58.639 CVE seguite
798 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.639 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2023-22337 | HIGH 7.5 | intel unison_software Improper input validation for some Intel Unison software may allow an unauthenticated user to potentially enable denial of service via network access. | 0,7% | — |
| CVE-2021-32585 | HIGH 7.2 | fortinet fortiwan An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiWAN before 4.5.9 may allow an attacker to perform a stored cross-site scripting attack via specifically crafted HTTP requests. | 0,7% | — |
| CVE-2021-29694 | HIGH 7.5 | ibm spectrum_protect_plus IBM Spectrum Protect Plus 10.1.0 through 10.1.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 200258. | 0,7% | — |
| CVE-2021-26413 | MED 6.2 | microsoft windows_10 Windows Installer Spoofing Vulnerability | 0,7% | — |
| CVE-2021-20419 | HIGH 7.5 | ibm security_guardium IBM Security Guardium 11.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 196280. | 0,7% | — |
| CVE-2021-20337 | HIGH 7.5 | ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.3.0 to 7.3.3 Patch 8 and 7.4.0 to 7.4.3 GA uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 194448. | 0,7% | — |
| CVE-2020-24419 | HIGH 7.0 | adobe after_effects Adobe After Effects version 17.1.1 (and earlier) for Windows is affected by an uncontrolled search path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that | 0,7% | — |
| CVE-2018-0364 | HIGH 8.8 | cisco unified_communications_domain_manager A vulnerability in the web-based management interface of Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The | 0,7% | — |
| CVE-2026-53362 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation path In __ip6_append_data(), when the paged-allocation branch is taken (MSG_MORE / NETIF_F_SG / large fraglen), alloclen and pagedlen are co | 0,7% | |
| CVE-2025-54906 | HIGH 7.8 | microsoft 365_apps Free of memory not on the heap in Microsoft Office allows an unauthorized attacker to execute code locally. | 0,7% | — |
| CVE-2025-48822 | HIGH 8.6 | microsoft windows_10_1607 Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally. | 0,7% | — |
| CVE-2024-38079 | HIGH 7.8 | microsoft windows_10_1507 Windows Graphics Component Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2024-38070 | HIGH 7.8 | microsoft windows_10_1507 Windows LockDown Policy (WLDP) Security Feature Bypass Vulnerability | 0,7% | — |
| CVE-2024-20321 | HIGH 8.6 | cisco nx-os A vulnerability in the External Border Gateway Protocol (eBGP) implementation of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability exists because eBGP | 0,7% | — |
| CVE-2023-39228 | MED 5.3 | intel unison_software Improper access control for some Intel Unison software may allow an unauthenticated user to potentially enable denial of service via network access. | 0,7% | — |
| CVE-2023-28772 | MED 6.7 | linux linux_kernel An issue was discovered in the Linux kernel before 5.13.3. lib/seq_buf.c has a seq_buf_putmem_hex buffer overflow. | 0,7% | — |
| CVE-2022-45888 | MED 6.4 | linux linux_kernel An issue was discovered in the Linux kernel through 6.0.9. drivers/char/xillybus/xillyusb.c has a race condition and use-after-free during physical removal of a USB device. | 0,7% | — |
| CVE-2022-22031 | HIGH 7.8 | microsoft windows_10 Windows Credential Guard Domain-joined Public Key Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2018-6664 | MED 5.8 | mcafee data_loss_prevention_endpoint Application Protections Bypass vulnerability in Microsoft Windows in McAfee Data Loss Prevention (DLP) Endpoint before 10.0.500 and DLP Endpoint before 11.0.400 allows authenticated users to bypass the product block action via a command-line utility. | 0,7% | — |
| CVE-2025-69219 | HIGH 8.8 | apache airflow_providers_http A user with access to the DB could craft a database entry that would result in executing code on Triggerer - which gives anyone who have access to DB the same permissions as Dag Author. Since direct DB access is not usual and recommended for Airflow, the likel | 0,7% | — |
| CVE-2024-45031 | MED 6.1 | apache syncope When editing objects in the Syncope Console, incomplete HTML tags could be used to bypass HTML sanitization. This made it possible to inject stored XSS payloads which would trigger for other users during ordinary usage of the application. XSS payloads could al | 0,7% | — |
| CVE-2024-38503 | MED 5.4 | apache syncope When editing a user, group or any object in the Syncope Console, HTML tags could be added to any text field and could lead to potential exploits. The same vulnerability was found in the Syncope Enduser, when editing “Personal Information” or “User Requests”. | 0,7% | — |
| CVE-2024-38223 | MED 6.8 | microsoft windows_10_1507 Windows Initial Machine Configuration Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2024-24278 | HIGH 7.5 | teamwire teamwire An issue in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive information via a crafted payload to the message function. | 0,7% | — |
| CVE-2022-23438 | MED 4.7 | fortinet fortios An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in FortiOS version 7.0.5 and prior and 6.4.9 and prior may allow an unauthenticated remote attacker to perform a reflected cross site scripting (XSS) | 0,7% | — |