58.535 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.535 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più basso | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2023-28962 | MED 5.3 | juniper junos An Improper Authentication vulnerability in upload-file.php, used by the J-Web component of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to upload arbitrary files to temporary folders on the device. This issue affects Juniper Net | 0,6% | — |
| CVE-2023-22396 | HIGH 7.5 | juniper junos An Uncontrolled Resource Consumption vulnerability in TCP processing on the Routing Engine (RE) of Juniper Networks Junos OS allows an unauthenticated network-based attacker to send crafted TCP packets destined to the device, resulting in an MBUF leak that ult | 0,6% | — |
| CVE-2022-29057 | MED 5.4 | fortinet fortiedr A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiEDR version 5.1.0, 5.0.0 through 5.0.3 Patch 6 and 4.0.0 allows a remote authenticated attacker to perform a reflected cross site scripting attack (XSS) by | 0,6% | — |
| CVE-2021-40832 | MED 5.5 | f-secure atlant A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the AVRDL unpacking module component used in certain F-Secure products can crash while scanning a fuzzed files. The exploit can be triggered remotely by an attacker. A successful | 0,6% | — |
| CVE-2021-40455 | MED 5.5 | microsoft windows_10 Windows Installer Spoofing Vulnerability | 0,6% | — |
| CVE-2021-33603 | MED 5.5 | f-secure atlant A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the AVPACK module component used in certain F-Secure products can crash while scanning a fuzzed files. The exploit can be triggered remotely by an attacker. A successful attack w | 0,6% | — |
| CVE-2021-27088 | HIGH 7.8 | microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2021-24005 | MED 4.0 | fortinet fortiauthenticator Usage of hard-coded cryptographic keys to encrypt configuration files and debug logs in FortiAuthenticator versions before 6.3.0 may allow an attacker with access to the files or the CLI configuration to decrypt the sensitive data, via knowledge of the hard-co | 0,6% | — |
| CVE-2021-22000 | HIGH 7.8 | vmware thinapp VMware Thinapp version 5.x prior to 5.2.10 contain a DLL hijacking vulnerability due to insecure loading of DLLs. A malicious actor with non-administrative privileges may exploit this vulnerability to elevate privileges to administrator level on the Windows op | 0,6% | — |
| CVE-2020-14331 | MED 6.6 | linux linux_kernel A flaw was found in the Linux kernel’s implementation of the invert video code on VGA consoles when a local attacker attempts to resize the console, calling an ioctl VT_RESIZE, which causes an out-of-bounds write to occur. This flaw allows a local user with ac | 0,6% | — |
| CVE-2019-17653 | HIGH 8.8 | fortinet fortisiem A Cross-Site Request Forgery (CSRF) vulnerability in the user interface of Fortinet FortiSIEM 5.2.5 could allow a remote, unauthenticated attacker to perform arbitrary actions using an authenticated user's session by persuading the victim to follow a malicious | 0,6% | — |
| CVE-2015-7513 | MED 6.5 | canonical ubuntu_linux arch/x86/kvm/x86.c in the Linux kernel before 4.4 does not reset the PIT counter values during state restoration, which allows guest OS users to cause a denial of service (divide-by-zero error and host OS crash) via a zero value, related to the kvm_vm_ioctl_se | 0,6% | — |
| CVE-2026-81866 | MED 4.3 | apache nifi Apache NiFi 2.9.0 through 2.11.0 provide Connector configuration update and verification REST API methods that do not enforce authorization checking on Assets and Secrets referenced in proposed configuration. Updating or verifying a Connector configuration ste | 0,6% | — |
| CVE-2026-59313 | CRIT 9.8 | vmware spring_framework Spring MVC applications using the functional web framework are vulnerable to stream corruption when using Server-Sent Events (SSE). Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 S | 0,6% | — |
| CVE-2026-47890 | CRIT 9.8 | vmware spring_framework Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fragments. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 | 0,6% | — |
| CVE-2026-42797 | MED 4.9 | apache syncope Exposure of Sensitive Information Through Data Queries vulnerability in Apache Syncope. An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficient entitlements for User | 0,6% | — |
| CVE-2026-20835 | MED 5.5 | microsoft windows_11_24h2 Out-of-bounds read in Capability Access Management Service (camsvc) allows an authorized attacker to disclose information locally. | 0,6% | — |
| CVE-2026-20829 | MED 5.5 | microsoft windows_10_1809 Out-of-bounds read in Windows TPM allows an authorized attacker to disclose information locally. | 0,6% | — |
| CVE-2025-53844 | HIGH 8.8 | fortinet fortios A out-of-bounds write vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11 allows attacker to execute unauthorized code or commands via specially crafted packets. | 0,6% | — |
| CVE-2025-26631 | HIGH 7.3 | microsoft visual_studio_code Uncontrolled search path element in Visual Studio Code allows an authorized attacker to elevate privileges locally. | 0,6% | — |
| CVE-2025-21378 | HIGH 7.8 | microsoft windows_10_1507 Windows CSC Service Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2024-53095 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: client: Fix use-after-free of network namespace. Recently, we got a customer report that CIFS triggers oops while reconnecting to a server. [0] The workload runs on Kubernetes, and so | 0,6% | — |
| CVE-2024-50185 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mptcp: handle consistently DSS corruption Bugged peer implementation can send corrupted DSS options, consistently hitting a few warning in the data path. Use DEBUG_NET assertions, to avoid t | 0,6% | — |
| CVE-2024-44970 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: SHAMPO, Fix invalid WQ linked list unlink When all the strides in a WQE have been consumed, the WQE is unlinked from the WQ linked list (mlx5_wq_ll_pop()). For SHAMPO, it is possi | 0,6% | — |
| CVE-2023-4147 | HIGH 7.8 | debian debian_linux A use-after-free flaw was found in the Linux kernel’s Netfilter functionality when adding a rule with NFTA_RULE_CHAIN_ID. This flaw allows a local user to crash or escalate their privileges on the system. | 0,6% | — |