-2021-22040 | MED 6.7 | vmware cloud_foundation VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process runn | 0,7% | — |
| CVE-2020-16988 | MED 6.9 | microsoft azure_sphere Azure Sphere Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2019-12619 | MED 6.5 | cisco sd-wan_firmware A vulnerability in the web interface for Cisco SD-WAN Solution vManage could allow an authenticated, remote attacker to impact the integrity of an affected system by executing arbitrary SQL queries. The vulnerability is due to insufficient validation of user-s | 0,7% | — |
| CVE-2018-10651 | MED 6.1 | citrix xenmobile_server There are Open Redirect Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3. | 0,7% | — |
| CVE-2016-1419 | HIGH 8.1 | cisco aironet_access_point_software Cisco Access Point devices with software 8.2(102.43) allow remote attackers to cause a denial of service (device reload) via crafted ARP packets, aka Bug ID CSCuy55803. | 0,7% | — |
| CVE-2010-4247 | MED 5.5 | citrix xen The do_block_io_op function in (1) drivers/xen/blkback/blkback.c and (2) drivers/xen/blktap/blktap.c in Xen before 3.4.0 for the Linux kernel 2.6.18, and possibly other versions, allows guest OS users to cause a denial of service (infinite loop and CPU consump | 0,7% | — |
| CVE-2026-72323 | CRIT 9.8 | In the Linux kernel, the following vulnerability has been resolved: ipv4: igmp: Fix potential UAF in igmp_gq_start_timer() A race condition exists between device teardown (inetdev_destroy) and incoming IGMP query processing (igmp_rcv), leading to a Use-After | 0,7% | — |
| CVE-2026-45171 | HIGH 8.8 | paloaltonetworks idira_privileged_session_manager Incomplete input validation and improperly configured folder permissions within Idira Privileged Session Manager (PSM) versions prior to 15.0.3, 14.6.3, 14.2.5, and 14.0.5, an authenticated, low-privileged user could potentially execute arbitrary code. CyberAr | 0,7% | — |
| CVE-2024-42247 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wireguard: allowedips: avoid unaligned 64-bit memory accesses On the parisc platform, the kernel issues kernel warnings because swap_endian() tries to load a 128-bit IPv6 address from an una | 0,7% | — |
| CVE-2024-38254 | MED 5.5 | microsoft windows_10_1507 Windows Authentication Information Disclosure Vulnerability | 0,7% | — |
| CVE-2023-44252 | HIGH 8.8 | fortinet fortiwan ** UNSUPPORTED WHEN ASSIGNED **An improper authentication vulnerability [CWE-287] in Fortinet FortiWAN version 5.2.0 through 5.2.1 and version 5.1.1 through 5.1.2 may allow an authenticated attacker to escalate his privileges via HTTP or HTTPs requests with cr | 0,7% | — |
| CVE-2023-29181 | HIGH 8.8 | fortinet fortios A use of externally-controlled format string in Fortinet FortiOS 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.14, 6.0.0 through 6.0.16, FortiProxy 7.2.0 through 7.2.4, 7.0.0 through 7.0.10, 2.0.0 through 2.0.12, 1.2.0 thro | 0,7% | — |
| CVE-2022-47213 | HIGH 7.8 | microsoft 365_apps Microsoft Office Graphics Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2022-47212 | HIGH 7.8 | microsoft 365_apps Microsoft Office Graphics Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2022-44682 | MED 6.8 | microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability | 0,7% | — |
| CVE-2022-38381 | MED 5.3 | fortinet fortiadc An improper handling of malformed request vulnerability [CWE-228] exists in FortiADC 5.0 all versions, 6.0.0 all versions, 6.1.0 all versions, 6.2.0 through 6.2.3, and 7.0.0 through 7.0.2. This may allow a remote attacker without privileges to bypass some Web | 0,7% | — |
| CVE-2019-20456 | HIGH 7.8 | goverlan client_agent Goverlan Reach Console before 9.50, Goverlan Reach Server before 3.50, and Goverlan Client Agent before 9.20.50 have an Untrusted Search Path that leads to Command Injection and Local Privilege Escalation via DLL hijacking. | 0,7% | — |
| CVE-2017-9077 | HIGH 7.8 | linux linux_kernel The tcp_v6_syn_recv_sock function in net/ipv6/tcp_ipv6.c in the Linux kernel through 4.11.1 mishandles inheritance, which allows local users to cause a denial of service or possibly have unspecified other impact via crafted system calls, a related issue to CVE | 0,7% | — |
| CVE-2015-0756 | MED 6.1 | cisco wireless_lan_controller Cisco Wireless LAN Controller (WLC) devices with software 7.4(1.1) allow remote attackers to cause a denial of service (wireless-networking outage) via crafted TCP traffic on the local network, aka Bug ID CSCug67104. | 0,7% | — |
| CVE-2012-1366 | MED 6.1 | cisco asr_1001 Cisco IOS before 15.1(1)SY on ASR 1000 devices, when Multicast Listener Discovery (MLD) tracking is enabled for IPv6, allows remote attackers to cause a denial of service (device reload) via crafted MLD packets, aka Bug ID CSCtz28544. | 0,7% | — |
| CVE-2005-0916 | LOW 2.1 | linux linux_kernel AIO in the Linux kernel 2.6.11 on the PPC64 or IA64 architectures with CONFIG_HUGETLB_PAGE enabled allows local users to cause a denial of service (system panic) via a process that executes the io_queue_init function but exits without running io_queue_release, | 0,7% | — |
| CVE-2026-69546 | HIGH 8.1 | microsoft windows_10_1607 Use after free in Active Directory Domain Services allows an unauthorized attacker to execute code over a network. | 0,7% | — |