58.650 CVE seguite
799 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.650 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2011-0570 | MED 6.9 | adobe acrobat Untrusted search path vulnerability in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows allows local users to gain privileges via a Trojan horse DLL in the current working directory, a different vulnerability than | 0,6% | — |
| CVE-2003-0462 | LOW 1.2 | linux linux_kernel A race condition in the way env_start and env_end pointers are initialized in the execve system call and used in fs/proc/base.c on Linux 2.4 allows local users to cause a denial of service (crash). | 0,6% | — |
| CVE-2026-69679 | MED 5.7 | microsoft windows_10_1607 Out-of-bounds read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network. | 0,6% | — |
| CVE-2026-69637 | MED 5.7 | microsoft windows_10_1607 Out-of-bounds read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network. | 0,6% | — |
| CVE-2026-69416 | MED 5.7 | microsoft windows_10_1607 Buffer over-read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network. | 0,6% | — |
| CVE-2026-69405 | MED 5.7 | microsoft windows_10_1607 Missing release of memory after effective lifetime in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network. | 0,6% | — |
| CVE-2026-48895 | HIGH 7.2 | apache apisix URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The attacker could manipulate some client headers to perform an open-redirect, to potentially expose the session token. This issue affects Apache APISIX: from 3.0.0 through 3 | 0,6% | — |
| CVE-2026-44913 | HIGH 7.2 | apache nifi Improper escaping of database table names in the CaptureChangeMySQL Processor included with Apache NiFi 1.2.0 through 2.9.0 allows for injecting SQL commands using crafted naming. Manual quoted boundaries added in Apache NiFi 1.8.0 narrowed the scope of potent | 0,6% | — |
| CVE-2026-42498 | HIGH 7.3 | apache tomcat Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.2 through 9.0.117, from 8.5.2 | 0,6% | — |
| CVE-2026-41731 | HIGH 8.1 | redhat fuse JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all of its subpackages. Combined with Jackson's default bean deserializat | 0,6% | — |
| CVE-2026-23980 | MED 6.5 | apache superset Improper Neutralization of Special Elements used in a SQL Command ('SQL Injection') vulnerability in Apache Superset allows an authenticated user with read access to conduct error-based SQL injection via the sqlExpression or where parameters. This issue affec | 0,6% | — |
| CVE-2025-48208 | HIGH 8.8 | apache hertzbeat Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache HertzBeat . The attacker needs to have an authenticated account with access, and the attack can only be triggered by crafting custom comman | 0,6% | — |
| CVE-2025-30377 | HIGH 8.4 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 0,6% | — |
| CVE-2024-43513 | MED 6.4 | microsoft windows_10_1507 BitLocker Security Feature Bypass Vulnerability | 0,6% | — |
| CVE-2024-42110 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: ntb_netdev: Move ntb_netdev_rx_handler() to call netif_rx() from __netif_rx() The following is emitted when using idxd (DSA) dmanegine as the data mover for ntb_transport that ntb_netde | 0,6% | — |
| CVE-2024-41169 | HIGH 7.5 | apache zeppelin The attacker can use the raft server protocol in an unauthenticated way. The attacker can see the server's resources, including directories and files. This issue affects Apache Zeppelin: from 0.10.1 up to 0.12.0. Users are recommended to upgrade to version 0 | 0,6% | — |
| CVE-2024-37973 | HIGH 8.8 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 0,6% | — |
| CVE-2024-28916 | HIGH 8.8 | microsoft xbox_gaming_services Xbox Gaming Services Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2022-20677 | MED 5.5 | cisco ios Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system | 0,6% | — |
| CVE-2021-33784 | HIGH 7.8 | microsoft windows_10 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2021-32587 | MED 4.3 | fortinet fortianalyzer An improper access control vulnerability in FortiManager and FortiAnalyzer GUI interface 7.0.0, 6.4.5 and below, 6.2.8 and below, 6.0.11 and below, 5.6.11 and below may allow a remote and authenticated attacker with restricted user profile to retrieve the list | 0,6% | — |
| CVE-2020-24440 | HIGH 7.0 | adobe prelude Adobe Prelude version 9.0.1 (and earlier) is affected by an uncontrolled search path element that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a mal | 0,6% | — |
| CVE-2020-15939 | MED 4.3 | fortinet fortisandbox An improper access control vulnerability (CWE-284) in FortiSandbox versions 3.2.1 and below and 3.1.4 and below may allow an authenticated, unprivileged attacker to download the device configuration file via the recovery URL. | 0,6% | — |
| CVE-2019-19165 | HIGH 7.2 | inogard activex AxECM.cab(ActiveX Control) in Inogard Ebiz4u contains a vulnerability that could allow remote files to be downloaded and executed by setting arguments to the activeX method. Download of Code Without Integrity Check vulnerability in ActiveX control of Inogard C | 0,6% | — |
| CVE-2019-1849 | HIGH 7.4 | cisco ios_xr A vulnerability in the Border Gateway Patrol (BGP) Multiprotocol Label Switching (MPLS)-based Ethernet VPN (EVPN) implementation of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to trigger a denial of service (DoS) condition on an aff | 0,6% | — |