EN
56.712 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia

CVE Tracker

56.712 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordinato dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-1999-0489 HIGH 10.0 microsoft windows_nt MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to paste a file name into the file upload intrinsic control, a variant of "untrusted scripted paste" as described in MS:MS98-013. 12,4%
CVE-1999-0461 HIGH 10.0 linux linux_kernel Versions of rpcbind including Linux, IRIX, and Wietse Venema's rpcbind allow a remote attacker to insert and delete entries by spoofing a source address. 3,2%
CVE-1999-0407 HIGH 10.0 microsoft internet_information_server By default, IIS 4.0 has a virtual directory /IISADMPWD which contains files that can be used as proxies for brute force password attacks, or to identify valid users on the system. 5,1%
CVE-1999-0385 HIGH 10.0 microsoft exchange_server The LDAP bind function in Exchange 5.5 has a buffer overflow that allows a remote attacker to conduct a denial of service or execute commands. 18,2%
CVE-1999-0364 HIGH 10.0 fms_inc. total_vb_sourcebook Microsoft Access 97 stores a database password as plaintext in a foreign mdb, allowing access to data. 5,2%
CVE-1999-0285 HIGH 10.0 microsoft windows_nt Denial of service in telnet from the Windows NT Resource Kit, by opening then immediately closing a connection. 6,7%
CVE-1999-0233 HIGH 10.0 microsoft internet_information_services IIS 1.0 allows users to execute arbitrary commands using .bat or .cmd files. 16,3%
CVE-1999-0226 HIGH 10.0 microsoft windows_nt Windows NT TCP/IP processes fragmented IP packets improperly, causing a denial of service. 5,9%
CVE-1999-0165 HIGH 10.0 bsdi bsd_os NFS cache poisoning. 2,0%
CVE-1999-0119 HIGH 10.0 microsoft windows_nt Windows NT 4.0 beta allows users to read and delete shares. 6,0%
CVE-1999-0067 HIGH 10.0 apache http_server phf CGI program allows remote command execution through shell metacharacters. 86,9%
CVE-2026-9135 CRIT 9.9 langflow langflow IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulnerability in the Policies component's ToolGuard integration that bypasses the allow_custom_components=false secur 0,8%
CVE-2026-8859 CRIT 9.9 langflow langflow IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended locations due to improper input validation in the APIRequest component. A path traversal vulnerability exists when the "Save to File" feature is enabl 0,6%
CVE-2026-8635 CRIT 9.9 langflow langflow IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipulating the database, execute arbitrary system commands, and achieve full system compromise with Langflow service permissions. 0,5%
CVE-2026-8481 CRIT 9.9 langflow langflow IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API endpoint. The POST /api/v1/validate/code endpoint accepts user-supplied Python code and executes it directly using Python's built-in exec() 0,8%
CVE-2026-8476 CRIT 9.9 langflow langflow IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching mechanism. The AsyncDiskCache class uses Python's unsafe pickle.loads() function to deserialize cached objects from disk without validation, 0,9%
CVE-2026-69851 CRIT 9.9 microsoft entra_id Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. 0,4%
CVE-2026-68789 CRIT 9.9 microsoft azure_sql_database Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network. 0,5%
CVE-2026-68782 CRIT 9.9 microsoft azure_sql_database Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network. 0,5%
CVE-2026-64879 CRIT 9.9 tenable security_center A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and achieve command injection via the audit file upload functionality. 2,3%
CVE-2026-64878 CRIT 9.9 tenable security_center Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resulting in remote code execution as a low-privileged OS user via the Analysis REST endpoint. 0,8%
CVE-2026-62830 CRIT 9.9 microsoft azure_sre_agent Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network. 0,5%
CVE-2026-59115 CRIT 9.9 microsoft entra_provisioning_service '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. 0,8%
CVE-2026-57100 CRIT 9.9 microsoft entra_provisioning_service Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. 0,8%
CVE-2026-57092 CRIT 9.9 microsoft windows_10_1607 Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network. 0,9%