58.135 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.135 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-1999-0381 | HIGH 7.2 | debian debian_linux super 3.11.6 and other versions have a buffer overflow in the syslog utility which allows a local user to gain root access. | 0,7% | — |
| CVE-2026-69268 | HIGH 8.8 | microsoft sharepoint_server Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 0,7% | — |
| CVE-2026-25077 | HIGH 8.8 | apache cloudstack Account users are allowed by default to register templates to be downloaded directly to the primary storage for deploying instances using the KVM hypervisor. Due to missing file name sanitization, an attacker can register malicious templates to execute arbitra | 0,7% | — |
| CVE-2024-22281 | HIGH 7.5 | apache helix ** UNSUPPORTED WHEN ASSIGNED ** The Apache Helix Front (UI) component contained a hard-coded secret, allowing an attacker to spoof sessions by generating their own fake cookies. This issue affects Apache Helix Front (UI): all versions. As this project is ret | 0,7% | — |
| CVE-2024-20307 | MED 6.8 | cisco ios A vulnerability in the IKEv1 fragmentation code of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a heap overflow, resulting in an affected device reloading. This vulnerability exists because crafted, f | 0,7% | — |
| CVE-2022-44694 | HIGH 7.8 | microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2021-26430 | MED 6.0 | microsoft azure_sphere Azure Sphere Denial of Service Vulnerability | 0,7% | — |
| CVE-2021-20407 | MED 5.3 | ibm security_verify_information_queue IBM Security Verify Information Queue 1.0.6 and 1.0.7 discloses sensitive information in source code that could be used in further attacks against the system. IBM X-Force ID: 196185. | 0,7% | — |
| CVE-2021-0217 | HIGH 7.4 | juniper junos A vulnerability in processing of certain DHCP packets from adjacent clients on EX Series and QFX Series switches running Juniper Networks Junos OS with DHCP local/relay server configured may lead to exhaustion of DMA memory causing a Denial of Service (DoS). O | 0,7% | — |
| CVE-2020-3429 | MED 6.5 | cisco ios_xe A vulnerability in the WPA2 and WPA3 security implementation of Cisco IOS XE Wireless Controller Software for the Cisco Catalyst 9000 Family could allow an unauthenticated, adjacent attacker to cause denial of service (DoS) condition on an affected device. The | 0,7% | — |
| CVE-2013-1151 | HIGH 7.1 | cisco adaptive_security_appliance_software Cisco Adaptive Security Appliances (ASA) devices with software 7.x before 7.2(5.10), 8.0 before 8.0(5.31), 8.1 and 8.2 before 8.2(5.38), 8.3 before 8.3(2.37), 8.4 before 8.4(5), 8.5 before 8.5(1.17), 8.6 before 8.6(1.10), and 8.7 before 8.7(1.3) allow remote a | 0,7% | — |
| CVE-2026-80096 | HIGH 8.8 | microsoft windows_10_1607 Out-of-bounds read in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network. | 0,7% | — |
| CVE-2023-52741 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: cifs: Fix use-after-free in rdata->read_into_pages() When the network status is unstable, use-after-free may occur when read data from the server. BUG: KASAN: use-after-free in readpages_ | 0,7% | — |
| CVE-2021-22040 | MED 6.7 | vmware cloud_foundation VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process runn | 0,7% | — |
| CVE-2020-16988 | MED 6.9 | microsoft azure_sphere Azure Sphere Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2019-12619 | MED 6.5 | cisco sd-wan_firmware A vulnerability in the web interface for Cisco SD-WAN Solution vManage could allow an authenticated, remote attacker to impact the integrity of an affected system by executing arbitrary SQL queries. The vulnerability is due to insufficient validation of user-s | 0,7% | — |
| CVE-2018-10651 | MED 6.1 | citrix xenmobile_server There are Open Redirect Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3. | 0,7% | — |
| CVE-2016-1419 | HIGH 8.1 | cisco aironet_access_point_software Cisco Access Point devices with software 8.2(102.43) allow remote attackers to cause a denial of service (device reload) via crafted ARP packets, aka Bug ID CSCuy55803. | 0,7% | — |
| CVE-2010-4247 | MED 5.5 | citrix xen The do_block_io_op function in (1) drivers/xen/blkback/blkback.c and (2) drivers/xen/blktap/blktap.c in Xen before 3.4.0 for the Linux kernel 2.6.18, and possibly other versions, allows guest OS users to cause a denial of service (infinite loop and CPU consump | 0,7% | — |
| CVE-2026-72323 | CRIT 9.8 | In the Linux kernel, the following vulnerability has been resolved: ipv4: igmp: Fix potential UAF in igmp_gq_start_timer() A race condition exists between device teardown (inetdev_destroy) and incoming IGMP query processing (igmp_rcv), leading to a Use-After | 0,7% | — |
| CVE-2026-69989 | HIGH 8.1 | microsoft windows_10_1607 Use after free in DNS Server allows an unauthorized attacker to execute code over a network. | 0,7% | — |
| CVE-2026-69732 | HIGH 8.1 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Link Layer Topology Discovery Protocol allows an unauthorized attacker to execute code over a network. | 0,7% | — |
| CVE-2026-23662 | HIGH 7.5 | microsoft azure_iot_explorer Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. | 0,7% | — |
| CVE-2024-42247 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wireguard: allowedips: avoid unaligned 64-bit memory accesses On the parisc platform, the kernel issues kernel warnings because swap_endian() tries to load a 128-bit IPv6 address from an una | 0,7% | — |
| CVE-2024-38254 | MED 5.5 | microsoft windows_10_1507 Windows Authentication Information Disclosure Vulnerability | 0,7% | — |