58.518 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.518 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-1999-0331 | HIGH 7.5 | microsoft internet_explorer Buffer overflow in Internet Explorer 4.0(1). | 5,0% | — |
| CVE-1999-0293 | HIGH 7.5 | cisco ios AAA authentication on Cisco systems allows attackers to execute commands without authorization. | 2,6% | — |
| CVE-1999-0284 | HIGH 7.5 | ibm lotus_domino_mail_server Denial of service to NT mail servers including Ipswitch, Mdaemon, and Exchange through a buffer overflow in the SMTP HELO command. | 11,5% | — |
| CVE-1999-0280 | HIGH 7.5 | microsoft internet_explorer Remote command execution in Microsoft Internet Explorer using .lnk and .url files. | 15,6% | — |
| CVE-1999-0256 | HIGH 7.5 | jgaa warftpd Buffer overflow in War FTP allows remote execution of commands. | 72,9% | — |
| CVE-1999-0253 | HIGH 7.5 | microsoft internet_information_server IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a . (dot) in the URL. | 8,0% | — |
| CVE-1999-0236 | HIGH 7.5 | apache http_server ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs. | 25,8% | — |
| CVE-1999-0161 | HIGH 7.5 | cisco ios In Cisco IOS 10.3, with the tacacs-ds or tacacs keyword, an extended IP access control list could bypass filtering. | 1,7% | — |
| CVE-1999-0160 | HIGH 7.5 | cisco ios Some classic Cisco IOS devices have a vulnerability in the PPP CHAP authentication to establish unauthorized PPP connections. | 1,2% | — |
| CVE-1999-0071 | HIGH 7.5 | apache http_server Apache httpd cookie buffer overflow for versions 1.1.1 and earlier. | 3,6% | — |
| CVE-1999-0045 | HIGH 7.5 | apache http_server List of arbitrary files on Web host via nph-test-cgi script. | 26,0% | — |
| CVE-2026-91734 | HIGH 7.4 | google chrome Incorrect authorization in Core in Google Chrome on on Windows prior to 153.0.8010.47 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High) | 0,1% | — |
| CVE-2026-9006 | HIGH 7.4 | ibm websphere_application_server IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an attacker to send unauthorized requests from the system, resulting in a security bypass or information disclosure | 0,4% | — |
| CVE-2026-8646 | HIGH 7.4 | ibm websphere_application_server IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to HTTP request smuggling. A remote attacker could smuggle a specially crafted request to the application server thereby allowi | 0,6% | — |
| CVE-2026-84003 | HIGH 7.4 | microsoft azure\/msal-node Authentication bypass by capture-replay in Microsoft Authentication Library (MSAL) for Node.js allows an unauthorized attacker to perform spoofing over a network. | 0,6% | — |
| CVE-2026-81383 | HIGH 7.4 | microsoft visual_studio_code Use of incorrectly-resolved name or reference in Visual Studio Code allows an unauthorized attacker to disclose information over a network. | 0,9% | — |
| CVE-2026-78461 | HIGH 7.4 | microsoft visual_studio_code Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. | 1,0% | — |
| CVE-2026-78254 | HIGH 7.4 | apache ant The ftp and scp tasks of Apache Ant can download files from a remote server. A malicious server can provide relative paths that allow it to write outside of the dedicated target directory for the download, making it possible to overwrite files of the attacker' | 0,5% | — |
| CVE-2026-69347 | HIGH 7.4 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Fast FAT Driver allows an unauthorized attacker to execute code locally. | 0,3% | — |
| CVE-2026-66321 | HIGH 7.4 | microsoft edge_chromium Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 1,1% | — |
| CVE-2026-65802 | HIGH 7.4 | microsoft edge_chromium External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network. | 0,9% | — |
| CVE-2026-59288 | HIGH 7.4 | vmware spring_for_graphql The GraphiQL page bundled with Spring for GraphQL sends requests to the GraphQL endpoints of the application. An attacker can share a malicious URL so that the victim's browser might leak confidential information to the attacker's website. Spring for GraphQL 2 | 0,4% | — |
| CVE-2026-58612 | HIGH 7.4 | microsoft powershell Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose information over a network. | 0,9% | — |
| CVE-2026-57993 | HIGH 7.4 | microsoft edge_chromium Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | 0,9% | — |
| CVE-2026-57991 | HIGH 7.4 | microsoft edge_chromium Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | 1,0% | — |