EN
58.387 CVE seguite
792 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.387 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più alto In KEV dal, ordina dal più alto
CVE-2026-43226 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/rds: No shortcut out of RDS_CONN_ERROR RDS connections carry a state "rds_conn_path::cp_state" and transitions from one state to another and are conditional upon an expected state: "rds_ 0,5% —
CVE-2026-32208 HIGH 8.8 microsoft edge_chromium Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Entra ID allows an authorized attacker to perform spoofing over a network. 0,5% —
CVE-2026-29170 MED 6.1 apache http_server A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via forward or reverse proxy configuration. Users are recommended to upgrade to v 0,5% —
CVE-2026-23456 HIGH 8.2 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: fix OOB read in decode_int() CONS case In decode_int(), the CONS case calls get_bits(bs, 2) to read a length value, then calls get_uint(bs, len) without checkin 0,5% —
CVE-2026-20944 HIGH 8.4 microsoft 365_apps Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0,5% —
CVE-2025-64677 HIGH 8.2 microsoft office_out-of-box_experience Improper neutralization of input during web page generation ('cross-site scripting') in Office Out-of-Box Experience allows an unauthorized attacker to perform spoofing over a network. 0,5% —
CVE-2025-21405 HIGH 7.3 microsoft visual_studio_2022 Visual Studio Elevation of Privilege Vulnerability 0,5% —
CVE-2024-45009 HIGH 8.2 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: only decrement add_addr_accepted for MPJ req Adding the following warning ... WARN_ON_ONCE(msk->pm.add_addr_accepted == 0) ... before decrementing the add_addr_accepted counte 0,5% —
CVE-2023-21815 HIGH 7.8 microsoft visual_studio_2017 Visual Studio Remote Code Execution Vulnerability 0,5% —
CVE-2022-41054 HIGH 7.8 microsoft windows_10 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability 0,5% —
CVE-2022-35707 HIGH 7.8 adobe bridge Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vuln 0,5% —
CVE-2022-35705 HIGH 7.8 adobe bridge Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vuln 0,5% —
CVE-2022-27509 MED 6.1 citrix application_delivery_controller_firmware Unauthenticated redirection to a malicious website 0,5% —
CVE-2022-22244 MED 5.3 juniper junos An XPath Injection vulnerability in the J-Web component of Juniper Networks Junos OS allows an unauthenticated attacker sending a crafted POST to reach the XPath channel, which may allow chaining to other unspecified vulnerabilities, leading to a partial loss 0,5% —
CVE-2022-20684 HIGH 7.4 cisco ios_xe A vulnerability in Simple Network Management Protocol (SNMP) trap generation for wireless clients of Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family could allow an unauthenticated, adjacent attacker to cause an affected device to unexpec 0,5% —
CVE-2021-38638 HIGH 7.8 microsoft windows_10 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability 0,5% —
CVE-2021-38630 HIGH 7.8 microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability 0,5% —
CVE-2021-38628 HIGH 7.8 microsoft windows_10 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability 0,5% —
CVE-2021-38626 HIGH 7.8 microsoft windows_server_2008 Windows Kernel Elevation of Privilege Vulnerability 0,5% —
CVE-2021-38625 HIGH 7.8 microsoft windows_server_2008 Windows Kernel Elevation of Privilege Vulnerability 0,5% —
CVE-2021-36974 HIGH 7.8 microsoft windows_10 Windows SMB Elevation of Privilege Vulnerability 0,5% —
CVE-2021-36973 HIGH 7.8 microsoft windows_10 Windows Redirected Drive Buffering System Elevation of Privilege Vulnerability 0,5% —
CVE-2021-36966 HIGH 7.8 microsoft windows_10 Windows Subsystem for Linux Elevation of Privilege Vulnerability 0,5% —
CVE-2021-36964 HIGH 7.8 microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability 0,5% —
CVE-2021-36954 HIGH 8.8 microsoft windows_10 Windows Bind Filter Driver Elevation of Privilege Vulnerability 0,5% —