EN
58.650 CVE seguite
798 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.650 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più alto In KEV dal, ordina dal più alto
CVE-2026-73635 HIGH 7.5 apache struts Allocation of resources without limits or throttling vulnerability in Apache Struts. When no fixed locale is configured, the locale used for localized-text lookups is taken from the incoming request, allowing an unauthenticated remote client to cause the frame 0,7% —
CVE-2026-73633 HIGH 7.5 apache struts Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts. When an application is configured to populate actions from a JSON request body, the plugin reads that body into memory without bounding how much it will accept, so a single re 0,7% —
CVE-2025-47956 MED 5.5 microsoft windows_security_app External control of file name or path in Windows Security App allows an authorized attacker to perform spoofing locally. 0,7% —
CVE-2025-24084 HIGH 8.4 microsoft windows_11_22h2 Untrusted pointer dereference in Windows Subsystem for Linux allows an unauthorized attacker to execute code locally. 0,7% —
CVE-2025-21341 MED 6.6 microsoft windows_10_1507 Windows Digital Media Elevation of Privilege Vulnerability 0,7% —
CVE-2025-20152 HIGH 8.6 cisco identity_services_engine A vulnerability in the RADIUS message processing feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handli 0,7% —
CVE-2023-35351 MED 6.6 microsoft windows_server_2008 Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability 0,7% —
CVE-2023-35346 MED 6.6 microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability 0,7% —
CVE-2023-35345 MED 6.6 microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability 0,7% —
CVE-2023-35344 MED 6.6 microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability 0,7% —
CVE-2021-34514 HIGH 7.8 microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability 0,7% —
CVE-2019-6696 MED 6.1 fortinet fortios An improper input validation vulnerability in FortiOS 6.2.1, 6.2.0, 6.0.8 and below until 5.4.0 under admin webUI may allow an attacker to perform an URL redirect attack via a specifically crafted request to the admin initial password change webpage. 0,7% —
CVE-2019-3701 MED 4.4 canonical ubuntu_linux An issue was discovered in can_can_gw_rcv in net/can/gw.c in the Linux kernel through 4.19.13. The CAN frame modification rules allow bitwise logical operations that can be also applied to the can_dlc field. The privileged user "root" with CAP_NET_ADMIN can cr 0,7% —
CVE-2019-1764 HIGH 8.1 cisco ip_conference_phone_8832_firmware A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack. The vulnerability is due t 0,7% —
CVE-2019-16154 MED 6.1 fortinet fortiauthenticator An improper neutralization of input during web page generation in FortiAuthenticator WEB UI 6.0.0 may allow an unauthenticated user to perform a cross-site scripting attack (XSS) via a parameter of the logon page. 0,7% —
CVE-2009-0028 LOW 2.1 linux linux_kernel The clone system call in the Linux kernel 2.6.28 and earlier allows local users to send arbitrary signals to a parent process from an unprivileged child process by launching an additional child process with the CLONE_PARENT flag, and then letting this new proc 0,7% —
CVE-2026-45583 HIGH 7.5 microsoft exchange_server Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network. 0,7% —
CVE-2025-47158 CRIT 9.0 microsoft azure_devops Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network. 0,7% —
CVE-2024-49052 HIGH 8.2 microsoft azure_functions Missing authentication for critical function in Microsoft Azure PolicyWatch allows an unauthorized attacker to elevate privileges over a network. 0,7% —
CVE-2024-29981 MED 4.3 microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability 0,7% —
CVE-2024-26954 HIGH 8.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slab-out-of-bounds in smb_strndup_from_utf16() If ->NameOffset of smb2_create_req is smaller than Buffer offset of smb2_create_req, slab-out-of-bounds read can happen from smb2_op 0,7% —
CVE-2023-38734 MED 6.6 ibm robotic_process_automation IBM Robotic Process Automation 21.0.0 through 21.0.7.1 and 23.0.0 through 23.0.1 is vulnerable to incorrect privilege assignment when importing users from an LDAP directory. IBM X-Force ID: 262481. 0,7% —
CVE-2022-37971 HIGH 7.1 microsoft malware_protection_engine Microsoft Windows Defender Elevation of Privilege Vulnerability 0,7% —
CVE-2022-3566 MED 4.6 linux linux_kernel A vulnerability was identified in Linux Kernel up to 4.19.316/5.4.278/5.10.220/5.15.161. This impacts the function tcp_getsockopt/tcp_setsockopt of the component TCP Handler. Such manipulation leads to race condition. A high complexity level is associated with 0,7% —
CVE-2022-23831 HIGH 7.5 amd amd_uprof Insufficient validation of the IOCTL input buffer in AMD μProf may allow an attacker to send an arbitrary buffer leading to a potential Windows kernel crash resulting in denial of service. 0,7% —