EN
58.306 CVE seguite
790 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.306 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più alto In KEV dal, ordina dal più alto
CVE-2025-54899 HIGH 7.8 microsoft 365_apps Free of memory not on the heap in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0,6% —
CVE-2025-54898 HIGH 7.8 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0,6% —
CVE-2025-54896 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0,6% —
CVE-2025-54550 HIGH 8.1 apache airflow The example example_xcom that was included in airflow documentation implemented unsafe pattern of reading value from xcom in the way that could be exploited to allow UI user who had access to modify XComs to perform arbitrary execution of code on the worker. S 0,6% —
CVE-2025-48823 MED 5.9 microsoft windows_10_1507 Cryptographic issues in Windows Cryptographic Services allows an unauthorized attacker to disclose information over a network. 0,6% —
CVE-2025-22859 MED 5.3 fortinet forticlientems A Relative Path Traversal vulnerability [CWE-23] in FortiClientEMS 7.4.0 through 7.4.1 and FortiClientEMS Cloud 7.4.0 through 7.4.1 may allow a remote unauthenticated attacker to perform a limited arbitrary file write on the system via upload requests. 0,6% —
CVE-2025-22038 HIGH 8.3 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate zero num_subauth before sub_auth is accessed Access psid->sub_auth[psid->num_subauth - 1] without checking if num_subauth is non-zero leads to an out-of-bounds read. This pat 0,6% —
CVE-2024-43633 MED 6.5 microsoft windows_11_22h2 Windows Hyper-V Denial of Service Vulnerability 0,6% —
CVE-2024-39928 HIGH 7.5 apache linkis In Apache Linkis <= 1.5.0, a Random string security vulnerability in Spark EngineConn, random string generated by the Token when starting Py4j uses the Commons Lang's RandomStringUtils. Users are recommended to upgrade to version 1.6.0, which fixes this issue. 0,6% —
CVE-2024-37982 MED 6.7 microsoft windows_10_1507 Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability 0,6% —
CVE-2024-37979 MED 6.7 microsoft windows_server_2012 Windows Kernel Elevation of Privilege Vulnerability 0,6% —
CVE-2023-20115 MED 5.4 cisco nx-os A vulnerability in the SFTP server implementation for Cisco Nexus 3000 Series Switches and 9000 Series Switches in standalone NX-OS mode could allow an authenticated, remote attacker to download or overwrite files from the underlying operating system of an aff 0,6% —
CVE-2023-0932 HIGH 8.8 google chrome Use after free in WebRTC in Google Chrome on Windows prior to 110.0.5481.177 allowed a remote attacker who convinced the user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Hig 0,6% —
CVE-2022-22450 LOW 3.8 ibm security_verify_governance IBM Security Verify Identity Manager 10.0 could allow a privileged user to upload a malicious file by bypassing extension security in an HTTP request. IBM X-Force ID: 224916. 0,6% —
CVE-2026-10816 HIGH 7.5 citrix netscaler_application_delivery_controller Arbitrary File Read (Unauthenticated) in NetScaler ADC and NetScaler Gateway if the access to NSIP, Cluster Management IP or SNIP with management access is enabled 0,6% —
CVE-2025-48002 MED 5.7 microsoft windows_11_24h2 Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to disclose information over an adjacent network. 0,6% —
CVE-2024-50563 HIGH 7.3 fortinet fortianalyzer A weak authentication in Fortinet FortiManager Cloud, FortiAnalyzer versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiAnalyzer Cloud versions 7.4.1 through 7.4.3, FortiManager versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiManager Cloud versions 0,6% —
CVE-2024-49054 MED 4.3 microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability 0,6% —
CVE-2021-47178 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: scsi: target: core: Avoid smp_processor_id() in preemptible code The BUG message "BUG: using smp_processor_id() in preemptible [00000000] code" was observed for TCMU devices with kernel conf 0,6% —
CVE-2021-28568 MED 5.8 adobe genuine_service Adobe Genuine Services version 7.1 (and earlier) is affected by an Insecure file permission vulnerability during installation process. A local authenticated attacker could leverage this vulnerability to achieve privilege escalation in the context of the curren 0,6% —
CVE-2021-21384 MED 6.3 shescape_project shescape shescape is a simple shell escape package for JavaScript. In shescape before version 1.1.3, anyone using _Shescape_ to defend against shell injection may still be vulnerable against shell injection if the attacker manages to insert a into the payload. For an e 0,6% —
CVE-2019-18177 MED 6.5 citrix application_delivery_controller_firmware In certain Citrix products, information disclosure can be achieved by an authenticated VPN user when there is a configured SSL VPN endpoint. This affects Citrix ADC and Citrix Gateway 13.0-58.30 and later releases before the CTX276688 update. 0,6% —
CVE-2019-15252 HIGH 8.0 cisco spa112_firmware Multiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, adjacent attacker to execute arbitrary code with elevated privileges. The vulnerabilities are due to improper validation of user-supplied input to th 0,6% —
CVE-2019-15251 HIGH 8.0 cisco spa112_firmware Multiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, adjacent attacker to execute arbitrary code with elevated privileges. The vulnerabilities are due to improper validation of user-supplied input to th 0,6% —
CVE-2019-15250 HIGH 8.0 cisco spa112_firmware Multiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, adjacent attacker to execute arbitrary code with elevated privileges. The vulnerabilities are due to improper validation of user-supplied input to th 0,6% —