58.254 CVE seguite
789 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.254 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2022-21900 | MED 4.6 | microsoft windows_10 Windows Hyper-V Security Feature Bypass Vulnerability | 0,7% | — |
| CVE-2021-42956 | HIGH 7.8 | zoho manageengine_remote_access_plus_server Zoho Remote Access Plus Server Windows Desktop Binary fixed in 10.1.2132.6 is affected by a sensitive information disclosure vulnerability. Due to improper privilege management, the process launches as the logged in user, so memory dump can be done by non-admi | 0,7% | — |
| CVE-2021-26603 | HIGH 8.6 | bandisoft ark_library A heap overflow issue was found in ARK library of bandisoft Co., Ltd when the Ark_DigPathA function parsed a file path. This vulnerability is due to missing support for string length check. | 0,7% | — |
| CVE-2020-3116 | MED 5.5 | cisco webex_meetings_online A vulnerability in the way Cisco Webex applications process Universal Communications Format (UCF) files could allow an attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient validation of UCF media files. An attacker co | 0,7% | — |
| CVE-2017-7339 | MED 6.1 | fortinet fortiportal A Cross-Site Scripting vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to execute unauthorized code or commands via the 'Name' and 'Description' inputs in the 'Add Revision Backup' functionality. | 0,7% | — |
| CVE-2016-1273 | MED 5.9 | juniper junos Juniper Junos OS before 13.2X51-D40, 14.x before 14.1X53-D30, and 15.x before 15.1X53-D20 on QFX5100 and QFX10002 switches do not have sufficient entropy, which makes it easier for remote attackers to defeat cryptographic encryption and authentication protecti | 0,7% | — |
| CVE-2026-71352 | HIGH 8.8 | microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Windows Remote Access Connection Manager allows an authorized attacker to execute code over a network. | 0,7% | — |
| CVE-2026-50685 | HIGH 7.5 | microsoft windows_10_1607 Double free in Windows DHCP Server allows an authorized attacker to execute code over a network. | 0,7% | — |
| CVE-2025-55676 | MED 5.5 | microsoft windows_11_24h2 Generation of error message containing sensitive information in Windows USB Video Driver allows an authorized attacker to disclose information locally. | 0,7% | — |
| CVE-2024-35273 | HIGH 7.2 | fortinet fortianalyzer A out-of-bounds write in Fortinet FortiManager version 7.4.0 through 7.4.2, FortiAnalyzer version 7.4.0 through 7.4.2 allows attacker to escalation of privilege via specially crafted http requests. | 0,7% | — |
| CVE-2024-30079 | HIGH 7.8 | microsoft windows_10_1507 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2024-23112 | HIGH 8.0 | fortinet fortios An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiOS version 7.4.0 through 7.4.1, 7.2.0 through 7.2.6, 7.0.1 through 7.0.13, 6.4.7 through 6.4.14, and FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through | 0,7% | — |
| CVE-2024-21446 | HIGH 7.8 | microsoft windows_10_1507 NTFS Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2023-22323 | HIGH 7.5 | f5 big-ip_access_policy_manager In BIP-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when OCSP authentication profile is configured on a virtual server, undisclosed requests can cause an increase in CPU | 0,7% | — |
| CVE-2022-38015 | MED 6.5 | microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability | 0,7% | — |
| CVE-2022-30304 | MED 4.3 | fortinet fortianalyzer An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiAnalyzer versions prior to 7.2.1, 7.0.4 and 6.4.8 may allow a remote unauthenticated attacker to perform a stored cross site scripting (XSS) attack via the URL parame | 0,7% | — |
| CVE-2022-23171 | MED 5.9 | atlasvpn atlasvpn AtlasVPN - Privilege Escalation Lack of proper security controls on named pipe messages can allow an attacker with low privileges to send a malicious payload and gain SYSTEM permissions on a windows computer where the AtlasVPN client is installed. | 0,7% | — |
| CVE-2022-21902 | HIGH 7.8 | microsoft windows_10 Windows DWM Core Library Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2022-0011 | MED 6.5 | paloaltonetworks pan-os PAN-OS software provides options to exclude specific websites from URL category enforcement and those websites are blocked or allowed (depending on your rules) regardless of their associated URL category. This is done by creating a custom URL category list or | 0,7% | — |
| CVE-2021-34753 | MED 5.8 | cisco secure_firewall_threat_defense A vulnerability in the payload inspection for Ethernet Industrial Protocol (ENIP) traffic for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured rules for ENIP traffic. This vulnerability is du | 0,7% | — |
| CVE-2019-1699 | MED 6.7 | cisco secure_firewall_management_center A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerabil | 0,7% | — |
| CVE-2015-4940 | LOW 2.1 | apache ambari Apache Ambari before 2.1, as used in IBM Infosphere BigInsights 4.x before 4.1, stores a cleartext BigSheets password in a configuration file, which allows local users to obtain sensitive information by reading this file. | 0,7% | — |
| CVE-2026-62823 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network. | 0,7% | — |
| CVE-2026-47294 | HIGH 8.0 | microsoft sharepoint_server Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 0,7% | — |
| CVE-2026-35433 | HIGH 7.3 | microsoft .net Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally. | 0,7% | — |