57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.971 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2023-45757 | MED 6.1 | apache brpc Security vulnerability in Apache bRPC <=1.6.0 on all platforms allows attackers to inject XSS code to the builtin rpcz page. An attacker that can send http request to bRPC server with rpcz enabled can inject arbitrary XSS code to the builtin rpcz page. Soluti | 1,0% | — |
| CVE-2023-36702 | HIGH 7.8 | microsoft windows_10_1507 Microsoft DirectMusic Remote Code Execution Vulnerability | 1,0% | — |
| CVE-2023-36029 | MED 4.3 | microsoft edge Microsoft Edge (Chromium-based) Spoofing Vulnerability | 1,0% | — |
| CVE-2023-20017 | MED 6.5 | cisco intersight_private_virtual_appliance Multiple vulnerabilities in Cisco Intersight Private Virtual Appliance could allow an authenticated, remote attacker to execute arbitrary commands using root-level privileges. The attacker would need to have Administrator privileges on the affected device to e | 1,0% | — |
| CVE-2023-20013 | MED 6.5 | cisco intersight_private_virtual_appliance Multiple vulnerabilities in Cisco Intersight Private Virtual Appliance could allow an authenticated, remote attacker to execute arbitrary commands using root-level privileges. The attacker would need to have Administrator privileges on the affected device to e | 1,0% | — |
| CVE-2021-41030 | MED 5.4 | fortinet forticlient_enterprise_management_server An authentication bypass by capture-replay vulnerability [CWE-294] in FortiClient EMS versions 7.0.1 and below and 6.4.4 and below may allow an unauthenticated attacker to impersonate an existing user by intercepting and re-using valid SAML authentication mess | 1,0% | — |
| CVE-2020-3506 | HIGH 8.8 | cisco 8000p_ip_camera_firmware Multiple vulnerabilities in the Cisco Discovery Protocol implementation for Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to execute code remotely or cause a reload of an affected IP camera. These vulnerabili | 1,0% | — |
| CVE-2020-16908 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists in Windows Setup in the way it handles directories.</p> <p>A locally authenticated attacker could run arbitrary code with elevated system privileges. After successfully exploiting the vulnerability, an attacker | 1,0% | — |
| CVE-2015-6404 | MED 4.0 | cisco hosted_collaboration_solution Cisco Hosted Collaboration Mediation Fulfillment 10.6(3) does not use RBAC, which allows remote authenticated users to obtain sensitive credential information by leveraging admin access and making SOAP API requests, aka Bug ID CSCuw84374. | 1,0% | — |
| CVE-2026-78510 | CRIT 9.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | 1,0% | — |
| CVE-2026-78509 | CRIT 9.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. | 1,0% | — |
| CVE-2026-77493 | CRIT 9.8 | microsoft windows_10_1607 Double free in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. | 1,0% | — |
| CVE-2026-47289 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 1,0% | — |
| CVE-2026-20307 | CRIT 9.9 | A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have at le | 1,0% | — |
| CVE-2024-52279 | MED 5.3 | apache zeppelin Improper Input Validation vulnerability in Apache Zeppelin. The fix for JDBC URL validation in CVE-2024-31864 did not account for URL encoded input. This issue affects Apache Zeppelin: from 0.11.1 before 0.12.0. Users are recommended to upgrade to version 0. | 1,0% | — |
| CVE-2024-45033 | HIGH 8.1 | apache apache-airflow-providers-fab Insufficient Session Expiration vulnerability in Apache Airflow Fab Provider. This issue affects Apache Airflow Fab Provider: before 1.5.2. When user password has been changed with admin CLI, the sessions for that user have not been cleared, leading to insuf | 1,0% | — |
| CVE-2024-43596 | MED 6.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 1,0% | — |
| CVE-2023-36886 | HIGH 7.6 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 1,0% | — |
| CVE-2023-35634 | HIGH 8.0 | microsoft windows_11_21h2 Windows Bluetooth Driver Remote Code Execution Vulnerability | 1,0% | — |
| CVE-2022-4543 | MED 5.5 | linux linux_kernel A flaw named "EntryBleed" was found in the Linux Kernel Page Table Isolation (KPTI). This issue could allow a local attacker to leak KASLR base via prefetch side-channels based on TLB timing for Intel systems. | 1,0% | — |
| CVE-2019-9818 | HIGH 8.3 | mozilla firefox A race condition is present in the crash generation server used to generate data for the crash reporter. This issue can lead to a use-after-free in the main process, resulting in a potentially exploitable crash and a sandbox escape. *Note: this vulnerability o | 1,0% | — |
| CVE-2026-69636 | MED 6.5 | microsoft sharepoint_server Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2026-69409 | MED 6.5 | microsoft sharepoint_server Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2026-50432 | MED 5.3 | microsoft windows_10_1607 Use after free in Windows Virtual Filtering Platform (VFP) allows an authorized attacker to deny service over a network. | 1,0% | — |
| CVE-2024-30053 | MED 6.5 | microsoft azure_migrate Azure Migrate Cross-Site Scripting Vulnerability | 1,0% | — |