EN
58.306 CVE seguite
790 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.306 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più alto In KEV dal, ordina dal più alto
CVE-2023-28965 MED 6.5 juniper junos An Improper Check or Handling of Exceptional Conditions within the storm control feature of Juniper Networks Junos OS allows an attacker sending a high rate of traffic to cause a Denial of Service. Continued receipt and processing of these packets will create 0,6% —
CVE-2023-28269 MED 6.2 microsoft windows_10_1507 Windows Boot Manager Security Feature Bypass Vulnerability 0,6% —
CVE-2022-4126 CRIT 9.6 abb rccmd Use of Default Password vulnerability in ABB RCCMD on Windows, Linux, MacOS allows Try Common or Default Usernames and Passwords.This issue affects RCCMD: before 4.40 230207. 0,6% —
CVE-2022-29103 HIGH 7.8 microsoft windows_10 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability 0,6% —
CVE-2022-20869 MED 6.1 cisco broadworks A vulnerability in the web-based management interface of Cisco BroadWorks Application Delivery Platform Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting attack against a user of the interface. This vulnerability exists 0,6% —
CVE-2021-38300 HIGH 7.8 debian debian_linux arch/mips/net/bpf_jit.c in the Linux kernel before 5.4.10 can generate undesirable machine code when transforming unprivileged cBPF programs, allowing execution of arbitrary code within the kernel context. This occurs because conditional branches can exceed th 0,6% —
CVE-2021-23006 MED 6.1 f5 big-iq_centralized_management On all 7.x and 6.x versions (fixed in 8.0.0), undisclosed BIG-IQ pages have a reflected cross-site scripting vulnerability. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated. 0,6% —
CVE-2021-21068 MED 6.1 adobe creative_cloud_desktop_application Adobe Creative Cloud Desktop Application version 5.3 (and earlier) is affected by a file handling vulnerability that could allow an attacker to cause arbitrary file overwriting. Exploitation of this issue requires physical access and user interaction. 0,6% —
CVE-2021-0279 HIGH 8.6 juniper contrail_cloud Juniper Networks Contrail Cloud (CC) releases prior to 13.6.0 have RabbitMQ service enabled by default with hardcoded credentials. The messaging services of RabbitMQ are used when coordinating operations and status information among Contrail services. An attac 0,6% —
CVE-2026-65667 CRIT 10.0 microsoft teams Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network. 0,6% —
CVE-2026-61484 CRIT 9.8 apache lucy ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to 0,6% —
CVE-2026-40421 MED 4.3 microsoft 365_apps Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally. 0,6% —
CVE-2025-29977 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0,6% —
CVE-2024-53209 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Fix receive ring space parameters when XDP is active The MTU setting at the time an XDP multi-buffer is attached determines whether the aggregation ring will be used and the rx_skb_ 0,6% —
CVE-2024-48944 MED 6.5 apache kylin Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin. Through a kylin server, an attacker may forge a request to invoke "/kylin/api/xxx/diag" api on another internal host and possibly get leaked information. There are two preconditions: 1) The atta 0,6% —
CVE-2023-52991 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: fix NULL pointer in skb_segment_list Commit 3a1296a38d0c ("net: Support GRO/GSO fraglist chaining.") introduced UDP listifyed GRO. The segmentation relies on frag_list being untouched w 0,6% —
CVE-2014-4632 MED 4.3 vmware vsphere_data_protection VMware vSphere Data Protection (VDP) 5.1, 5.5 before 5.5.9, and 5.8 before 5.8.1 and the proxy client in EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) 6.x and 7.0.x do not properly verify X.509 certificates from vCenter Server SSL servers, which 0,6% —
CVE-2012-6533 MED 4.4 symantec encryption_desktop Buffer overflow in pgpwded.sys in Symantec PGP Desktop 10.x and Encryption Desktop 10.3.0 before MP1 on Windows XP and Server 2003 allows local users to gain privileges via a crafted application. 0,6% —
CVE-2026-9182 CRIT 9.8 esri arcgis_server Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted file to the affected endpoint. Successful exploitation could allow arbitrary file upload, potentially allowing fo 0,6% —
CVE-2026-52844 HIGH 7.5 caddyserver caddy Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, on Windows, Caddy path matchers treat /private\secret.txt as outside /private/*, but file_server later resolves the same request path as private\secret.txt on disk. An unauthenti 0,6% —
CVE-2026-45650 MED 4.3 microsoft bing User interface (ui) misrepresentation of critical information in Microsoft Bing allows an unauthorized attacker to perform spoofing over a network. 0,6% —
CVE-2026-21261 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 0,6% —
CVE-2026-21258 MED 5.5 microsoft 365_apps Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 0,6% —
CVE-2025-49703 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0,6% —
CVE-2025-0103 HIGH 8.8 paloaltonetworks expedition An SQL injection vulnerability in Palo Alto Networks Expedition enables an authenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. This vulnerability also enables attackers 0,6% —