58.639 CVE seguite
797 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.639 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-69524 | HIGH 8.1 | microsoft windows_10_1607 Use after free in Active Directory Domain Services allows an unauthorized attacker to execute code over a network. | 0,7% | — |
| CVE-2026-69325 | HIGH 8.1 | microsoft windows_10_1607 Heap-based buffer overflow in Microsoft JScript allows an unauthorized attacker to execute code over a network. | 0,7% | — |
| CVE-2026-55007 | HIGH 8.1 | microsoft exchange_server Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network. | 0,7% | — |
| CVE-2026-50112 | HIGH 8.8 | apache cloudstack SSRF via Metalink Mirror URL Resolution: An authenticated tenant can register a template pointing to an attacker-controlled metalink file containing internal targets. The Secondary Storage VM will retrieve the data and persist it as a template file, which can | 0,7% | — |
| CVE-2026-42811 | CRIT 9.9 | apache polaris In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials that only work for one table's files, but a crafted namespace or table name can cause those credentials to work across the configured bucket instead. Apache Polaris builds Google | 0,7% | — |
| CVE-2023-21737 | HIGH 7.8 | microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2023-21736 | HIGH 7.8 | microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2023-21735 | HIGH 7.8 | microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2022-44704 | HIGH 7.8 | microsoft windows_sysmon Microsoft Windows System Monitor (Sysmon) Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2022-22460 | HIGH 7.5 | ibm security_verify_governance IBM Security Verify Identity Manager 10.0 contains sensitive information in the source code repository that could be used in further attacks against the system. IBM X-Force ID: 225013. | 0,7% | — |
| CVE-2021-40131 | MED 5.5 | cisco common_services_platform_collector A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to | 0,7% | — |
| CVE-2020-7851 | HIGH 7.8 | innorix file_transfer_solution Innorix Web-Based File Transfer Solution versuibs prior to and including 9.2.18.385 contains a vulnerability that could allow remote files to be downloaded and executed by setting the arguments to the internal method. A remote attacker could induce a user to a | 0,7% | — |
| CVE-2020-4320 | MED 6.5 | ibm mq IBM MQ Appliance and IBM MQ AMQP Channels 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD do not correctly block or allow clients based on the certificate distinguished name SSLPEER setting. IBM X-Force ID: 177403. | 0,7% | — |
| CVE-2020-3591 | MED 4.3 | cisco catalyst_sd-wan_manager A vulnerability in the web-based management interface of the Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability exists because the web-ba | 0,7% | — |
| CVE-2019-10250 | MED 5.9 | ucweb uc_browser UCWeb UC Browser 7.0.185.1002 on Windows uses HTTP for downloading certain PDF modules, which allows MITM attacks. | 0,7% | — |
| CVE-2018-10882 | MED 4.8 | canonical ubuntu_linux A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bound write in in fs/jbd2/transaction.c code, a denial of service, and a system crash by unmounting a crafted ext4 filesystem image. | 0,7% | — |
| CVE-2017-3007 | HIGH 7.8 | adobe creative_cloud Adobe Thor versions 3.9.5.353 and earlier have a vulnerability in the directory search path used to find resources, related to Creative Cloud desktop applications. | 0,7% | — |
| CVE-2014-9895 | MED 5.5 | google android drivers/media/media-device.c in the Linux kernel before 3.11, as used in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices, does not properly initialize certain data structures, which allows local users to obtain sensitive information via a crafted app | 0,7% | — |
| CVE-2014-2131 | MED 6.1 | cisco ios The packet driver in Cisco IOS allows remote attackers to cause a denial of service (device reload) via a series of (1) Virtual Switching Systems (VSS) or (2) Bidirectional Forwarding Detection (BFD) packets, aka Bug IDs CSCug41049 and CSCue61890. | 0,7% | — |
| CVE-2025-21598 | HIGH 7.5 | juniper junos An Out-of-bounds Read vulnerability in Juniper Networks Junos OS and Junos OS Evolved's routing protocol daemon (rpd) allows an unauthenticated, network-based attacker to send malformed BGP packets to a device configured with packet receive trace options enabl | 0,7% | — |
| CVE-2024-44986 | HIGH 8.1 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: ipv6: fix possible UAF in ip6_finish_output2() If skb_expand_head() returns NULL, skb has been freed and associated dst/idev could also have been freed. We need to hold rcu_read_lock() to m | 0,7% | — |
| CVE-2024-26172 | MED 5.5 | microsoft windows_10_1809 Windows DWM Core Library Information Disclosure Vulnerability | 0,7% | — |
| CVE-2024-21387 | MED 5.3 | microsoft edge_chromium Microsoft Edge for Android Spoofing Vulnerability | 0,7% | — |
| CVE-2023-48396 | CRIT 9.1 | apache seatunnel Web Authentication vulnerability in Apache SeaTunnel. Since the jwt key is hardcoded in the application, an attacker can forge any token to log in any user. Attacker can get secret key in /seatunnel-server/seatunnel-app/src/main/resources/application.yml and | 0,7% | — |
| CVE-2023-32028 | HIGH 7.8 | microsoft ole_db_driver_for_sql_server Microsoft SQL OLE DB Remote Code Execution Vulnerability | 0,7% | — |