EN
57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

57.971 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più alto In KEV dal, ordina dal più alto
CVE-2026-47299 HIGH 7.2 microsoft azure_monitor_agent Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate privileges over a network. 0,9%
CVE-2025-21198 CRIT 9.0 microsoft hpc_pack_2016 Microsoft High Performance Compute (HPC) Pack Remote Code Execution Vulnerability 0,9%
CVE-2024-30001 MED 6.8 microsoft windows_10_1809 Windows Mobile Broadband Driver Remote Code Execution Vulnerability 0,9%
CVE-2023-38160 MED 5.5 microsoft windows_10_1507 Windows TCP/IP Information Disclosure Vulnerability 0,9%
CVE-2023-21792 HIGH 7.8 microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability 0,9%
CVE-2023-21784 HIGH 7.8 microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability 0,9%
CVE-2023-21782 HIGH 7.8 microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability 0,9%
CVE-2023-21780 HIGH 7.8 microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability 0,9%
CVE-2022-34874 LOW 3.3 foxit pdf_editor This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.2.53575. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicio 0,9%
CVE-2022-34873 LOW 3.3 foxit pdf_editor This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicio 0,9%
CVE-2021-1657 HIGH 7.8 microsoft windows_10 Windows Fax Compose Form Remote Code Execution Vulnerability 0,9%
CVE-2020-3565 MED 5.8 cisco secure_firewall_threat_defense A vulnerability in the TCP Intercept functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured Access Control Policies (including Geolocation) and Service Polices on an affected system. 0,9%
CVE-2019-1433 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1407, CVE-2019-1435, CVE-2019-14 0,9%
CVE-2019-1285 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1256. 0,9%
CVE-2019-1271 HIGH 7.8 microsoft windows_10 An elevation of privilege exists in hdAudio.sys which may lead to an out of band write, aka 'Windows Media Elevation of Privilege Vulnerability'. 0,9%
CVE-2019-1269 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC).An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the local system, aka 'Wi 0,9%
CVE-2026-50649 HIGH 7.8 microsoft .net Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally. 0,9%
CVE-2026-27651 HIGH 7.5 f5 nginx_open_source When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP authentication is enabled, and (2) the authentication server p 0,9%
CVE-2026-21229 HIGH 8.0 microsoft power_bi_report_server Improper input validation in Power BI allows an authorized attacker to execute code over a network. 0,9%
CVE-2024-43495 HIGH 7.3 microsoft windows_11_22h2 Windows libarchive Remote Code Execution Vulnerability 0,9%
CVE-2023-36562 HIGH 7.1 microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 0,9%
CVE-2023-36410 HIGH 7.6 microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability 0,9%
CVE-2023-36031 HIGH 7.6 microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability 0,9%
CVE-2023-27559 MED 5.3 ibm db2 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may crash when using a specially crafted subquery. IBM X-Force ID: 249196. 0,9%
CVE-2022-23678 MED 5.9 hp aruba_virtual_intranet_access A vulnerability in the Aruba Virtual Intranet Access (VIA) client for Microsoft Windows operating system client communications that could allow for an attacker in a privileged network position to intercept sensitive information in Aruba Virtual Intranet Access 0,9%