EN
58.352 CVE seguite
790 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.352 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più alto In KEV dal, ordina dal più alto
CVE-2026-62815 CRIT 9.8 microsoft windows_11_23h2 Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. 1,2% —
CVE-2025-21253 MED 5.3 microsoft edge Microsoft Edge for IOS and Android Spoofing Vulnerability 1,2% —
CVE-2023-36722 MED 4.4 microsoft windows_10_1507 Active Directory Domain Services Information Disclosure Vulnerability 1,2% —
CVE-2004-0424 HIGH 7.2 linux linux_kernel Integer overflow in the ip_setsockopt function in Linux kernel 2.4.22 through 2.4.25 and 2.6.1 through 2.6.3 allows local users to cause a denial of service (crash) or execute arbitrary code via the MCAST_MSFILTER socket option. 1,2% —
CVE-2024-45498 HIGH 8.8 apache airflow Example DAG: example_inlet_event_extra.py shipped with Apache Airflow version 2.10.0 has a vulnerability that allows an authenticated attacker with only DAG trigger permission to execute arbitrary commands. If you used that example as the base of your DAGs - p 1,2% —
CVE-2022-20816 MED 6.5 cisco unified_communications_manager A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to delete arbitrary fi 1,2% —
CVE-2020-16982 MED 6.1 microsoft azure_sphere Azure Sphere Unsigned Code Execution Vulnerability 1,2% —
CVE-2019-0775 MED 4.7 microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0702, CVE-2019-0755, CVE-2019-0767, CVE-2019-0782. 1,2% —
CVE-2017-5073 HIGH 8.8 google chrome Use after free in print preview in Blink in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. 1,2% —
CVE-2017-5056 HIGH 8.8 google chrome A use after free in Blink in Google Chrome prior to 57.0.2987.133 for Linux, Windows, and Mac, and 57.0.2987.132 for Android, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. 1,2% —
CVE-2017-4928 HIGH 7.5 vmware vcenter_server The flash-based vSphere Web Client (6.0 prior to 6.0 U3c and 5.5 prior to 5.5 U3f) i.e. not the new HTML5-based vSphere Client, contains SSRF and CRLF injection issues due to improper neutralization of URLs. An attacker may exploit these issues by sending a PO 1,2% —
CVE-2017-2310 MED 5.3 juniper junos_space A firewall bypass vulnerability in the host based firewall of Juniper Networks Junos Space versions prior to 16.1R1 may permit certain crafted packets, representing a network integrity risk. 1,2% —
CVE-2016-5021 MED 4.9 f5 big-ip_access_policy_manager The iControl REST service in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.5.x before 11.5.4, 11.6.x before 11.6.1, and 12.x before 12.0.0 HF3; BIG-IP DNS 12.x before 12.0.0 HF3; BIG-IP GTM 11.5.x before 11.5.4 and 11.6.x before 11. 1,2% —
CVE-2013-3474 MED 6.3 cisco wireless_lan_controller The Web Administrator Interface on Cisco Wireless LAN Controller (WLC) devices allows remote authenticated users to cause a denial of service (device crash) by leveraging membership in the Full Manager managers group, Read Only managers group, or Lobby Ambassa 1,2% —
CVE-2023-32038 HIGH 8.8 microsoft windows_10_1507 Microsoft ODBC Driver Remote Code Execution Vulnerability 1,2% —
CVE-2018-5542 HIGH 8.1 f5 big-ip_access_policy_manager F5 BIG-IP 13.0.0-13.0.1, 12.1.0-12.1.3.6, or 11.2.1-11.6.3.2 HTTPS health monitors do not validate the identity of the monitored server. 1,2% —
CVE-2024-43600 HIGH 7.8 microsoft office Microsoft Office Elevation of Privilege Vulnerability 1,2% —
CVE-2021-33768 HIGH 8.0 microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability 1,2% —
CVE-2020-8190 HIGH 7.5 citrix application_delivery_controller_firmware Incorrect file permissions in Citrix ADC and Citrix Gateway before versions 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 allows privilege escalation. 1,2% —
CVE-2020-3238 HIGH 8.1 cisco iox A vulnerability in the Cisco Application Framework component of the Cisco IOx application environment could allow an authenticated, remote attacker to write or modify arbitrary files in the virtual instance that is running on the affected device. The vulnerabi 1,2% —
CVE-2020-0904 MED 6.5 microsoft windows_10 <p>A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate specific malicious data from a user on a guest operating system.</p> <p>To exploit the vulnerability, an attacker who already has a privileged accoun 1,2% —
CVE-2020-0886 HIGH 7.8 microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Storage Services improperly handle file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges.</p> <p>To exploit the vulnerability, an attacker wo 1,2% —
CVE-2024-5914 CRIT 9.8 paloaltonetworks cortex_xsoar_commonscripts A command injection issue in Palo Alto Networks Cortex XSOAR CommonScripts Pack allows an unauthenticated attacker to execute arbitrary commands within the context of an integration container. 1,2% —
CVE-2024-49050 HIGH 8.8 microsoft python Visual Studio Code Python Extension Remote Code Execution Vulnerability 1,2% —
CVE-2024-21326 CRIT 9.6 microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 1,2% —