EN
58.639 CVE seguite
798 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.639 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più alto In KEV dal, ordina dal più alto
CVE-2025-62207 HIGH 8.6 microsoft azure_monitor Azure Monitor Elevation of Privilege Vulnerability 0,7% —
CVE-2025-24067 HIGH 7.8 microsoft windows_10_1507 Heap-based buffer overflow in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally. 0,7% —
CVE-2025-24066 HIGH 7.8 microsoft windows_10_1507 Heap-based buffer overflow in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. 0,7% —
CVE-2025-21188 MED 6.0 microsoft azure_network_watcher Azure Network Watcher VM Extension Elevation of Privilege Vulnerability 0,7% —
CVE-2024-35277 HIGH 8.6 fortinet fortimanager A missing authentication for critical function in Fortinet FortiPortal version 6.0.0 through 6.0.15, FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14 allows attacker to access to the configuration of the 0,7% —
CVE-2024-30329 LOW 3.3 foxit pdf_editor Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerabil 0,7% —
CVE-2024-30030 HIGH 7.8 microsoft windows_server_2008 Win32k Elevation of Privilege Vulnerability 0,7% —
CVE-2024-30028 HIGH 7.8 microsoft windows_10_1507 Win32k Elevation of Privilege Vulnerability 0,7% —
CVE-2024-20339 HIGH 8.6 cisco secure_firewall_threat_defense A vulnerability in the TLS processing feature of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerabi 0,7% —
CVE-2023-38131 MED 6.5 intel unison_software Improper input validationation for some Intel Unison software may allow an authenticated user to potentially enable denial of service via network access. 0,7% —
CVE-2022-33675 HIGH 7.8 microsoft azure_site_recovery_vmware_to_azure Azure Site Recovery Elevation of Privilege Vulnerability 0,7% —
CVE-2021-27363 MED 4.4 debian debian_linux An issue was discovered in the Linux kernel through 5.11.3. A kernel pointer leak can be used to determine the address of the iscsi_transport structure. When an iSCSI transport is registered with the iSCSI subsystem, the transport's handle is available to unpr 0,7% —
CVE-2020-16989 MED 5.4 microsoft azure_sphere Azure Sphere Elevation of Privilege Vulnerability 0,7% —
CVE-2020-12657 HIGH 7.8 linux linux_kernel An issue was discovered in the Linux kernel before 5.6.5. There is a use-after-free in block/bfq-iosched.c related to bfq_idle_slice_timer_body. 0,7% —
CVE-2020-1002 HIGH 7.1 microsoft forefront_endpoint_protection_2010 An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Defender Elevation of Privilege Vu 0,7% —
CVE-2014-0737 MED 4.3 cisco unified_ip_phone_7960g The Cisco Unified IP Phone 7960G 9.2(1) and earlier allows remote attackers to bypass authentication and change trust relationships by injecting a Certificate Trust List (CTL) file, aka Bug ID CSCuj66795. 0,7% —
CVE-2010-3849 MED 4.7 canonical ubuntu_linux The econet_sendmsg function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2, when an econet address is configured, allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a sendmsg call that specifies a NULL value 0,7% —
CVE-2026-42535 CRIT 9.1 apache http_server A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes. Users are recommended to upgrade to version 2.4.68, which fixes t 0,7% —
CVE-2026-22153 HIGH 8.1 fortinet fortios An Authentication Bypass by Primary Weakness vulnerability [CWE-305] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4 may allow an unauthenticated attacker to bypass LDAP authentication of Agentless VPN or FSSO policy, when the remote LDAP server is confi 0,7% —
CVE-2025-64663 CRIT 9.9 microsoft azure_language Custom Question Answering Elevation of Privilege Vulnerability 0,7% —
CVE-2025-30412 CRIT 10.0 acronis cyber_protect Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis Cyber Protect 15 (Linux, Windows) before build 41800. 0,7% —
CVE-2025-23316 CRIT 9.8 nvidia triton_inference_server NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause a remote code execution by manipulating the model name parameter in the model control APIs. A successful exploit of this vulnerab 0,7% —
CVE-2024-41178 HIGH 7.5 apache arrow Exposure of temporary credentials in logs in Apache Arrow Rust Object Store (`object_store` crate), version 0.10.1 and earlier on all platforms using AWS WebIdentityTokens.  On certain error conditions, the logs may contain the OIDC token passed to AssumeRol 0,7% —
CVE-2024-30382 HIGH 7.5 juniper junos An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based, unauthenticated attacker to send a specific routing update, causing an rpd core due to m 0,7% —
CVE-2023-37464 HIGH 8.6 cisco cjose OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). The AES GCM decryption routine incorrectly uses the Tag length from the actual Authentication Tag provided in the JWE. The spec says that a fixed length of 16 octet 0,7% —