EN
58.306 CVE seguite
790 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.306 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più alto In KEV dal, ordina dal più alto
CVE-2018-0056 MED 6.5 juniper junos If a duplicate MAC address is learned by two different interfaces on an MX Series device, the MAC address learning function correctly flaps between the interfaces. However, the Layer 2 Address Learning Daemon (L2ALD) daemon might crash when attempting to delet 0,6% —
CVE-2018-0010 MED 6.5 juniper junos_space A vulnerability in the Juniper Networks Junos Space Security Director allows a user who does not have SSH access to a device to reuse the URL that was created for another user to perform SSH access. Affected releases are all versions of Junos Space Security Di 0,6% —
CVE-2013-3068 MED 6.8 cisco linksys_wrt310n_router_firmware Cross-site request forgery (CSRF) vulnerability in apply.cgi in Linksys WRT310Nv2 2.0.0.1 allows remote attackers to hijack the authentication of administrators for requests that change passwords and modify remote management ports. 0,6% —
CVE-2026-78446 MED 5.3 microsoft windows_10_1607 Use after free in Windows Distributed File System (DFS) allows an authorized attacker to deny service over a network. 0,6% —
CVE-2026-67587 HIGH 8.8 apache airflow Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the stored callback path. Because `SyncCallback` is itself an Airflow class it passes the default `allowed_deserializati 0,6% —
CVE-2025-59390 CRIT 9.8 apache druid Apache Druid’s Kerberos authenticator uses a weak fallback secret when the `druid.auth.authenticator.kerberos.cookieSignatureSecret` configuration is not explicitly set. In this case, the secret is generated using `ThreadLocalRandom`, which is not a crypto-gr 0,6% —
CVE-2025-47979 MED 5.5 microsoft windows_server_2022_23h2 Insertion of sensitive information into log file in Windows Failover Cluster allows an authorized attacker to disclose information locally. 0,6% —
CVE-2024-45720 HIGH 8.2 apache subversion On Windows platforms, a "best fit" character encoding conversion of command line arguments to Subversion's executables (e.g., svn.exe, etc.) may lead to unexpected command line argument interpretation, including argument injection and execution of other progra 0,6% —
CVE-2024-28919 MED 6.7 microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability 0,6% —
CVE-2024-20669 MED 6.7 microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability 0,6% —
CVE-2023-52881 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tcp: do not accept ACK of bytes we never sent This patch is based on a detailed report and ideas from Yepeng Pan and Christian Rossow. ACK seq validation is currently following RFC 5961 5.2 0,6% —
CVE-2023-47148 MED 5.3 ibm spectrum_protect_plus IBM Storage Protect Plus Server 10.1.0 through 10.1.15.2 Admin Console could allow a remote attacker to obtain sensitive information due to improper validation of unsecured endpoints which could be used in further attacks against the system. IBM X-Force ID: 0,6% —
CVE-2023-21572 MED 6.5 microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability 0,6% —
CVE-2022-49110 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: revisit gc autotuning as of commit 4608fdfc07e1 ("netfilter: conntrack: collect all entries in one cycle") conntrack gc was changed to run every 2 minutes. On systems 0,6% —
CVE-2022-20939 MED 4.3 cisco smart_software_manager_on-prem A vulnerability in the web-based management interface of Cisco Smart Software Manager On-Prem could allow an authenticated, remote attacker to elevate privileges on an affected system. This vulnerability is due to inadequate protection of sensitive user 0,6% —
CVE-2021-34764 MED 4.8 cisco firepower_management_center_virtual_appliance Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an attacker to execute a cross-site scripting (XSS) attack or an open redirect attack. For more information about these vulnerabiliti 0,6% —
CVE-2021-33656 MED 6.8 debian debian_linux When setting font with malicous data by ioctl cmd PIO_FONT,kernel will write memory out of bounds. 0,6% —
CVE-2021-31820 HIGH 7.5 octopus octopus_server In Octopus Server after version 2018.8.2 if the Octopus Server Web Request Proxy is configured with authentication, the password is shown in plaintext in the UI. 0,6% —
CVE-2021-22117 HIGH 7.8 broadcom rabbitmq_server RabbitMQ installers on Windows prior to version 3.8.16 do not harden plugin directory permissions, potentially allowing attackers with sufficient local filesystem permissions to add arbitrary plugins. 0,6% —
CVE-2019-1649 MED 6.7 cisco 15454-m-wse-k9_firmware A vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure Boot implementation could allow an authenticated, local attacker to write a modified firmware image to the component. This vulnerability af 0,6% —
CVE-2019-1567 MED 5.4 paloaltonetworks expedition_migration_tool The Expedition Migration tool 1.1.6 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the User Mapping Settings. 0,6% —
CVE-2009-3725 HIGH 7.2 canonical ubuntu_linux The connector layer in the Linux kernel before 2.6.31.5 does not require the CAP_SYS_ADMIN capability for certain interaction with the (1) uvesafb, (2) pohmelfs, (3) dst, or (4) dm subsystem, which allows local users to bypass intended access restrictions and 0,6% —
CVE-2025-59282 HIGH 7.0 microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows an unauthorized attacker to execute code locally. 0,6% —
CVE-2025-49696 HIGH 8.4 microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally. 0,6% —
CVE-2025-21184 HIGH 7.0 microsoft windows_10_1507 Windows Core Messaging Elevation of Privileges Vulnerability 0,6% —