EN
58.127 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.127 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più alto In KEV dal, ordina dal più alto
CVE-2026-42934 MED 4.8 f5 dos NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When charset, source_charset, and charset_map and proxy_pass with disabled buffering ("off") directives are configured, unauthenticated attackers can send requests tha 0,7%
CVE-2026-22444 HIGH 7.1 apache solr The "create core" API of Apache Solr 8.6 through 9.10.0 lacks sufficient input validation on some API parameters, which can cause Solr to check the existence of and attempt to read file-system paths that should be disallowed by Solr's "allowPaths" security se 0,7%
CVE-2024-40957 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: seg6: fix parameter passing when calling NF_HOOK() in End.DX4 and End.DX6 behaviors input_action_end_dx4() and input_action_end_dx6() are called NF_HOOK() for PREROUTING hook, in PREROUTING 0,7%
CVE-2024-29064 MED 6.2 microsoft windows_10_1507 Windows Hyper-V Denial of Service Vulnerability 0,7%
CVE-2024-26241 HIGH 7.8 microsoft windows_10_1507 Win32k Elevation of Privilege Vulnerability 0,7%
CVE-2024-20351 HIGH 8.6 cisco secure_firewall_threat_defense A vulnerability in the TCP/IP traffic handling function of the Snort Detection Engine of Cisco Firepower Threat Defense (FTD) Software and Cisco FirePOWER Services could allow an unauthenticated, remote attacker to cause legitimate network traffic to be droppe 0,7%
CVE-2023-20061 MED 6.5 cisco packaged_contact_center_enterprise Multiple vulnerabilities in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to collect sensitive information or perform a server-side request forgery (SSRF) attack on an affected system. Cisco plans to release software updates t 0,7%
CVE-2022-22713 MED 5.6 microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability 0,7%
CVE-2022-21905 MED 4.6 microsoft windows_10 Windows Hyper-V Security Feature Bypass Vulnerability 0,7%
CVE-2021-41374 MED 6.7 microsoft azure_sphere Azure Sphere Information Disclosure Vulnerability 0,7%
CVE-2020-26068 MED 5.5 cisco roomos A vulnerability in the xAPI service of Cisco Telepresence CE Software and Cisco RoomOS Software could allow an authenticated, remote attacker to generate an access token for an affected device. The vulnerability is due to insufficient access authorization. An 0,7%
CVE-2020-0822 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Language Pack Installer improperly handles file operations, aka 'Windows Language Pack Installer Elevation of Privilege Vulnerability'. 0,7%
CVE-2014-7999 HIGH 7.7 cisco meraki_mr Cisco-Meraki MS, MR, and MX devices with firmware before 2014-09-24 allow remote authenticated users to install arbitrary firmware by leveraging unspecified HTTP handler access on the local network, aka Cisco-Meraki defect ID 00478565. 0,7%
CVE-2026-66819 HIGH 8.8 microsoft sql_server_2017 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. 0,7%
CVE-2026-62827 HIGH 8.8 microsoft sharepoint_server Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. 0,7%
CVE-2026-24343 HIGH 8.8 apache hertzbeat Improper Neutralization of Data within XPath Expressions ('XPath Injection') vulnerability in Apache HertzBeat. This issue affects Apache HertzBeat: from 1.7.1 before 1.8.0. Users are recommended to upgrade to version 1.8.0, which fixes the issue. 0,7%
CVE-2026-20274 CRIT 9.8 cisco ios_xr As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple inte 0,7%
CVE-2025-21419 HIGH 7.1 microsoft windows_10_1507 Windows Setup Files Cleanup Elevation of Privilege Vulnerability 0,7%
CVE-2024-3841 MED 6.1 fedoraproject fedora Insufficient data validation in Browser Switcher in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to inject scripts or HTML into a privileged page via a malicious file. (Chromium security severity: Medium) 0,7%
CVE-2024-38133 HIGH 7.8 microsoft windows_10_1809 Windows Kernel Elevation of Privilege Vulnerability 0,7%
CVE-2024-26253 MED 6.8 microsoft windows_10_1507 Windows rndismp6.sys Remote Code Execution Vulnerability 0,7%
CVE-2024-26252 MED 6.8 microsoft windows_10_1507 Windows rndismp6.sys Remote Code Execution Vulnerability 0,7%
CVE-2023-28248 HIGH 7.8 microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability 0,7%
CVE-2022-38411 HIGH 7.8 adobe animate Adobe Animate version 21.0.11 (and earlier) and 22.0.7 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interacti 0,7%
CVE-2022-38030 MED 4.3 microsoft windows_10 Windows USB Serial Driver Information Disclosure Vulnerability 0,7%