58.441 CVE seguite
792 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.441 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più basso | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-69402 | HIGH 7.3 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 0,4% | — |
| CVE-2026-59275 | MED 6.6 | vmware spring_advanced_message_queuing_protocol A single hostile AMQP message can terminate the entire consumer JVM (System.exit(99)), not just the listener thread — full availability loss for every workload co-located in that process. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 S | 0,4% | — |
| CVE-2026-58300 | MED 6.2 | microsoft edge_chromium Absolute path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-55045 | HIGH 8.4 | microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2026-47288 | HIGH 7.1 | microsoft windows_server_2012 Integer overflow or wraparound in Windows Kerberos allows an authorized attacker to execute code over an adjacent network. | 0,4% | — |
| CVE-2026-45458 | HIGH 8.4 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2026-45456 | HIGH 8.4 | microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2026-40367 | HIGH 8.4 | microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2026-23902 | HIGH 8.1 | apache dolphinscheduler Incorrect Authorization vulnerability in Apache DolphinScheduler allows authenticated users with system login permissions to use tenants that are not defined on the platform during workflow execution. This issue affects Apache DolphinScheduler versions prior | 0,4% | — |
| CVE-2026-20329 | CRIT 9.9 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has cond | 0,4% | — |
| CVE-2026-20194 | CRIT 9.1 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), engineering teams have conducted a comprehensive internal security review. This review | 0,4% | — |
| CVE-2025-43574 | HIGH 7.8 | adobe acrobat Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction i | 0,4% | — |
| CVE-2025-43573 | HIGH 7.8 | adobe acrobat Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction i | 0,4% | — |
| CVE-2025-20376 | MED 6.5 | cisco unified_contact_center_express A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to upload and execute arbitrary files. This vulnerability is due to an insufficient input validation associated to file upload mechanisms. An attacker could exp | 0,4% | — |
| CVE-2024-56717 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: mscc: ocelot: fix incorrect IFH SRC_PORT field in ocelot_ifh_set_basic() Packets injected by the CPU should have a SRC_PORT field equal to the CPU port module index in the Analyzer bloc | 0,4% | — |
| CVE-2024-50568 | MED 5.9 | fortinet fortios A channel accessible by non-endpoint vulnerability [CWE-300] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7 and before 7.0.14 & FortiProxy version 7.4.0 through 7.4.3, 7.2.0 through 7.2.9 and before 7.0.16 allows an unauthenticated attack | 0,4% | — |
| CVE-2024-49046 | HIGH 7.8 | microsoft windows_10_1507 Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability | 0,4% | — |
| CVE-2024-40910 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ax25: Fix refcount imbalance on inbound connections When releasing a socket in ax25_release(), we call netdev_put() to decrease the refcount on the associated ax.25 device. However, the exec | 0,4% | — |
| CVE-2024-33506 | LOW 3.3 | fortinet fortimanager An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiManager 7.4.2 and below, 7.2.5 and below, 7.0.12 and below allows a remote authenticated attacker assigned to an Administrative Domain (ADOM) to access device summary | 0,4% | — |
| CVE-2023-20205 | MED 5.4 | cisco evolved_programmable_network_manager Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a use | 0,4% | — |
| CVE-2023-20204 | MED 5.4 | cisco broadworks_application_delivery_platform A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists | 0,4% | — |
| CVE-2023-20203 | MED 5.4 | cisco evolved_programmable_network_manager Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a use | 0,4% | — |
| CVE-2023-20132 | MED 5.4 | cisco webex_meetings Multiple vulnerabilities in the web interface of Cisco Webex Meetings could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack or upload arbitrary files as recordings. For more information about these vulnerabilities, | 0,4% | — |
| CVE-2022-2991 | MED 6.7 | linux linux_kernel A heap-based buffer overflow was found in the Linux kernel's LightNVM subsystem. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. This vulnerability allows a local | 0,4% | — |
| CVE-2022-20945 | HIGH 7.4 | cisco catalyst_9800-40_firmware A vulnerability in the 802.11 association frame validation of Cisco Catalyst 9100 Series Access Points (APs) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insu | 0,4% | — |