58.165 CVE seguite
789 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.165 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2024-56626 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix Out-of-Bounds Write in ksmbd_vfs_stream_write An offset from client could be a negative value, It could allows to write data outside the bounds of the allocated buffer. Note that | 0,7% | — |
| CVE-2024-38250 | HIGH 7.8 | microsoft 365_copilot Windows Graphics Component Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2024-20358 | MED 6.0 | cisco adaptive_security_appliance_software A vulnerability in the Cisco Adaptive Security Appliance (ASA) restore functionality that is available in Cisco ASA Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands on the und | 0,7% | — |
| CVE-2023-32331 | HIGH 7.5 | ibm sterling_connect\ IBM Connect:Express for UNIX 1.5.0 is vulnerable to a buffer overflow that could allow a remote attacker to cause a denial of service through its browser UI. IBM X-Force ID: 254979. | 0,7% | — |
| CVE-2022-45432 | MED 5.3 | dahuasecurity dhi-dss4004-s2_firmware Some Dahua software products have a vulnerability of unauthenticated search for devices. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could unauthenticated search for devices | 0,7% | — |
| CVE-2022-22204 | MED 5.3 | juniper junos An Improper Release of Memory Before Removing Last Reference vulnerability in the Session Initiation Protocol (SIP) Application Layer Gateway (ALG) of Juniper Networks Junos OS allows unauthenticated network-based attacker to cause a partial Denial of Service | 0,7% | — |
| CVE-2022-21963 | MED 6.4 | microsoft windows_10 Windows Resilient File System (ReFS) Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2021-40447 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2020-4926 | CRIT 9.1 | ibm elastic_storage_system A vulnerability in the Spectrum Scale 5.1 core component and IBM Elastic Storage System 6.1 could allow unauthorized access to user data or injection of arbitrary data in the communication protocol. IBM X-Force ID: 191600. | 0,7% | — |
| CVE-2011-2526 | MED 4.4 | apache tomcat Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.19, when sendfile is enabled for the HTTP APR or HTTP NIO connector, does not validate certain request attributes, which allows local users to bypass intended file access restrictions or | 0,7% | — |
| CVE-2007-6192 | MED 4.3 | citrix netscaler The web management interface in Citrix NetScaler 8.0 build 47.8 uses weak encryption (XOR of unpadded data) to store credentials within a cookie, which makes it easier for remote attackers to obtain cleartext credentials when a cookie is captured via a known-p | 0,7% | — |
| CVE-2025-24067 | HIGH 7.8 | microsoft windows_10_1507 Heap-based buffer overflow in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally. | 0,7% | — |
| CVE-2025-24066 | HIGH 7.8 | microsoft windows_10_1507 Heap-based buffer overflow in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. | 0,7% | — |
| CVE-2025-21341 | MED 6.6 | microsoft windows_10_1507 Windows Digital Media Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2025-20152 | HIGH 8.6 | cisco identity_services_engine A vulnerability in the RADIUS message processing feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handli | 0,7% | — |
| CVE-2023-35351 | MED 6.6 | microsoft windows_server_2008 Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2023-35346 | MED 6.6 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2023-35345 | MED 6.6 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2023-35344 | MED 6.6 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2019-6696 | MED 6.1 | fortinet fortios An improper input validation vulnerability in FortiOS 6.2.1, 6.2.0, 6.0.8 and below until 5.4.0 under admin webUI may allow an attacker to perform an URL redirect attack via a specifically crafted request to the admin initial password change webpage. | 0,7% | — |
| CVE-2019-3701 | MED 4.4 | canonical ubuntu_linux An issue was discovered in can_can_gw_rcv in net/can/gw.c in the Linux kernel through 4.19.13. The CAN frame modification rules allow bitwise logical operations that can be also applied to the can_dlc field. The privileged user "root" with CAP_NET_ADMIN can cr | 0,7% | — |
| CVE-2019-1764 | HIGH 8.1 | cisco ip_conference_phone_8832_firmware A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack. The vulnerability is due t | 0,7% | — |
| CVE-2019-16154 | MED 6.1 | fortinet fortiauthenticator An improper neutralization of input during web page generation in FortiAuthenticator WEB UI 6.0.0 may allow an unauthenticated user to perform a cross-site scripting attack (XSS) via a parameter of the logon page. | 0,7% | — |
| CVE-2009-0028 | LOW 2.1 | linux linux_kernel The clone system call in the Linux kernel 2.6.28 and earlier allows local users to send arbitrary signals to a parent process from an unprivileged child process by launching an additional child process with the CLONE_PARENT flag, and then letting this new proc | 0,7% | — |
| CVE-2026-49297 | HIGH 8.1 | apache apache-airflow-providers-google Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator` joined GCS object names returned by the bucket listing API directly to a destination filesystem path without normalisation or containment check. A user with w | 0,7% | — |