58.650 CVE seguite
798 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.650 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-73635 | HIGH 7.5 | apache struts Allocation of resources without limits or throttling vulnerability in Apache Struts. When no fixed locale is configured, the locale used for localized-text lookups is taken from the incoming request, allowing an unauthenticated remote client to cause the frame | 0,7% | — |
| CVE-2026-73633 | HIGH 7.5 | apache struts Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts. When an application is configured to populate actions from a JSON request body, the plugin reads that body into memory without bounding how much it will accept, so a single re | 0,7% | — |
| CVE-2025-47956 | MED 5.5 | microsoft windows_security_app External control of file name or path in Windows Security App allows an authorized attacker to perform spoofing locally. | 0,7% | — |
| CVE-2025-24084 | HIGH 8.4 | microsoft windows_11_22h2 Untrusted pointer dereference in Windows Subsystem for Linux allows an unauthorized attacker to execute code locally. | 0,7% | — |
| CVE-2025-21341 | MED 6.6 | microsoft windows_10_1507 Windows Digital Media Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2025-20152 | HIGH 8.6 | cisco identity_services_engine A vulnerability in the RADIUS message processing feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handli | 0,7% | — |
| CVE-2023-35351 | MED 6.6 | microsoft windows_server_2008 Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2023-35346 | MED 6.6 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2023-35345 | MED 6.6 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2023-35344 | MED 6.6 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2021-34514 | HIGH 7.8 | microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2019-6696 | MED 6.1 | fortinet fortios An improper input validation vulnerability in FortiOS 6.2.1, 6.2.0, 6.0.8 and below until 5.4.0 under admin webUI may allow an attacker to perform an URL redirect attack via a specifically crafted request to the admin initial password change webpage. | 0,7% | — |
| CVE-2019-3701 | MED 4.4 | canonical ubuntu_linux An issue was discovered in can_can_gw_rcv in net/can/gw.c in the Linux kernel through 4.19.13. The CAN frame modification rules allow bitwise logical operations that can be also applied to the can_dlc field. The privileged user "root" with CAP_NET_ADMIN can cr | 0,7% | — |
| CVE-2019-1764 | HIGH 8.1 | cisco ip_conference_phone_8832_firmware A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack. The vulnerability is due t | 0,7% | — |
| CVE-2019-16154 | MED 6.1 | fortinet fortiauthenticator An improper neutralization of input during web page generation in FortiAuthenticator WEB UI 6.0.0 may allow an unauthenticated user to perform a cross-site scripting attack (XSS) via a parameter of the logon page. | 0,7% | — |
| CVE-2009-0028 | LOW 2.1 | linux linux_kernel The clone system call in the Linux kernel 2.6.28 and earlier allows local users to send arbitrary signals to a parent process from an unprivileged child process by launching an additional child process with the CLONE_PARENT flag, and then letting this new proc | 0,7% | — |
| CVE-2026-45583 | HIGH 7.5 | microsoft exchange_server Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network. | 0,7% | — |
| CVE-2025-47158 | CRIT 9.0 | microsoft azure_devops Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network. | 0,7% | — |
| CVE-2024-49052 | HIGH 8.2 | microsoft azure_functions Missing authentication for critical function in Microsoft Azure PolicyWatch allows an unauthorized attacker to elevate privileges over a network. | 0,7% | — |
| CVE-2024-29981 | MED 4.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability | 0,7% | — |
| CVE-2024-26954 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slab-out-of-bounds in smb_strndup_from_utf16() If ->NameOffset of smb2_create_req is smaller than Buffer offset of smb2_create_req, slab-out-of-bounds read can happen from smb2_op | 0,7% | — |
| CVE-2023-38734 | MED 6.6 | ibm robotic_process_automation IBM Robotic Process Automation 21.0.0 through 21.0.7.1 and 23.0.0 through 23.0.1 is vulnerable to incorrect privilege assignment when importing users from an LDAP directory. IBM X-Force ID: 262481. | 0,7% | — |
| CVE-2022-37971 | HIGH 7.1 | microsoft malware_protection_engine Microsoft Windows Defender Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2022-3566 | MED 4.6 | linux linux_kernel A vulnerability was identified in Linux Kernel up to 4.19.316/5.4.278/5.10.220/5.15.161. This impacts the function tcp_getsockopt/tcp_setsockopt of the component TCP Handler. Such manipulation leads to race condition. A high complexity level is associated with | 0,7% | — |
| CVE-2022-23831 | HIGH 7.5 | amd amd_uprof Insufficient validation of the IOCTL input buffer in AMD μProf may allow an attacker to send an arbitrary buffer leading to a potential Windows kernel crash resulting in denial of service. | 0,7% | — |