EN
58.306 CVE seguite
790 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.306 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più alto In KEV dal, ordina dal più alto
CVE-2026-69876 HIGH 8.0 microsoft windows_10_1607 Use after free in Windows DHCP Server allows an authorized attacker to execute code over an adjacent network. 0,6% —
CVE-2026-69847 HIGH 8.0 microsoft windows_10_1607 Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over an adjacent network. 0,6% —
CVE-2026-69777 HIGH 8.0 microsoft windows_11_24h2 Heap-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges over an adjacent network. 0,6% —
CVE-2026-69412 HIGH 8.0 microsoft windows_10_1607 Stack-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over an adjacent network. 0,6% —
CVE-2026-57866 HIGH 8.8 apache impala Server side request forgery in Apache Impala versions 4.4.x and 4.5.x.  Authenticated Impala users with permissions to execute the ai_generate_text() function can exfiltrate secrets provided by the credential providers configured in the `hadoop.security.creden 0,6% —
CVE-2026-52999 CRIT 9.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_osf: fix out-of-bounds read on option matching In nf_osf_match(), the nf_osf_hdr_ctx structure is initialized once and passed by reference to nf_osf_match_one() for each 0,6% —
CVE-2026-50683 HIGH 8.0 microsoft windows_10_1607 Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to elevate privileges over an adjacent network. 0,6% —
CVE-2026-49050 HIGH 8.8 apache dolphinscheduler General user can mint admin access tokens via /access-tokens This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue. 0,6% —
CVE-2025-60714 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows OLE allows an unauthorized attacker to execute code locally. 0,6% —
CVE-2024-5911 MED 4.9 paloaltonetworks pan-os An arbitrary file upload vulnerability in Palo Alto Networks Panorama software enables an authenticated read-write administrator with access to the web interface to disrupt system processes and crash the Panorama. Repeated attacks eventually cause the Panorama 0,6% —
CVE-2024-50145 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: octeon_ep: Add SKB allocation failures handling in __octep_oq_process_rx() build_skb() returns NULL in case of a memory allocation failure so handle it inside __octep_oq_process_rx() to avoi 0,6% —
CVE-2024-45106 HIGH 8.1 apache ozone Improper authentication of an HTTP endpoint in the S3 Gateway of Apache Ozone 1.4.0 allows any authenticated Kerberos user to revoke and regenerate the S3 secrets of any other user. This is only possible if: * ozone.s3g.secret.http.enabled is set to true. T 0,6% —
CVE-2024-41909 MED 5.9 apache mina_sshd Like many other SSH implementations, Apache MINA SSHD suffered from the issue that is more widely known as CVE-2023-48795. An attacker that can intercept traffic between client and server could drop certain packets from the stream, potentially causing client a 0,6% —
CVE-2024-38188 HIGH 7.1 microsoft azure_network_watcher_agent Azure Network Watcher VM Agent Elevation of Privilege Vulnerability 0,6% —
CVE-2024-3383 HIGH 7.4 paloaltonetworks pan-os A vulnerability in how Palo Alto Networks PAN-OS software processes data received from Cloud Identity Engine (CIE) agents enables modification of User-ID groups. This impacts user access to network resources where users may be inappropriately denied or allowed 0,6% —
CVE-2024-20381 HIGH 8.8 cisco ios_xr A vulnerability in the JSON-RPC API feature in Cisco Crosswork Network Services Orchestrator (NSO) and ConfD that is used by the web-based management interfaces of Cisco Optical Site Manager and Cisco RV340 Dual WAN Gigabit VPN Routers could allow an authentic 0,6% —
CVE-2024-1545 MED 5.9 wolfssl wolfssl Fault Injection vulnerability in RsaPrivateDecryption function in wolfssl/wolfcrypt/src/rsa.c in WolfSSL wolfssl5.6.6 on Linux/Windows allows remote attacker co-resides in the same system with a victim process to disclose information and escalate privileges vi 0,6% —
CVE-2023-36914 MED 5.5 microsoft windows_10_21h2 Windows Smart Card Resource Management Server Security Feature Bypass Vulnerability 0,6% —
CVE-2023-36904 HIGH 7.8 microsoft windows_10_1809 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability 0,6% —
CVE-2023-26205 HIGH 8.1 fortinet fortiadc An improper access control vulnerability [CWE-284] in FortiADC automation feature 7.1.0 through 7.1.2, 7.0 all versions, 6.2 all versions, 6.1 all versions may allow an authenticated low-privileged attacker to escalate their privileges to super_admin via a spe 0,6% —
CVE-2022-24960 MED 6.5 pdftron pdftron A use after free vulnerability was discovered in PDFTron SDK version 9.2.0. A crafted PDF can overwrite RIP with data previously allocated on the heap. This issue affects: PDFTron PDFTron SDK 9.2.0 on OSX; 9.2.0 on Linux; 9.2.0 on Windows. 0,6% —
CVE-2021-1527 MED 5.3 cisco webex_player A vulnerability in Cisco Webex Player for Windows and MacOS could allow an attacker to cause the affected software to terminate or to gain access to memory state information that is related to the vulnerable application. The vulnerability is due to insufficien 0,6% —
CVE-2020-6648 MED 5.3 fortinet fortios A cleartext storage of sensitive information vulnerability in FortiOS command line interface in versions 6.2.4 and earlier and FortiProxy 2.0.0, 1.2.9 and earlier may allow an authenticated attacker to obtain sensitive information such as users passwords by co 0,6% —
CVE-2016-2064 HIGH 7.8 linux linux_kernel sound/soc/msm/qdsp6v2/msm-audio-effects-q6-v2.c in the MSM QDSP6 audio driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to cause a denial of service (buffer 0,6% —
CVE-2013-3451 MED 6.8 cisco unified_communications_manager Multiple cross-site request forgery (CSRF) vulnerabilities in Cisco Unified Communications Manager (Unified CM) allow remote attackers to hijack the authentication of arbitrary users for requests that perform arbitrary Unified CM operations, aka Bug ID CSCui13 0,6% —