EN
58.650 CVE seguite
799 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.650 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più alto In KEV dal, ordina dal più alto
CVE-2022-21914 HIGH 7.8 microsoft windows_10 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability 0,7% —
CVE-2022-21885 HIGH 7.8 microsoft windows_10 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability 0,7% —
CVE-2022-21884 HIGH 7.8 microsoft windows_server Local Security Authority Subsystem Service Elevation of Privilege Vulnerability 0,7% —
CVE-2022-21835 HIGH 7.8 microsoft windows_10 Microsoft Cryptographic Services Elevation of Privilege Vulnerability 0,7% —
CVE-2026-42527 HIGH 8.1 apache camel Deserialization of Untrusted Data vulnerability in Apache Camel. The default ObjectInputFilter pattern shipped with several Apache Camel components for defense-in-depth deserialization filtering ('java.**;javax.**;org.apache.camel.**;!*', or the no-'javax.**' 0,7% —
CVE-2026-31378 MED 6.5 apache ofbiz Improper Input Validation vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue. 0,7% —
CVE-2026-24266 MED 5.9 nvidia triton_inference_server NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a use-after-free issue. A successful exploit of this vulnerability might lead to denial of service. 0,7% —
CVE-2024-41783 CRIT 9.1 ibm sterling_secure_proxy IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow a privileged user to inject commands into the underlying operating system due to improper validation of a specified type of input. 0,7% —
CVE-2024-20459 MED 6.5 cisco ata_191_firmware A vulnerability in the web-based management interface of Cisco ATA 190 Multiplatform Series Analog Telephone Adapter firmware could allow an authenticated, remote attacker with high privileges to execute arbitrary commands as the root user on the underlying op 0,7% —
CVE-2023-32016 MED 5.5 microsoft windows_10_1507 Windows Installer Information Disclosure Vulnerability 0,7% —
CVE-2023-29341 HIGH 7.8 microsoft av1_video_extension AV1 Video Extension Remote Code Execution Vulnerability 0,7% —
CVE-2023-29340 HIGH 7.8 microsoft av1_video_extension AV1 Video Extension Remote Code Execution Vulnerability 0,7% —
CVE-2023-24905 HIGH 7.8 microsoft windows_10_20h2 Remote Desktop Client Remote Code Execution Vulnerability 0,7% —
CVE-2023-22285 HIGH 7.5 intel unison_software Improper access control for some Intel Unison software may allow an unauthenticated user to potentially enable denial of service via network access. 0,7% —
CVE-2023-20270 MED 5.8 cisco secure_firewall_threat_defense A vulnerability in the interaction between the Server Message Block (SMB) protocol preprocessor and the Snort 3 detection engine for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the configured policies 0,7% —
CVE-2022-20691 MED 5.3 cisco ata_190_firmware A vulnerability in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Adaptive Telephone Adapter firmware could allow an unauthenticated, adjacent attacker to cause a DoS condition of an affected device. This vulnerability is due to missing l 0,7% —
CVE-2021-32603 HIGH 8.8 fortinet fortianalyzer A server-side request forgery (SSRF) (CWE-918) vulnerability in FortiManager and FortiAnalyser GUI 7.0.0, 6.4.5 and below, 6.2.7 and below, 6.0.11 and below, 5.6.11 and below may allow a remote and authenticated attacker to access unauthorized files and servic 0,7% —
CVE-2021-1255 MED 4.6 cisco data_center_network_manager Multiple vulnerabilities in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For more information about these vulnerabilities, see the 0,7% —
CVE-2020-25221 HIGH 7.8 linux linux_kernel get_gate_page in mm/gup.c in the Linux kernel 5.7.x and 5.8.x before 5.8.7 allows privilege escalation because of incorrect reference counting (caused by gate page mishandling) of the struct page that backs the vsyscall page. The result is a refcount underflow 0,7% —
CVE-2018-0006 MED 6.5 juniper junos A high rate of VLAN authentication attempts sent from an adjacent host on the local broadcast domain can trigger high memory utilization by the BBE subscriber management daemon (bbe-smgd), and lead to a denial of service condition. The issue was caused by atte 0,7% —
CVE-2011-2204 LOW 1.9 apache tomcat Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.17, when the MemoryUserDatabase is used, creates log entries containing passwords upon encountering errors in JMX user creation, which allows local users to obtain sensitive information b 0,7% —
CVE-2026-65128 HIGH 8.8 nvidia infra_controller NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause SQL injection. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure. 0,7% —
CVE-2026-62882 MED 4.3 microsoft 365_apps Insufficiently protected credentials in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network. 0,7% —
CVE-2026-20838 MED 5.5 microsoft windows_11_23h2 Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally. 0,7% —
CVE-2026-20827 MED 5.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to disclose information locally. 0,7% —