58.165 CVE seguite
789 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.165 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-20837 | HIGH 7.8 | microsoft windows_10_1809 Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally. | 0,7% | — |
| CVE-2025-69219 | HIGH 8.8 | apache airflow_providers_http A user with access to the DB could craft a database entry that would result in executing code on Triggerer - which gives anyone who have access to DB the same permissions as Dag Author. Since direct DB access is not usual and recommended for Airflow, the likel | 0,7% | — |
| CVE-2025-55674 | MED 6.5 | apache superset A bypass of the DISALLOWED_SQL_FUNCTIONS security feature in Apache Superset allows for the execution of blocked SQL functions. An attacker can use a special inline block to circumvent the denylist. This allows a user with SQL Lab access to execute functions t | 0,7% | — |
| CVE-2025-21206 | HIGH 7.3 | microsoft visual_studio_2017 Visual Studio Installer Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2024-38247 | HIGH 7.8 | microsoft windows_10_1507 Windows Graphics Component Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2024-38046 | HIGH 7.8 | microsoft windows_10_1507 PowerShell Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2024-23662 | MED 5.3 | fortinet fortios An exposure of sensitive information to an unauthorized actor in Fortinet FortiOS at least version at least 7.4.0 through 7.4.1 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.15 and 6.4.0 through 6.4.15 allows attacker to information disclosure via HTTP request | 0,7% | — |
| CVE-2024-22371 | LOW 2.9 | apache camel Exposure of sensitive data by by crafting a malicious EventFactory and providing a custom ExchangeCreatedEvent that exposes sensitive data. Vulnerability in Apache Camel.This issue affects Apache Camel: from 3.21.X through 3.21.3, from 3.22.X through 3.22.0, f | 0,7% | — |
| CVE-2024-21614 | HIGH 7.5 | juniper junos An Improper Check for Unusual or Exceptional Conditions vulnerability in Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based, unauthenticated attacker to cause rpd to crash, leading to Denial of Service (DoS) | 0,7% | — |
| CVE-2023-36868 | MED 6.5 | microsoft azure_service_fabric Azure Service Fabric on Windows Information Disclosure Vulnerability | 0,7% | — |
| CVE-2023-23375 | HIGH 7.8 | microsoft odbc Microsoft ODBC and OLE DB Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2023-20258 | MED 6.5 | cisco evolved_programmable_network_manager A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. This vulnerability is due to improper processing of serialized J | 0,7% | — |
| CVE-2019-1828 | MED 5.9 | cisco rv320_firmware A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to access administrative credentials. The vulnerability exists because affected devices u | 0,7% | — |
| CVE-2019-16784 | HIGH 7.0 | pyinstaller pyinstaller In PyInstaller before version 3.6, only on Windows, a local privilege escalation vulnerability is present in this particular case: If a software using PyInstaller in "onefile" mode is launched by a privileged user (at least more than the current one) which hav | 0,7% | — |
| CVE-2026-64303 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: spi: fsl-lpspi: terminate the RX channel on TX prepare failure path When dmaengine_prep_slave_sg() fails for the TX channel, the error path terminates the TX DMA channel but leaves the RX ch | 0,7% | — |
| CVE-2026-44930 | CRIT 9.8 | apache cxf An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository. Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix th | 0,7% | — |
| CVE-2026-41870 | HIGH 8.8 | apache nutch Missing Authorization, Improper Control of Generation of Code ('Code Injection'), Improper Control of Dynamically-Managed Code Resources, Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Nutch Server ( | 0,7% | — |
| CVE-2026-20340 | HIGH 8.8 | A vulnerability in Cisco Secure FMC Software could allow an authenticated, remote attacker to execute arbitrary commands at the root privilege level. This vulnerability is due to unsecured deserialization of web-management user-controlled data. An atta | 0,7% | — |
| CVE-2025-25247 | MED 6.1 | apache felix_webconsole Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix Webconsole. This issue affects Apache Felix Webconsole 4.x up to 4.9.8 and 5.x up to 5.0.8. Users are recommended to upgrade to version 4.9.10 | 0,7% | — |
| CVE-2024-56644 | HIGH 7.5 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: net/ipv6: release expired exception dst cached in socket Dst objects get leaked in ip6_negative_advice() when this function is executed for an expired IPv6 route located in the exception tab | 0,7% | — |
| CVE-2024-30392 | HIGH 7.5 | juniper junos A Stack-based Buffer Overflow vulnerability in Flow Processing Daemon (flowd) of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause Denial of Service (DoS). On all Junos OS MX Series platforms with SPC3 and MS-MPC/-MIC, when | 0,7% | — |
| CVE-2023-6105 | MED 5.5 | zohocorp manageengine_access_manager_plus An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed | 0,7% | — |
| CVE-2022-38007 | HIGH 7.8 | microsoft azure_arc Azure Guest Configuration and Azure Arc-enabled servers Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2021-29737 | HIGH 7.5 | ibm infosphere_information_server IBM InfoSphere Data Flow Designer Engine (IBM InfoSphere Information Server 11.7 ) component has improper validation of the REST API server certificate. IBM X-Force ID: 201301. | 0,7% | — |
| CVE-2026-82428 | HIGH 8.8 | Description Dependency artifacts uploaded with `storm jar --artifacts` were stored under a blob key derived only from the Maven coordinate, for example `dep---.jar`. The key was therefore identical for every user of the cluster and predictable in advance. Whe | 0,7% | — |