EN
58.639 CVE seguite
797 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.639 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più alto In KEV dal, ordina dal più alto
CVE-2026-69524 HIGH 8.1 microsoft windows_10_1607 Use after free in Active Directory Domain Services allows an unauthorized attacker to execute code over a network. 0,7% —
CVE-2026-69325 HIGH 8.1 microsoft windows_10_1607 Heap-based buffer overflow in Microsoft JScript allows an unauthorized attacker to execute code over a network. 0,7% —
CVE-2026-55007 HIGH 8.1 microsoft exchange_server Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network. 0,7% —
CVE-2026-50112 HIGH 8.8 apache cloudstack SSRF via Metalink Mirror URL Resolution: An authenticated tenant can register a template pointing to an attacker-controlled metalink file containing internal targets. The Secondary Storage VM will retrieve the data and persist it as a template file, which can 0,7% —
CVE-2026-42811 CRIT 9.9 apache polaris In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials that only work for one table's files, but a crafted namespace or table name can cause those credentials to work across the configured bucket instead. Apache Polaris builds Google 0,7% —
CVE-2023-21737 HIGH 7.8 microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability 0,7% —
CVE-2023-21736 HIGH 7.8 microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability 0,7% —
CVE-2023-21735 HIGH 7.8 microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability 0,7% —
CVE-2022-44704 HIGH 7.8 microsoft windows_sysmon Microsoft Windows System Monitor (Sysmon) Elevation of Privilege Vulnerability 0,7% —
CVE-2022-22460 HIGH 7.5 ibm security_verify_governance IBM Security Verify Identity Manager 10.0 contains sensitive information in the source code repository that could be used in further attacks against the system. IBM X-Force ID: 225013. 0,7% —
CVE-2021-40131 MED 5.5 cisco common_services_platform_collector A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to 0,7% —
CVE-2020-7851 HIGH 7.8 innorix file_transfer_solution Innorix Web-Based File Transfer Solution versuibs prior to and including 9.2.18.385 contains a vulnerability that could allow remote files to be downloaded and executed by setting the arguments to the internal method. A remote attacker could induce a user to a 0,7% —
CVE-2020-4320 MED 6.5 ibm mq IBM MQ Appliance and IBM MQ AMQP Channels 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD do not correctly block or allow clients based on the certificate distinguished name SSLPEER setting. IBM X-Force ID: 177403. 0,7% —
CVE-2020-3591 MED 4.3 cisco catalyst_sd-wan_manager A vulnerability in the web-based management interface of the Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability exists because the web-ba 0,7% —
CVE-2019-10250 MED 5.9 ucweb uc_browser UCWeb UC Browser 7.0.185.1002 on Windows uses HTTP for downloading certain PDF modules, which allows MITM attacks. 0,7% —
CVE-2018-10882 MED 4.8 canonical ubuntu_linux A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bound write in in fs/jbd2/transaction.c code, a denial of service, and a system crash by unmounting a crafted ext4 filesystem image. 0,7% —
CVE-2017-3007 HIGH 7.8 adobe creative_cloud Adobe Thor versions 3.9.5.353 and earlier have a vulnerability in the directory search path used to find resources, related to Creative Cloud desktop applications. 0,7% —
CVE-2014-9895 MED 5.5 google android drivers/media/media-device.c in the Linux kernel before 3.11, as used in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices, does not properly initialize certain data structures, which allows local users to obtain sensitive information via a crafted app 0,7% —
CVE-2014-2131 MED 6.1 cisco ios The packet driver in Cisco IOS allows remote attackers to cause a denial of service (device reload) via a series of (1) Virtual Switching Systems (VSS) or (2) Bidirectional Forwarding Detection (BFD) packets, aka Bug IDs CSCug41049 and CSCue61890. 0,7% —
CVE-2025-21598 HIGH 7.5 juniper junos An Out-of-bounds Read vulnerability in Juniper Networks Junos OS and Junos OS Evolved's routing protocol daemon (rpd) allows an unauthenticated, network-based attacker to send malformed BGP packets to a device configured with packet receive trace options enabl 0,7% —
CVE-2024-44986 HIGH 8.1 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: ipv6: fix possible UAF in ip6_finish_output2() If skb_expand_head() returns NULL, skb has been freed and associated dst/idev could also have been freed. We need to hold rcu_read_lock() to m 0,7% —
CVE-2024-26172 MED 5.5 microsoft windows_10_1809 Windows DWM Core Library Information Disclosure Vulnerability 0,7% —
CVE-2024-21387 MED 5.3 microsoft edge_chromium Microsoft Edge for Android Spoofing Vulnerability 0,7% —
CVE-2023-48396 CRIT 9.1 apache seatunnel Web Authentication vulnerability in Apache SeaTunnel. Since the jwt key is hardcoded in the application, an attacker can forge any token to log in any user. Attacker can get secret key in /seatunnel-server/seatunnel-app/src/main/resources/application.yml and 0,7% —
CVE-2023-32028 HIGH 7.8 microsoft ole_db_driver_for_sql_server Microsoft SQL OLE DB Remote Code Execution Vulnerability 0,7% —