58.254 CVE seguite
789 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.254 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2022-41096 | HIGH 7.8 | microsoft windows_10 Microsoft DWM Core Library Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2022-38032 | MED 6.6 | microsoft windows_10 Windows Portable Device Enumerator Service Security Feature Bypass Vulnerability | 0,6% | — |
| CVE-2020-3590 | MED 6.4 | cisco catalyst_sd-wan_manager A vulnerability in the web-based management interface of the Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user. The vulnerability exists because the web-based management in | 0,6% | — |
| CVE-2020-3587 | MED 6.4 | cisco catalyst_sd-wan_manager A vulnerability in the web-based management interface of the Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user. The vulnerability exists because the web-based management in | 0,6% | — |
| CVE-2019-6663 | MED 5.5 | f5 big-ip_access_policy_manager The BIG-IP 15.0.0-15.0.1, 14.0.0-14.1.2.2, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.1-11.6.5.1, BIG-IQ 7.0.0, 6.0.0-6.1.0, and 5.2.0-5.4.0, iWorkflow 2.3.0, and Enterprise Manager 3.1.1 configuration utility is vulnerable to Anti DNS Pinning (DNS Rebinding) at | 0,6% | — |
| CVE-2014-3321 | MED 5.7 | cisco asr_9000_rsp440_router Cisco IOS XR 4.3.4 and earlier on ASR 9000 devices, when bridge-group virtual interface (BVI) routing is enabled, allows remote attackers to cause a denial of service (chip and card hangs) via a series of crafted MPLS packets, aka Bug ID CSCuo91149. | 0,6% | — |
| CVE-2014-3145 | MED 4.9 | canonical ubuntu_linux The BPF_S_ANC_NLATTR_NEST extension implementation in the sk_run_filter function in net/core/filter.c in the Linux kernel through 3.14.3 uses the reverse order in a certain subtraction, which allows local users to cause a denial of service (over-read and syste | 0,6% | — |
| CVE-2014-2115 | MED 6.8 | cisco emergency_responder Multiple cross-site request forgery (CSRF) vulnerabilities in CERUserServlet pages in Cisco Emergency Responder (ER) 8.6 and earlier allow remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCun24250. | 0,6% | — |
| CVE-2014-1446 | LOW 1.9 | linux linux_kernel The yam_ioctl function in drivers/net/hamradio/yam.c in the Linux kernel before 3.12.8 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability for an | 0,6% | — |
| CVE-2026-72987 | HIGH 8.1 | microsoft windows_10_1607 Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. | 0,6% | — |
| CVE-2026-57983 | HIGH 8.7 | microsoft edge_chromium Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network. | 0,6% | — |
| CVE-2025-53378 | HIGH 7.6 | trendmicro worry-free_business_security_services A missing authentication vulnerability in Trend Micro Worry-Free Business Security Services (WFBSS) agent could have allowed an unauthenticated attacker to remotely take control of the agent on affected installations. Also note: this vulnerability only affe | 0,6% | — |
| CVE-2025-32720 | MED 5.5 | microsoft windows_10_1507 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | 0,6% | — |
| CVE-2025-26521 | HIGH 8.1 | apache cloudstack When an Apache CloudStack user-account creates a CKS-based Kubernetes cluster in a project, the API key and the secret key of the 'kubeadmin' user of the caller account are used to create the secret config in the CKS-based Kubernetes cluster. A member of the p | 0,6% | — |
| CVE-2025-21375 | HIGH 7.8 | microsoft windows_10_1507 Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2025-21367 | HIGH 7.8 | microsoft windows_10_1809 Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2024-38618 | MED 5.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ALSA: timer: Set lower bound of start tick time Currently ALSA timer doesn't have the lower limit of the start tick time, and it allows a very small size, e.g. 1 tick with 1ns resolution for | 0,6% | — |
| CVE-2024-20405 | MED 4.8 | cisco finesse A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct a stored XSS attack by exploiting an RFI vulnerability. This vulnerability is due to insufficient validation of user-supplied | 0,6% | — |
| CVE-2023-23391 | MED 5.5 | microsoft 365_copilot Office for Android Spoofing Vulnerability | 0,6% | — |
| CVE-2023-20862 | MED 6.3 | netapp active_iq_unified_manager In Spring Security, versions 5.7.x prior to 5.7.8, versions 5.8.x prior to 5.8.3, and versions 6.0.x prior to 6.0.3, the logout support does not properly clean the security context if using serialized versions. Additionally, it is not possible to explicitly sa | 0,6% | — |
| CVE-2022-48743 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: amd-xgbe: Fix skb data length underflow There will be BUG_ON() triggered in include/linux/skbuff.h leading to intermittent kernel panic, when the skb length underflow is detected. Fix | 0,6% | — |
| CVE-2021-31185 | MED 5.5 | microsoft windows_10 Windows Desktop Bridge Denial of Service Vulnerability | 0,6% | — |
| CVE-2021-28443 | MED 5.5 | microsoft windows_10 Windows Console Driver Denial of Service Vulnerability | 0,6% | — |
| CVE-2019-12614 | MED 4.1 | canonical ubuntu_linux An issue was discovered in dlpar_parse_cc_property in arch/powerpc/platforms/pseries/dlpar.c in the Linux kernel through 5.1.6. There is an unchecked kstrdup of prop->name, which might allow an attacker to cause a denial of service (NULL pointer dereference an | 0,6% | — |
| CVE-2026-55799 | CRIT 9.8 | apache ranger Remote Code Execution Vulnerability in GraalScriptEngineCreator in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue. | 0,6% | — |