EN
58.518 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.518 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordinato dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-1999-0331 HIGH 7.5 microsoft internet_explorer Buffer overflow in Internet Explorer 4.0(1). 5,0% —
CVE-1999-0293 HIGH 7.5 cisco ios AAA authentication on Cisco systems allows attackers to execute commands without authorization. 2,6% —
CVE-1999-0284 HIGH 7.5 ibm lotus_domino_mail_server Denial of service to NT mail servers including Ipswitch, Mdaemon, and Exchange through a buffer overflow in the SMTP HELO command. 11,5% —
CVE-1999-0280 HIGH 7.5 microsoft internet_explorer Remote command execution in Microsoft Internet Explorer using .lnk and .url files. 15,6% —
CVE-1999-0256 HIGH 7.5 jgaa warftpd Buffer overflow in War FTP allows remote execution of commands. 72,9% —
CVE-1999-0253 HIGH 7.5 microsoft internet_information_server IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a . (dot) in the URL. 8,0% —
CVE-1999-0236 HIGH 7.5 apache http_server ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs. 25,8% —
CVE-1999-0161 HIGH 7.5 cisco ios In Cisco IOS 10.3, with the tacacs-ds or tacacs keyword, an extended IP access control list could bypass filtering. 1,7% —
CVE-1999-0160 HIGH 7.5 cisco ios Some classic Cisco IOS devices have a vulnerability in the PPP CHAP authentication to establish unauthorized PPP connections. 1,2% —
CVE-1999-0071 HIGH 7.5 apache http_server Apache httpd cookie buffer overflow for versions 1.1.1 and earlier. 3,6% —
CVE-1999-0045 HIGH 7.5 apache http_server List of arbitrary files on Web host via nph-test-cgi script. 26,0% —
CVE-2026-91734 HIGH 7.4 google chrome Incorrect authorization in Core in Google Chrome on on Windows prior to 153.0.8010.47 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High) 0,1% —
CVE-2026-9006 HIGH 7.4 ibm websphere_application_server IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an attacker to send unauthorized requests from the system, resulting in a security bypass or information disclosure 0,4% —
CVE-2026-8646 HIGH 7.4 ibm websphere_application_server IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to HTTP request smuggling. A remote attacker could smuggle a specially crafted request to the application server thereby allowi 0,6% —
CVE-2026-84003 HIGH 7.4 microsoft azure\/msal-node Authentication bypass by capture-replay in Microsoft Authentication Library (MSAL) for Node.js allows an unauthorized attacker to perform spoofing over a network. 0,6% —
CVE-2026-81383 HIGH 7.4 microsoft visual_studio_code Use of incorrectly-resolved name or reference in Visual Studio Code allows an unauthorized attacker to disclose information over a network. 0,9% —
CVE-2026-78461 HIGH 7.4 microsoft visual_studio_code Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. 1,0% —
CVE-2026-78254 HIGH 7.4 apache ant The ftp and scp tasks of Apache Ant can download files from a remote server. A malicious server can provide relative paths that allow it to write outside of the dedicated target directory for the download, making it possible to overwrite files of the attacker' 0,5% —
CVE-2026-69347 HIGH 7.4 microsoft windows_10_1607 Heap-based buffer overflow in Windows Fast FAT Driver allows an unauthorized attacker to execute code locally. 0,3% —
CVE-2026-66321 HIGH 7.4 microsoft edge_chromium Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. 1,1% —
CVE-2026-65802 HIGH 7.4 microsoft edge_chromium External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network. 0,9% —
CVE-2026-59288 HIGH 7.4 vmware spring_for_graphql The GraphiQL page bundled with Spring for GraphQL sends requests to the GraphQL endpoints of the application. An attacker can share a malicious URL so that the victim's browser might leak confidential information to the attacker's website. Spring for GraphQL 2 0,4% —
CVE-2026-58612 HIGH 7.4 microsoft powershell Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose information over a network. 0,9% —
CVE-2026-57993 HIGH 7.4 microsoft edge_chromium Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. 0,9% —
CVE-2026-57991 HIGH 7.4 microsoft edge_chromium Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. 1,0% —