EN
58.306 CVE seguite
790 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.306 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più alto In KEV dal, ordina dal più alto
CVE-2025-27728 HIGH 7.8 microsoft windows_11_24h2 Out-of-bounds read in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. 0,6% —
CVE-2025-27490 HIGH 7.8 microsoft windows_10_21h2 Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. 0,6% —
CVE-2025-24074 HIGH 7.8 microsoft windows_10_1809 Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. 0,6% —
CVE-2025-24073 HIGH 7.8 microsoft windows_10_1507 Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. 0,6% —
CVE-2025-24062 HIGH 7.8 microsoft windows_10_21h2 Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. 0,6% —
CVE-2025-24060 HIGH 7.8 microsoft windows_10_1809 Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. 0,6% —
CVE-2025-24058 HIGH 7.8 microsoft windows_10_1809 Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. 0,6% —
CVE-2024-38016 HIGH 7.8 microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability 0,6% —
CVE-2022-41083 HIGH 7.8 microsoft jupyter Visual Studio Code Elevation of Privilege Vulnerability 0,6% —
CVE-2022-37999 HIGH 7.8 microsoft windows_10 Windows Group Policy Preference Client Elevation of Privilege Vulnerability 0,6% —
CVE-2022-37994 HIGH 7.8 microsoft windows_10 Windows Group Policy Preference Client Elevation of Privilege Vulnerability 0,6% —
CVE-2022-37993 HIGH 7.8 microsoft windows_10 Windows Group Policy Preference Client Elevation of Privilege Vulnerability 0,6% —
CVE-2021-41032 MED 6.3 fortinet fortios An improper access control vulnerability [CWE-284] in FortiOS versions 6.4.8 and prior and 7.0.3 and prior may allow an authenticated attacker with a restricted user profile to gather sensitive information and modify the SSL-VPN tunnel status of other VDOMs us 0,6% —
CVE-2021-26608 HIGH 8.8 handysoft hshell An arbitrary file download and execution vulnerability was found in the HShell.dll of handysoft Co., Ltd groupware ActiveX module. This issue is due to missing support for integrity check of download URL or downloaded file hash. 0,6% —
CVE-2020-3968 HIGH 8.2 vmware cloud_foundation VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain an out-of-bounds write vulnerability in the USB 3.0 controller (xH 0,6% —
CVE-2020-36115 MED 5.4 egavilanmedia phpcrud Stored Cross Site Scripting (XSS) vulnerability in EGavilan Media CRUD Operation with PHP, MySQL, Bootstrap, and Dompdf via First Name or Last Name parameter in the 'Add New Record Feature'. 0,6% —
CVE-2014-3610 MED 5.5 canonical ubuntu_linux The WRMSR processing functionality in the KVM subsystem in the Linux kernel through 3.17.2 does not properly handle the writing of a non-canonical address to a model-specific register, which allows guest OS users to cause a denial of service (host OS crash) by 0,6% —
CVE-2014-3404 MED 4.3 cisco ios_xe The Autonomic Networking Infrastructure (ANI) component in Cisco IOS XE does not properly validate certificates, which allows remote attackers to trigger acceptance of an invalid message via crafted messages, aka Bug ID CSCuq22677. 0,6% —
CVE-2013-4312 MED 6.2 linux linux_kernel The Linux kernel before 4.4.1 allows local users to bypass file-descriptor limits and cause a denial of service (memory consumption) by sending each descriptor over a UNIX socket before closing it, related to net/unix/af_unix.c and net/unix/garbage.c. 0,6% —
CVE-2012-4088 MED 4.3 cisco unified_computing_system The FTP server in Cisco Unified Computing System (UCS) has a hardcoded password for an unspecified user account, which makes it easier for remote attackers to read or modify files by leveraging knowledge of this password, aka Bug ID CSCtg20769. 0,6% —
CVE-2026-74848 HIGH 7.5 apache apisix Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache APISIX. An attacker could make other clients receive attacker-chosen or other users' responses on serverless-plugin routes. This issue affects Apache 0,6% —
CVE-2026-69366 HIGH 7.1 microsoft windows_10_1607 Use after free in Windows Kernel allows an authorized attacker to elevate privileges over a network. 0,6% —
CVE-2026-68846 HIGH 7.1 microsoft windows_10_1607 Use after free in Windows Kernel allows an authorized attacker to elevate privileges over a network. 0,6% —
CVE-2026-29169 HIGH 7.5 apache http_server A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious request.mod_dav_lock is not used internally by mod_dav or mod_dav_fs. The only known use-case for mod_dav_lock was m 0,6% —
CVE-2025-66675 HIGH 8.2 apache struts Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. This issue affects Apache Struts: from 2.0.0 through 6.7.4, from 7.0.0 through 7.0.3. Users are recommended to upgrade to version 6.8.0 or 7.1 0,6% —