58.306 CVE seguite
790 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.306 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-69597 | HIGH 7.1 | microsoft windows_11_23h2 Use after free in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network. | 0,6% | — |
| CVE-2026-69502 | CRIT 10.0 | microsoft azure_sql_database Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. | 0,6% | — |
| CVE-2026-69451 | HIGH 7.1 | microsoft windows_10_1607 Use after free in Windows Management Instrumentation allows an authorized attacker to elevate privileges over a network. | 0,6% | — |
| CVE-2026-69396 | HIGH 7.1 | microsoft windows_10_1607 Use after free in Windows NDIS allows an authorized attacker to elevate privileges over a network. | 0,6% | — |
| CVE-2026-69357 | HIGH 7.1 | microsoft windows_10_1607 Use after free in Windows NDIS allows an authorized attacker to elevate privileges over a network. | 0,6% | — |
| CVE-2026-69337 | HIGH 7.1 | microsoft windows_10_1607 Double free in Windows Registry allows an authorized attacker to elevate privileges over a network. | 0,6% | — |
| CVE-2026-69314 | HIGH 7.1 | microsoft windows_10_1607 Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges over a network. | 0,6% | — |
| CVE-2026-69305 | HIGH 7.1 | microsoft windows_10_1607 Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges over a network. | 0,6% | — |
| CVE-2026-69296 | HIGH 7.1 | microsoft windows_10_1607 Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges over a network. | 0,6% | — |
| CVE-2026-69274 | HIGH 7.1 | microsoft windows_10_1607 Use after free in Windows Win32K allows an authorized attacker to elevate privileges over a network. | 0,6% | — |
| CVE-2026-68835 | HIGH 7.1 | microsoft windows_10_1607 Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges over a network. | 0,6% | — |
| CVE-2025-33065 | MED 5.5 | microsoft windows_10_1507 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | 0,6% | — |
| CVE-2025-33063 | MED 5.5 | microsoft windows_10_1809 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | 0,6% | — |
| CVE-2025-33061 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | 0,6% | — |
| CVE-2025-33060 | MED 5.5 | microsoft windows_10_1507 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | 0,6% | — |
| CVE-2025-33059 | MED 5.5 | microsoft windows_10_1507 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | 0,6% | — |
| CVE-2025-33058 | MED 5.5 | microsoft windows_10_1507 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | 0,6% | — |
| CVE-2025-33052 | MED 5.5 | microsoft windows_10_1809 Use of uninitialized resource in Windows DWM Core Library allows an authorized attacker to disclose information locally. | 0,6% | — |
| CVE-2025-24069 | MED 5.5 | microsoft windows_10_1507 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | 0,6% | — |
| CVE-2025-21278 | MED 6.2 | microsoft windows_10_1507 Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability | 0,6% | — |
| CVE-2023-20195 | MED 4.7 | cisco identity_services_engine Two vulnerabilities in Cisco ISE could allow an authenticated, remote attacker to upload arbitrary files to an affected device. To exploit these vulnerabilities, an attacker must have valid Administrator credentials on the affected device. These vulnerabilitie | 0,6% | — |
| CVE-2021-39076 | HIGH 7.5 | ibm security_guardium IBM Security Guardium 10.5 and 11.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive information. IBM X-Force ID: 215585. | 0,6% | — |
| CVE-2020-13974 | HIGH 7.8 | canonical ubuntu_linux An issue was discovered in the Linux kernel 4.4 through 5.7.1. drivers/tty/vt/keyboard.c has an integer overflow if k_ascii is called several times in a row, aka CID-b86dab054059. NOTE: Members in the community argue that the integer overflow does not lead to | 0,6% | — |
| CVE-2019-17388 | HIGH 7.8 | aviatrix vpn_client Weak file permissions applied to the Aviatrix VPN Client through 2.2.10 installation directory on Windows and Linux allow a local attacker to execute arbitrary code by gaining elevated privileges through file modifications. | 0,6% | — |
| CVE-2018-3989 | MED 4.3 | wibu wibukey An exploitable kernel memory disclosure vulnerability exists in the 0x8200E804 IOCTL handler functionality of WIBU-SYSTEMS WibuKey.sys Version 6.40 (Build 2400).A specially crafted IRP request can cause the driver to return uninitialized memory, resulting in k | 0,6% | — |