58.360 CVE seguite
792 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.360 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2024-26692 | HIGH 8.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: Fix regression in writes when non-standard maximum write size negotiated The conversion to netfs in the 6.3 kernel caused a regression when maximum write size is set by the server to an | 0,5% | — |
| CVE-2023-38738 | MED 6.8 | ibm openpages_with_watson IBM OpenPages with Watson 8.3 and 9.0 could provide weaker than expected security in a OpenPages environment using Native authentication. If OpenPages is using Native authentication an attacker with access to the OpenPages database could through a series of s | 0,5% | — |
| CVE-2023-28656 | HIGH 8.1 | f5 nginx_api_connectivity_manager NGINX Management Suite may allow an authenticated attacker to gain access to configuration objects outside of their assigned environment. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0,5% | — |
| CVE-2023-21537 | HIGH 7.8 | microsoft windows_10_1607 Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2023-20060 | MED 6.1 | cisco prime_collaboration_deployment A vulnerability in the web-based management interface of Cisco Prime Collaboration Deployment could allow an unauthenticated, remote attacker to conduct a cross-site scripting attack against a user of the interface. This vulnerability exists because the web | 0,5% | — |
| CVE-2022-27230 | HIGH 7.5 | f5 big-ip_access_policy_manager On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP APM, and F5 BIG-IP Guided Configuration (GC) all versions prior to 9.0, a reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of F5 BIG-IP Guided Co | 0,5% | — |
| CVE-2022-20927 | HIGH 7.7 | cisco adaptive_security_appliance_software A vulnerability in the SSL/TLS client of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. Thi | 0,5% | — |
| CVE-2020-9291 | MED 6.3 | fortinet forticlient An Insecure Temporary File vulnerability in FortiClient for Windows 6.2.1 and below may allow a local user to gain elevated privileges via exhausting the pool of temporary file names combined with a symbolic link attack. | 0,5% | — |
| CVE-2020-26541 | MED 6.5 | linux linux_kernel The Linux kernel through 5.8.13 does not properly enforce the Secure Boot Forbidden Signature Database (aka dbx) protection mechanism. This affects certs/blacklist.c and certs/system_keyring.c. | 0,5% | — |
| CVE-2018-14656 | HIGH 7.0 | linux linux_kernel A missing address check in the callers of the show_opcodes() in the Linux kernel allows an attacker to dump the kernel memory at an arbitrary kernel address into the dmesg log. | 0,5% | — |
| CVE-2026-71558 | CRIT 9.8 | apache fory Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafted input payload can bypass type compatibility checks during polymorphic smart-pointer deserialization, causing | 0,5% | — |
| CVE-2026-63800 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: pNFS: Fix use-after-free in pnfs_update_layout() When hitting the NFS_LAYOUT_RETURN branch in pnfs_update_layout(), the code calls pnfs_prepare_to_retry_layoutget(lo). If it succeeds, pnfs_p | 0,5% | — |
| CVE-2026-57969 | HIGH 8.8 | microsoft azure_cyclecloud Missing authentication for critical function in Azure CycleCloud allows an authorized attacker to elevate privileges over a network. | 0,5% | — |
| CVE-2026-48827 | HIGH 7.1 | apache mina_sshd Path traversal vulnerability in Apache MINA SSHD bundle sshd-git. Lack of path validation in git-upload-pack, git-receive-pack, and other git operations allows users authenticated over SSH access to git repositories outside the configured git server root direc | 0,5% | — |
| CVE-2026-47300 | HIGH 8.8 | microsoft .net Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network. | 0,5% | — |
| CVE-2025-53737 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0,5% | — |
| CVE-2025-48977 | MED 6.5 | apache ignite Relative Path Traversal vulnerability in Apache Ignite REST API. Authenticated REST API users can read any file on the server with "cmd=log" command and a log path crafted in a certain way. This issue affects Apache Ignite: from 2.0.0 through 2.17.0. Users a | 0,5% | — |
| CVE-2025-3944 | HIGH 7.2 | tridium niagara Incorrect Permission Assignment for Critical Resource vulnerability in Tridium Niagara Framework on QNX, Tridium Niagara Enterprise Security on QNX allows File Manipulation. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Ni | 0,5% | — |
| CVE-2025-22088 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: RDMA/erdma: Prevent use-after-free in erdma_accept_newconn() After the erdma_cep_put(new_cep) being called, new_cep will be freed, and the following dereference will cause a UAF problem. Fix | 0,5% | — |
| CVE-2024-43528 | HIGH 7.8 | microsoft windows_10_1809 Windows Secure Kernel Mode Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2024-31493 | MED 6.5 | fortinet fortisoar An improper removal of sensitive information before storage or transfer vulnerability [CWE-212] in FortiSOAR version 7.3.0, version 7.2.2 and below, version 7.0.3 and below may allow an authenticated low privileged user to read Connector passwords in plain-tex | 0,5% | — |
| CVE-2023-38732 | MED 4.3 | ibm robotic_process_automation IBM Robotic Process Automation 21.0.0 through 21.0.7 server could allow an authenticated user to view sensitive information from application logs. IBM X-Force ID: 262289. | 0,5% | — |
| CVE-2023-33152 | HIGH 7.0 | microsoft 365_apps Microsoft ActiveX Remote Code Execution Vulnerability | 0,5% | — |
| CVE-2023-20181 | MED 6.1 | cisco spa500ds_firmware A vulnerability in the web-based management interface of Cisco Small Business SPA500 Series IP Phones could allow an unauthenticated, remote attacker to conduct XSS attacks. This vulnerability is due to insufficient validation of user-supplied input by the web | 0,5% | — |
| CVE-2022-37992 | HIGH 7.8 | microsoft windows_10 Windows Group Policy Elevation of Privilege Vulnerability | 0,5% | — |