57.479 CVE seguite
782 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.479 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2025-21328 | MED 4.3 | microsoft windows_10_1507 MapUrlToZone Security Feature Bypass Vulnerability | 1,5% | — |
| CVE-2023-22886 | HIGH 8.8 | apache apache-airflow-providers-jdbc Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow JDBC Provider. Airflow JDBC Provider Connection’s [Connection URL] parameters had no restrictions, which made it possible to implement RCE attacks via different type JDBC driv | 1,5% | — |
| CVE-2019-6698 | CRIT 9.8 | fortinet fortirecorder_firmware Use of Hard-coded Credentials vulnerability in FortiRecorder all versions below 2.7.4 may allow an unauthenticated attacker with knowledge of the aforementioned credentials and network access to FortiCameras to take control of those, provided they are managed | 1,5% | — |
| CVE-2019-12270 | HIGH 7.4 | opentext brava\! OpenText Brava! Enterprise and Brava! Server 7.5 through 16.4 configure excessive permissions by default on Windows. During installation, a displaylistcache file share is created on the Windows server with full read and write permissions for the Everyone group | 1,5% | — |
| CVE-2018-8121 | MED 4.7 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 10 Servers, Windows 10. This CVE ID is unique from CVE-2018-8207. | 1,5% | — |
| CVE-2016-8451 | HIGH 7.0 | linux linux_kernel An elevation of privilege vulnerability in the Synaptics touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged p | 1,5% | — |
| CVE-1999-0195 | MED 5.0 | linux linux_kernel Denial of service in RPC portmapper allows attackers to register or unregister RPC services or spoof RPC services using a spoofed source IP address such as 127.0.0.1. | 1,5% | — |
| CVE-2026-63514 | HIGH 8.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 1,5% | — |
| CVE-2026-21514 | HIGH 7.8 | microsoft 365_apps Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally. | 1,5% | |
| CVE-2025-27491 | HIGH 7.1 | microsoft windows_10_1507 Use after free in Windows Hyper-V allows an authorized attacker to execute code over a network. | 1,5% | — |
| CVE-2021-38890 | HIGH 7.5 | ibm sterling_connect\ IBM Sterling Connect:Direct Web Services 1.0 and 6.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 209507. | 1,5% | — |
| CVE-2016-8980 | HIGH 8.1 | ibm bigfix_inventory IBM BigFix Inventory v9 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available me | 1,5% | — |
| CVE-2022-41081 | HIGH 8.1 | microsoft windows_10 Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | 1,5% | — |
| CVE-2021-42320 | HIGH 8.0 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability | 1,5% | — |
| CVE-2021-37595 | CRIT 9.8 | freerdp freerdp In FreeRDP before 2.4.0 on Windows, wf_cliprdr_server_file_contents_request in client/Windows/wf_cliprdr.c has missing input checks for a FILECONTENTS_RANGE File Contents Request PDU. | 1,5% | — |
| CVE-2021-24098 | MED 5.5 | microsoft windows_10 Windows Console Driver Denial of Service Vulnerability | 1,5% | — |
| CVE-2019-1872 | MED 5.3 | cisco telepresence_video_communication_server A vulnerability in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway Series software could allow an unauthenticated, remote attacker to cause an affected system to send arbitrary network requests. The vulnerability is due to improper res | 1,5% | — |
| CVE-2019-1629 | MED 5.3 | cisco integrated_management_controller A vulnerability in the configuration import utility of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to have write access and upload arbitrary data to the filesystem. The vulnerability is due to a failure to delet | 1,5% | — |
| CVE-2018-0437 | HIGH 7.8 | cisco umbrella_enterprise_roaming_client A vulnerability in the Cisco Umbrella Enterprise Roaming Client (ERC) could allow an authenticated, local attacker to elevate privileges to Administrator. To exploit the vulnerability, the attacker must authenticate with valid local user credentials. This vuln | 1,5% | — |
| CVE-2016-8491 | CRIT 9.1 | fortinet fortiwlc The presence of a hardcoded account named 'core' in Fortinet FortiWLC allows attackers to gain unauthorized read/write access via a remote shell. | 1,5% | — |
| CVE-2016-0181 | MED 5.5 | microsoft windows_10 Microsoft Windows 10 Gold and 1511 allows local users to bypass the Virtual Secure Mode Hypervisor Code Integrity (HVCI) protection mechanism and perform RWX markings of kernel-mode pages via a crafted application, aka "Hypervisor Code Integrity Security Featu | 1,5% | — |
| CVE-2015-7759 | LOW 3.7 | f5 big-ip_access_policy_manager BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, Link Controller, and PEM 12.0.0 before HF1, when the TCP profile for a virtual server is configured with Congestion Metrics Cache enabled, allow remote attackers to cause a denial of service (Traffic Management Microk | 1,5% | — |
| CVE-2014-1956 | MED 5.0 | fortinet fortiweb CRLF injection vulnerability in FortiGuard FortiWeb before 5.0.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors. | 1,5% | — |
| CVE-2013-1277 | MED 4.9 | microsoft windows_7 Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently | 1,5% | — |
| CVE-2013-1276 | MED 4.9 | microsoft windows_7 Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently | 1,5% | — |