57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.971 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-78505 | HIGH 8.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network. | 0,8% | — |
| CVE-2026-73006 | HIGH 8.8 | microsoft windows_10_1607 Stack-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. | 0,8% | — |
| CVE-2026-69797 | HIGH 8.8 | microsoft 365_apps Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network. | 0,8% | — |
| CVE-2026-69767 | HIGH 8.8 | microsoft 365_apps Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network. | 0,8% | — |
| CVE-2026-69678 | HIGH 8.8 | microsoft 365_apps Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network. | 0,8% | — |
| CVE-2026-69632 | HIGH 8.8 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code over a network. | 0,8% | — |
| CVE-2025-60723 | MED 6.3 | microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an authorized attacker to deny service over a network. | 0,8% | — |
| CVE-2025-27741 | HIGH 7.8 | microsoft windows_10_1507 Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally. | 0,8% | — |
| CVE-2024-49111 | MED 6.6 | microsoft windows_10_1809 Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability | 0,8% | — |
| CVE-2023-36872 | MED 5.5 | microsoft vp9_video_extensions VP9 Video Extensions Information Disclosure Vulnerability | 0,8% | — |
| CVE-2022-30300 | MED 6.5 | fortinet fortiweb A relative path traversal vulnerability [CWE-23] in FortiWeb 7.0.0 through 7.0.1, 6.3.6 through 6.3.18, 6.4 all versions may allow an authenticated attacker to obtain unauthorized access to files and data via specifically crafted HTTP GET requests. | 0,8% | — |
| CVE-2022-22712 | MED 5.6 | microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability | 0,8% | — |
| CVE-2022-0972 | HIGH 8.8 | google chrome Use after free in Extensions in Google Chrome prior to 99.0.4844.74 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. | 0,8% | — |
| CVE-2021-31375 | HIGH 7.2 | juniper junos An Improper Input Validation vulnerability in routing process daemon (RPD) of Juniper Networks Junos OS devices configured with BGP origin validation using Resource Public Key Infrastructure (RPKI), allows an attacker to send a specific BGP update which may ca | 0,8% | — |
| CVE-2020-3981 | MED 5.8 | vmware cloud_foundation VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x), Fusion (11.x before 11.5.6) contain an out-of-bounds read vulnerability due to a time-of-check time-of-use issue in ACPI dev | 0,8% | — |
| CVE-2020-3940 | MED 5.9 | vmware workspace_one_boxer VMware Workspace ONE SDK and dependent mobile application updates address sensitive information disclosure vulnerability. | 0,8% | — |
| CVE-2020-15937 | MED 4.7 | fortinet fortios An improper neutralization of input vulnerability in FortiGate version 6.2.x below 6.2.5 and 6.4.x below 6.4.1 may allow a remote attacker to perform a stored cross site scripting attack (XSS) via the IPS and WAF logs dashboard. | 0,8% | — |
| CVE-2020-12464 | MED 6.7 | linux linux_kernel usb_sg_cancel in drivers/usb/core/message.c in the Linux kernel before 5.6.8 has a use-after-free because a transfer occurs without a reference, aka CID-056ad39ee925. | 0,8% | — |
| CVE-2016-3193 | MED 5.4 | fortinet fortianalyzer_firmware Cross-site scripting (XSS) vulnerability in the appliance web-application in Fortinet FortiManager 5.x before 5.0.12, 5.2.x before 5.2.6, and 5.4.x before 5.4.1 and FortiAnalyzer 5.x before 5.0.13, 5.2.x before 5.2.6, and 5.4.x before 5.4.1 allows remote authe | 0,8% | — |
| CVE-2016-1476 | MED 5.4 | cisco ip_phone_8800_series_firmware Cross-site scripting (XSS) vulnerability on Cisco IP Phone 8800 devices with software 11.0 allows remote authenticated users to inject arbitrary web script or HTML via crafted parameters, aka Bug ID CSCuz03024. | 0,8% | — |
| CVE-2025-65995 | MED 6.5 | apache airflow When a DAG failed during parsing, Airflow’s error-reporting in the UI could include the full kwargs passed to the operators. If those kwargs contained sensitive values (such as secrets), they might be exposed in the UI tracebacks to authenticated users who had | 0,8% | — |
| CVE-2024-21363 | HIGH 7.8 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 0,8% | — |
| CVE-2022-22779 | LOW 3.7 | keybase keybase The Keybase Clients for macOS and Windows before version 5.9.0 fails to properly remove exploded messages initiated by a user. This can occur if the receiving user switches to a non-chat feature and places the host in a sleep state before the sending user expl | 0,8% | — |
| CVE-2021-31961 | MED 6.1 | microsoft windows_10 Windows InstallService Elevation of Privilege Vulnerability | 0,8% | — |
| CVE-2020-3356 | MED 6.1 | cisco data_center_network_manager A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability is due to insuff | 0,8% | — |