58.165 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.165 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2022-26794 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2022-26790 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2021-47259 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: NFS: Fix use-after-free in nfs4_init_client() KASAN reports a use-after-free when attempting to mount two different exports through two different NICs that belong to the same server. Olga w | 0,7% | — |
| CVE-2021-21096 | MED 5.5 | adobe bridge Adobe Bridge versions 10.1.1 (and earlier) and 11.0.1 (and earlier) are affected by an Improper Authorization vulnerability in the Genuine Software Service. A low-privileged attacker could leverage this vulnerability to achieve application denial-of-service in | 0,7% | — |
| CVE-2020-5414 | MED 5.7 | vmware operations_manager VMware Tanzu Application Service for VMs (2.7.x versions prior to 2.7.19, 2.8.x versions prior to 2.8.13, and 2.9.x versions prior to 2.9.7) contains an App Autoscaler that logs the UAA admin password. This credential is redacted on VMware Tanzu Operations Man | 0,7% | — |
| CVE-2020-12659 | MED 6.7 | linux linux_kernel An issue was discovered in the Linux kernel before 5.6.7. xdp_umem_reg in net/xdp/xdp_umem.c has an out-of-bounds write (by a user with the CAP_NET_ADMIN capability) because of a lack of headroom validation. | 0,7% | — |
| CVE-2018-20856 | HIGH 7.8 | linux linux_kernel An issue was discovered in the Linux kernel before 4.18.7. In block/blk-core.c, there is an __blk_drain_queue() use-after-free because a certain error case is mishandled. | 0,7% | — |
| CVE-2018-0451 | HIGH 8.8 | cisco tetration_analytics A vulnerability in the web-based management interface of Cisco Tetration Analytics could allow an authenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due | 0,7% | — |
| CVE-2026-62899 | MED 5.9 | microsoft .net Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network. | 0,7% | — |
| CVE-2026-59173 | HIGH 7.5 | apache traffic_server Uncontrolled Resource Consumption vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.1.13, from 10.0.0 through 10.1.2. Users are recommended to upgrade to version 9.1.14 or 10.1.3, which fixes the issue. | 0,7% | — |
| CVE-2026-43868 | MED 5.3 | apache thrift Memory Allocation with Excessive Size Value vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. | 0,7% | — |
| CVE-2026-33120 | HIGH 8.8 | microsoft sql_server_2016 Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network. | 0,7% | — |
| CVE-2026-20821 | MED 6.2 | microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an unauthorized attacker to disclose information locally. | 0,7% | — |
| CVE-2025-24042 | HIGH 7.3 | microsoft visual_studio_code Visual Studio Code JS Debug Extension Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2025-21288 | MED 6.5 | microsoft windows_10_1507 Windows COM Server Information Disclosure Vulnerability | 0,7% | — |
| CVE-2025-21272 | MED 6.5 | microsoft windows_10_1507 Windows COM Server Information Disclosure Vulnerability | 0,7% | — |
| CVE-2024-52056 | MED 6.5 | wowza streaming_engine Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to delete any directory on the file system if the target directory contains an XML definition file. | 0,7% | — |
| CVE-2024-44986 | HIGH 8.1 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: ipv6: fix possible UAF in ip6_finish_output2() If skb_expand_head() returns NULL, skb has been freed and associated dst/idev could also have been freed. We need to hold rcu_read_lock() to m | 0,7% | — |
| CVE-2024-37087 | MED 5.3 | vmware cloud_foundation The vCenter Server contains a denial-of-service vulnerability. A malicious actor with network access to vCenter Server may create a denial-of-service condition. | 0,7% | — |
| CVE-2024-20658 | HIGH 7.8 | microsoft windows_10_1507 Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2023-36770 | HIGH 7.8 | microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2023-26211 | MED 6.8 | fortinet fortisoar An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSOAR 7.3.0 through 7.3.2 allows an authenticated, remote attacker to inject arbitrary web script or HTML via the Communications module. | 0,7% | — |
| CVE-2021-41347 | HIGH 7.8 | microsoft windows_10 Windows AppX Deployment Service Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2021-28349 | HIGH 7.8 | microsoft windows_10 Windows GDI+ Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2021-28348 | HIGH 7.8 | microsoft windows_10 Windows GDI+ Remote Code Execution Vulnerability | 0,7% | — |