58.211 CVE seguite
789 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.211 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2022-21875 | HIGH 7.0 | microsoft windows_10 Windows Storage Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2022-21873 | HIGH 7.0 | microsoft windows_10 Tile Data Repository Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2022-21872 | HIGH 7.0 | microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2022-21870 | HIGH 7.0 | microsoft windows_10 Tablet Windows User Interface Application Core Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2022-20952 | MED 5.3 | cisco asyncos A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA), could allow an unauthenticated, remote attacker to bypass a configured rule, thereby allowing traffic onto a | 0,7% | — |
| CVE-2019-7222 | MED 5.5 | canonical ubuntu_linux The KVM implementation in the Linux kernel through 4.20.5 has an Information Leak. | 0,7% | — |
| CVE-2018-0408 | MED 5.4 | cisco sf300-08_firmware A vulnerability in the web-based management interface of Cisco Small Business 300 Series (Sx300) Managed Switches could allow an authenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based management | 0,7% | — |
| CVE-2018-0407 | MED 5.4 | cisco sf300-08_firmware A vulnerability in the web-based management interface of Cisco Small Business 300 Series (Sx300) Managed Switches could allow an authenticated, remote attacker to conduct a persistent cross-site scripting (XSS) attack against a user of the web-based management | 0,7% | — |
| CVE-2014-7991 | MED 4.3 | cisco unified_communications_manager The Remote Mobile Access Subsystem in Cisco Unified Communications Manager (CM) 10.0(1) and earlier does not properly validate the Subject Alternative Name (SAN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof VCS core devices | 0,7% | — |
| CVE-2013-0346 | LOW 2.1 | apache tomcat Apache Tomcat 7.x uses world-readable permissions for the log directory and its files, which might allow local users to obtain sensitive information by reading a file. NOTE: One Tomcat distributor has stated "The tomcat log directory does not contain any sensi | 0,7% | — |
| CVE-2026-63041 | HIGH 8.8 | apache apisix Reliance on Untrusted Inputs in a Security Decision vulnerability in Apache APISIX. This vulnerability allows an attacker to escalate privilege or perform an authorization bypass by sending certain values that the attach-consumer-label plugin does not sanitis | 0,7% | — |
| CVE-2026-45860 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conncount: increase the connection clean up limit to 64 After the optimization to only perform one GC per jiffy, a new problem was introduced. If more than 8 new connections ar | 0,7% | — |
| CVE-2026-28779 | HIGH 7.5 | apache airflow Apache Airflow versions 3.1.0 through 3.1.7 session token (_token) in cookies is set to path=/ regardless of the configured [webserver] base_url or [api] base_url. This allows any application co-hosted under the same domain to capture valid Airflow session tok | 0,7% | — |
| CVE-2025-21384 | HIGH 8.3 | microsoft azure_health_bot An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in Microsoft Azure Health Bot to elevate privileges over a network. | 0,7% | — |
| CVE-2023-52628 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: nftables: exthdr: fix 4-byte stack OOB write If priv->len is a multiple of 4, then dst[len / 4] can write past the destination array which leads to stack corruption. This constru | 0,7% | — |
| CVE-2023-36705 | HIGH 7.8 | microsoft windows_10_1507 Windows Installer Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2023-33834 | MED 4.3 | ibm security_verify_information_queue IBM Security Verify Information Queue 10.0.4 and 10.0.5 could allow a remote attacker to obtain sensitive information that could aid in further attacks against the system. IBM X-force ID: 256014. | 0,7% | — |
| CVE-2022-49356 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Trap RDMA segment overflows Prevent svc_rdma_build_writes() from walking off the end of a Write chunk's segment array. Caught with KASAN. The test that this fix replaces is invalid, | 0,7% | — |
| CVE-2022-40748 | MED 5.4 | ibm infosphere_information_server IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trust | 0,7% | — |
| CVE-2022-38166 | HIGH 7.5 | f-secure elements_endpoint_protection In F-Secure Endpoint Protection for Windows and macOS before channel with Capricorn database 2022-11-22_07, the aerdl.dll unpacker handler crashes. This can lead to a scanning engine crash, triggerable remotely by an attacker for denial of service. | 0,7% | — |
| CVE-2022-35721 | MED 5.4 | ibm jazz_for_service_management IBM Jazz for Service Management 1.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a | 0,7% | — |
| CVE-2022-33683 | MED 5.9 | apache pulsar Apache Pulsar Brokers and Proxies create an internal Pulsar Admin Client that does not verify peer TLS certificates, even when tlsAllowInsecureConnection is disabled via configuration. The Pulsar Admin Client's intra-cluster and geo-replication HTTPS connectio | 0,7% | — |
| CVE-2022-24544 | HIGH 7.8 | microsoft windows_10 Windows Kerberos Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2022-21845 | MED 4.7 | microsoft windows_10 Windows Kernel Information Disclosure Vulnerability | 0,7% | — |
| CVE-2021-47486 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: riscv, bpf: Fix potential NULL dereference The bpf_jit_binary_free() function requires a non-NULL argument. When the RISC-V BPF JIT fails to converge in NR_JIT_ITERATIONS steps, jit_data->he | 0,7% | — |