EN
57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

57.971 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più alto In KEV dal, ordina dal più alto
CVE-2023-21793 HIGH 7.8 microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability 0,9%
CVE-2023-21791 HIGH 7.8 microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability 0,9%
CVE-2023-21790 HIGH 7.8 microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability 0,9%
CVE-2023-21789 HIGH 7.8 microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability 0,9%
CVE-2023-21788 HIGH 7.8 microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability 0,9%
CVE-2023-21787 HIGH 7.8 microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability 0,9%
CVE-2023-21786 HIGH 7.8 microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability 0,9%
CVE-2023-21785 HIGH 7.8 microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability 0,9%
CVE-2023-21781 HIGH 7.8 microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability 0,9%
CVE-2022-43640 MED 5.5 foxit pdf_editor This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 12.0.1.12430. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicio 0,9%
CVE-2021-36928 MED 6.0 microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 0,9%
CVE-2020-3117 MED 4.7 cisco content_security_management_appliance A vulnerability in the API Framework of Cisco AsyncOS for Cisco Web Security Appliance (WSA) and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to inject crafted HTTP headers in the web server's response. The 0,9%
CVE-2019-8921 MED 6.5 bluez bluez An issue was discovered in bluetoothd in BlueZ through 5.48. The vulnerability lies in the handling of a SVC_ATTR_REQ by the SDP implementation. By crafting a malicious CSTATE, it is possible to trick the server into returning more bytes than the buffer actual 0,9%
CVE-2012-2848 MED 4.3 google chrome The drag-and-drop implementation in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allows user-assisted remote attackers to bypass intended file access restrictions via a crafted web site. 0,9%
CVE-2026-69463 CRIT 9.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code over a network. 0,9%
CVE-2025-33206 HIGH 7.8 nvidia nsight_graphics NVIDIA NSIGHT Graphics for Linux contains a vulnerability where an attacker could cause command injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and denial of service. 0,9%
CVE-2022-29581 HIGH 7.8 canonical ubuntu_linux Improper Update of Reference Count vulnerability in net/sched of Linux Kernel allows local attacker to cause privilege escalation to root. This issue affects: Linux Kernel versions prior to 5.18; version 4.14 and later versions. 0,9%
CVE-2022-21901 CRIT 9.0 microsoft windows_10 Windows Hyper-V Elevation of Privilege Vulnerability 0,9%
CVE-2021-1685 HIGH 7.3 microsoft windows_10 Windows AppX Deployment Extensions Elevation of Privilege Vulnerability 0,9%
CVE-2020-15436 MED 6.7 broadcom brocade_fabric_operating_system_firmware Use-after-free vulnerability in fs/block_dev.c in the Linux kernel before 5.8 allows local users to gain privileges or cause a denial of service by leveraging improper access to a certain error field. 0,9%
CVE-2020-1203 HIGH 7.8 microsoft visual_studio An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector fail to properly handle objects in memory, aka 'Diagnostic Hub Standard Collector Elevation of Privilege Vulnerability'. This CVE 0,9%
CVE-2020-1202 HIGH 7.8 microsoft visual_studio An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector fail to properly handle objects in memory, aka 'Diagnostic Hub Standard Collector Elevation of Privilege Vulnerability'. This CVE 0,9%
CVE-2018-4394 HIGH 7.8 apple iphone_os A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1, macOS Mojave 10.14.1, tvOS 12.1, watchOS 5.1, iTunes 12.9.1. 0,9%
CVE-2018-0247 MED 4.7 cisco aironet_access_point_software A vulnerability in Web Authentication (WebAuth) clients for the Cisco Wireless LAN Controller (WLC) and Aironet Access Points running Cisco IOS Software could allow an unauthenticated, adjacent attacker to bypass authentication and pass traffic. The vulnerabil 0,9%
CVE-2017-7440 MED 6.5 gfi kerio_connect Kerio Connect 8.0.0 through 9.2.2, and Kerio Connect Client desktop application for Windows and Mac 9.2.0 through 9.2.2, when e-mail preview is enabled, allows remote attackers to conduct clickjacking attacks via a crafted e-mail message. 0,9%