EN
58.650 CVE seguite
798 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.650 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più alto In KEV dal, ordina dal più alto
CVE-2023-28296 HIGH 7.8 microsoft visual_studio_2017 Visual Studio Remote Code Execution Vulnerability 0,7% —
CVE-2023-20042 MED 6.8 cisco adaptive_security_appliance_software A vulnerability in the AnyConnect SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected 0,7% —
CVE-2022-21967 HIGH 7.0 microsoft windows_10 Xbox Live Auth Manager for Windows Elevation of Privilege Vulnerability 0,7% —
CVE-2021-39063 CRIT 9.1 ibm spectrum_protect_plus IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information due to a misconfiguration in access control headers. IBM X-Force ID: 0,7% —
CVE-2021-29773 MED 5.4 ibm security_guardium IBM Security Guardium 10.6 and 11.3 could allow a remote authenticated attacker to obtain sensitive information or modify user details caused by an insecure direct object vulnerability (IDOR). IBM X-Force ID: 202865. 0,7% —
CVE-2020-5905 MED 4.3 f5 big-ip_access_policy_manager In version 11.6.1-11.6.5.2 of the BIG-IP system Configuration utility Network > WCCP page, the system does not sanitize all user-provided data before display. 0,7% —
CVE-2020-3199 HIGH 8.8 cisco ios Multiple vulnerabilities in the Cisco IOx application environment of Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) and Cisco 1000 Series Connected Grid Routers (CGR1000) that are running Cisco IOS Software could allow an attacker t 0,7% —
CVE-2026-64394 HIGH 8.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: add a WRITE_DAC/WRITE_OWNER check to SMB2 SET_INFO SECURITY commit cc57232cae23 ("ksmbd: fix FSCTL permission bypass by adding a permission check for FSCTL_SET_SPARSE") added a fp->da 0,7% —
CVE-2026-41699 HIGH 8.1 vmware spring_for_graphql Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. An attacker can craft a malicious GraphQL request that can lead to Remote Code Execution when the application exposes a paginated (Connection) f 0,7% —
CVE-2026-25180 MED 5.5 microsoft 365_copilot Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to disclose information locally. 0,7% —
CVE-2025-33211 HIGH 7.5 nvidia triton_inference_server NVIDIA Triton Server for Linux contains a vulnerability where an attacker may cause an improper validation of specified quantity in input. A successful exploit of this vulnerability may lead to denial of service. 0,7% —
CVE-2023-36701 HIGH 7.8 microsoft windows_10_1507 Microsoft Resilient File System (ReFS) Elevation of Privilege Vulnerability 0,7% —
CVE-2023-24896 MED 5.4 microsoft dynamics_365 Dynamics 365 Finance Spoofing Vulnerability 0,7% —
CVE-2022-36772 MED 6.5 ibm infosphere_information_server IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information that should only be available to a privileged user. 0,7% —
CVE-2022-31739 HIGH 8.8 mozilla firefox When downloading files on Windows, the % character was not escaped, which could have lead to a download incorrectly being saved to attacker-influenced paths that used variables such as %HOMEPATH% or %APPDATA%.<br>*This bug only affects Firefox for Windows. Oth 0,7% —
CVE-2022-22329 MED 4.3 ibm control_desk IBM Control Desk 7.6.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent 0,7% —
CVE-2022-21871 HIGH 7.0 microsoft visual_studio_2017 Microsoft Diagnostics Hub Standard Collector Runtime Elevation of Privilege Vulnerability 0,7% —
CVE-2020-8428 HIGH 7.1 linux linux_kernel fs/namei.c in the Linux kernel before 5.5 has a may_create_in_sticky use-after-free, which allows local users to cause a denial of service (OOPS) or possibly obtain sensitive information from kernel memory, aka CID-d0cb50185ae9. One attack vector may be an ope 0,7% —
CVE-2019-15217 MED 4.6 canonical ubuntu_linux An issue was discovered in the Linux kernel before 5.2.3. There is a NULL pointer dereference caused by a malicious USB device in the drivers/media/usb/zr364xx/zr364xx.c driver. 0,7% —
CVE-2017-12341 MED 6.7 cisco nx-os A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. An attacker would need valid administrator credentials to perform this exploit. The vulnerability is due to insufficie 0,7% —
CVE-2013-0248 MED 6.8 apache commons_fileupload The default configuration of javax.servlet.context.tempdir in Apache Commons FileUpload 1.0 through 1.2.2 uses the /tmp directory for uploaded files, which allows local users to overwrite arbitrary files via an unspecified symlink attack. 0,7% —
CVE-2012-4001 MED 5.0 google mod_pagespeed The mod_pagespeed module before 0.10.22.6 for the Apache HTTP Server does not properly verify its host name, which allows remote attackers to trigger HTTP requests to arbitrary hosts via unspecified vectors, as demonstrated by requests to intranet servers. 0,7% —
CVE-2026-52760 MED 6.1 apache activemq Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web Console. The browse page in the web console renders a message Id directly without sanitization. This allows an authentic 0,7% —
CVE-2026-42253 MED 6.1 apache activemq Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web. The MessageServlet in the ActiveMQ web console API copies every JMS message property into an HTTP response header witho 0,7% —
CVE-2026-33414 HIGH 7.8 podman_project podman Podman is a tool for managing OCI containers and pods. Versions 4.8.0 through 5.8.1 contain a command injection vulnerability in the HyperV machine backend in pkg/machine/hyperv/stubber.go, where the VM image path is inserted into a PowerShell double-quoted st 0,7% —