58.650 CVE seguite
799 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.650 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2022-21873 | HIGH 7.0 | microsoft windows_10 Tile Data Repository Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2022-21872 | HIGH 7.0 | microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2022-21870 | HIGH 7.0 | microsoft windows_10 Tablet Windows User Interface Application Core Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2022-20952 | MED 5.3 | cisco asyncos A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA), could allow an unauthenticated, remote attacker to bypass a configured rule, thereby allowing traffic onto a | 0,7% | — |
| CVE-2019-7222 | MED 5.5 | canonical ubuntu_linux The KVM implementation in the Linux kernel through 4.20.5 has an Information Leak. | 0,7% | — |
| CVE-2018-0408 | MED 5.4 | cisco sf300-08_firmware A vulnerability in the web-based management interface of Cisco Small Business 300 Series (Sx300) Managed Switches could allow an authenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based management | 0,7% | — |
| CVE-2018-0407 | MED 5.4 | cisco sf300-08_firmware A vulnerability in the web-based management interface of Cisco Small Business 300 Series (Sx300) Managed Switches could allow an authenticated, remote attacker to conduct a persistent cross-site scripting (XSS) attack against a user of the web-based management | 0,7% | — |
| CVE-2014-7991 | MED 4.3 | cisco unified_communications_manager The Remote Mobile Access Subsystem in Cisco Unified Communications Manager (CM) 10.0(1) and earlier does not properly validate the Subject Alternative Name (SAN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof VCS core devices | 0,7% | — |
| CVE-2013-0346 | LOW 2.1 | apache tomcat Apache Tomcat 7.x uses world-readable permissions for the log directory and its files, which might allow local users to obtain sensitive information by reading a file. NOTE: One Tomcat distributor has stated "The tomcat log directory does not contain any sensi | 0,7% | — |
| CVE-2026-62750 | MED 6.5 | microsoft windows_10_1607 Partial string comparison in Windows HTTP Protocol Stack allows an unauthorized attacker to perform tampering over an adjacent network. | 0,7% | — |
| CVE-2026-24304 | CRIT 9.9 | microsoft azure_resource_manager Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network. | 0,7% | — |
| CVE-2025-38488 | CRIT 9.8 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: smb: client: fix use-after-free in crypt_message when using async crypto The CVE-2024-50047 fix removed asynchronous crypto handling from crypt_message(), assuming all crypto operations are | 0,7% | — |
| CVE-2023-36705 | HIGH 7.8 | microsoft windows_10_1507 Windows Installer Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2023-33834 | MED 4.3 | ibm security_verify_information_queue IBM Security Verify Information Queue 10.0.4 and 10.0.5 could allow a remote attacker to obtain sensitive information that could aid in further attacks against the system. IBM X-force ID: 256014. | 0,7% | — |
| CVE-2022-49356 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Trap RDMA segment overflows Prevent svc_rdma_build_writes() from walking off the end of a Write chunk's segment array. Caught with KASAN. The test that this fix replaces is invalid, | 0,7% | — |
| CVE-2022-40748 | MED 5.4 | ibm infosphere_information_server IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trust | 0,7% | — |
| CVE-2022-35721 | MED 5.4 | ibm jazz_for_service_management IBM Jazz for Service Management 1.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a | 0,7% | — |
| CVE-2022-33683 | MED 5.9 | apache pulsar Apache Pulsar Brokers and Proxies create an internal Pulsar Admin Client that does not verify peer TLS certificates, even when tlsAllowInsecureConnection is disabled via configuration. The Pulsar Admin Client's intra-cluster and geo-replication HTTPS connectio | 0,7% | — |
| CVE-2022-29060 | HIGH 8.1 | fortinet fortiddos A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiDDoS API 5.5.0 through 5.5.1, 5.4.0 through 5.4.2, 5.3.0 through 5.3.1, 5.2.0, 5.1.0 may allow an attacker who managed to retrieve the key from one device to sign JWT tokens for any device. | 0,7% | — |
| CVE-2022-24544 | HIGH 7.8 | microsoft windows_10 Windows Kerberos Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2022-21845 | MED 4.7 | microsoft windows_10 Windows Kernel Information Disclosure Vulnerability | 0,7% | — |
| CVE-2021-47486 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: riscv, bpf: Fix potential NULL dereference The bpf_jit_binary_free() function requires a non-NULL argument. When the RISC-V BPF JIT fails to converge in NR_JIT_ITERATIONS steps, jit_data->he | 0,7% | — |
| CVE-2021-28438 | MED 5.5 | microsoft windows_10 Windows Console Driver Denial of Service Vulnerability | 0,7% | — |
| CVE-2021-1477 | MED 4.3 | cisco secure_firewall_management_center A vulnerability in an access control mechanism of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to access services beyond the scope of their authorization. This vulnerability is due to insufficient enforcement o | 0,7% | — |
| CVE-2019-6639 | MED 4.8 | f5 big-ip_advanced_firewall_manager On BIG-IP (AFM, PEM) 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.1-11.5.8, an undisclosed TMUI pages for AFM and PEM Subscriber management are vulnerable to a stored cross-site scripting (XSS) issue. This is a co | 0,7% | — |