EN
58.650 CVE seguite
799 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.650 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più alto In KEV dal, ordina dal più alto
CVE-2024-50276 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: vertexcom: mse102x: Fix possible double free of TX skb The scope of the TX skb is wider than just mse102x_tx_frame_spi(), so in case the TX skb room needs to be expanded, we should free 0,7% —
CVE-2024-38173 MED 6.7 microsoft 365_apps Microsoft Outlook Remote Code Execution Vulnerability 0,7% —
CVE-2024-30394 HIGH 7.5 juniper junos A Stack-based Buffer Overflow vulnerability in the Routing Protocol Daemon (RPD) component of Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause an rpd crash, leading to Denial of Service (DoS). On all Junos OS and Junos 0,7% —
CVE-2024-29049 MED 4.1 microsoft edge_chromium Microsoft Edge (Chromium-based) Webview2 Spoofing Vulnerability 0,7% —
CVE-2022-4187 MED 6.5 google chrome Insufficient policy enforcement in DevTools in Google Chrome on Windows prior to 108.0.5359.71 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. (Chromium security severity: Medium) 0,7% —
CVE-2022-21900 MED 4.6 microsoft windows_10 Windows Hyper-V Security Feature Bypass Vulnerability 0,7% —
CVE-2021-42956 HIGH 7.8 zoho manageengine_remote_access_plus_server Zoho Remote Access Plus Server Windows Desktop Binary fixed in 10.1.2132.6 is affected by a sensitive information disclosure vulnerability. Due to improper privilege management, the process launches as the logged in user, so memory dump can be done by non-admi 0,7% —
CVE-2021-26603 HIGH 8.6 bandisoft ark_library A heap overflow issue was found in ARK library of bandisoft Co., Ltd when the Ark_DigPathA function parsed a file path. This vulnerability is due to missing support for string length check. 0,7% —
CVE-2020-3116 MED 5.5 cisco webex_meetings_online A vulnerability in the way Cisco Webex applications process Universal Communications Format (UCF) files could allow an attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient validation of UCF media files. An attacker co 0,7% —
CVE-2017-7339 MED 6.1 fortinet fortiportal A Cross-Site Scripting vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to execute unauthorized code or commands via the 'Name' and 'Description' inputs in the 'Add Revision Backup' functionality. 0,7% —
CVE-2016-1273 MED 5.9 juniper junos Juniper Junos OS before 13.2X51-D40, 14.x before 14.1X53-D30, and 15.x before 15.1X53-D20 on QFX5100 and QFX10002 switches do not have sufficient entropy, which makes it easier for remote attackers to defeat cryptographic encryption and authentication protecti 0,7% —
CVE-2026-72954 HIGH 7.5 microsoft windows_10_1607 Use after free in Windows Deployment Services allows an authorized attacker to execute code over a network. 0,7% —
CVE-2026-72943 HIGH 7.5 microsoft windows_10_1607 Use after free in Windows Deployment Services allows an authorized attacker to execute code over a network. 0,7% —
CVE-2026-72928 HIGH 7.5 microsoft windows_server_2025 Use after free in Windows DNS allows an authorized attacker to execute code over a network. 0,7% —
CVE-2026-70341 HIGH 8.5 microsoft edge Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network. 0,7% —
CVE-2026-69852 HIGH 7.5 microsoft windows_10_1607 Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine 0,7% —
CVE-2026-69599 HIGH 7.5 microsoft windows_11_23h2 Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network. 0,7% —
CVE-2026-69539 HIGH 7.5 microsoft windows_10_1607 Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network. 0,7% —
CVE-2026-69514 HIGH 7.5 microsoft windows_10_1607 Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to execute code over a network. 0,7% —
CVE-2026-69429 HIGH 7.5 microsoft windows_10_1809 Heap-based buffer overflow in Windows IKE Extension allows an authorized attacker to execute code over a network. 0,7% —
CVE-2026-67379 HIGH 8.5 microsoft sql_server_2019 Stack-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. 0,7% —
CVE-2026-62813 HIGH 7.5 microsoft windows_10_1607 Use after free in Active Directory Domain Services allows an authorized attacker to execute code over a network. 0,7% —
CVE-2026-62787 HIGH 7.5 microsoft windows_10_1607 Use after free in Windows DNS allows an authorized attacker to execute code over a network. 0,7% —
CVE-2026-52911 HIGH 8.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: scope conn->binding slowpath to bound sessions only When the binding SESSION_SETUP sets conn->binding = true, the flag stays set after the call so that the global session lookup in ks 0,7% —
CVE-2026-50685 HIGH 7.5 microsoft windows_10_1607 Double free in Windows DHCP Server allows an authorized attacker to execute code over a network. 0,7% —