EN
56.635 CVE seguite
776 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia

CVE Tracker

56.635 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordinato dal più basso Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2026-27906 MED 4.4 microsoft windows_10_21h2 Improper input validation in Windows Hello allows an authorized attacker to bypass a security feature locally. 0,4%
CVE-2026-21901 MED 4.4 juniper junos A NULL Pointer Dereference vulnerability in the management daemon (mgd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, high-privileged attacker setting or deactivating a specific SSH configuration parameter to create a Denial of Service (DoS 0,2%
CVE-2026-20962 MED 4.4 microsoft windows_10_1809 Use of uninitialized resource in Dynamic Root of Trust for Measurement (DRTM) allows an authorized attacker to disclose information locally. 0,4%
CVE-2026-20825 MED 4.4 microsoft windows_10_1809 Improper access control in Windows Hyper-V allows an authorized attacker to disclose information locally. 0,5%
CVE-2026-0268 MED 4.4 paloaltonetworks prisma_access_agent A security control bypass vulnerability in Prisma Access Agent for Linux allows a local attacker to route network traffic outside the VPN tunnel. This does not impact Prisma Access Agent on Windows, macOS, iOS, Android, or ChromeOS. 0,1%
CVE-2026-0232 MED 4.4 paloaltonetworks cortex_xdr_agent A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows allows a local Windows administrator to disable the agent. This issue may be leveraged by malware to perform malicious activity without detection. 0,1%
CVE-2025-53765 MED 4.4 microsoft azure_app_service_on_azure_stack Exposure of private personal information to an unauthorized actor in Azure Stack allows an authorized attacker to disclose information locally. 0,5%
CVE-2025-47969 MED 4.4 microsoft windows_11_22h2 Exposure of sensitive information to an unauthorized actor in Windows Hello allows an authorized attacker to disclose information locally. 0,6%
CVE-2025-46752 MED 4.4 fortinet fortidlp_agent A insertion of sensitive information into log file in Fortinet FortiDLP 12.0.0 through 12.0.5, 11.5.1, 11.4.6, 11.4.5 allows attacker to information disclosure via re-using the enrollment code. 0,1%
CVE-2025-33104 MED 4.4 ibm websphere_application_server IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a 0,2%
CVE-2025-30413 MED 4.4 acronis agent Credentials are not deleted from Acronis Agent after plan revocation. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 40497, Acronis Cyber Protect 17 (Linux, macOS, Windows) before build 41186. 0,2%
CVE-2025-24997 MED 4.4 microsoft windows_10_21h2 Null pointer dereference in Windows Kernel Memory allows an authorized attacker to deny service locally. 0,6%
CVE-2025-24795 MED 4.4 snowflake snowflake_connector The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. On Linux s 0,1%
CVE-2025-24791 MED 4.4 snowflake snowflake_connector snowflake-connector-nodejs is a NodeJS driver for Snowflake. Snowflake discovered and remediated a vulnerability in the Snowflake NodeJS Driver. File permissions checks of the temporary credential cache could be bypassed by an attacker with write access to the 0,1%
CVE-2025-24790 MED 4.4 snowflake snowflake_jdbc Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connect to Snowflake. Snowflake discovered and remediated a vulnerability in the Snowflake JDBC Driver. On Linux systems, when temporary credential caching 0,2%
CVE-2025-23413 MED 4.4 f5 big-ip_next_central_manager When users log in through the webUI or API using local authentication, BIG-IP Next Central Manager may log sensitive information in the pgaudit log files. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. 0,2%
CVE-2025-23336 MED 4.4 nvidia triton_inference_server NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause a denial of service by loading a misconfigured model. A successful exploit of this vulnerability might lead to denial of service. 0,3%
CVE-2025-23335 MED 4.4 nvidia triton_inference_server NVIDIA Triton Inference Server for Windows and Linux and the Tensor RT backend contain a vulnerability where an attacker could cause an underflow by a specific model configuration and a specific input. A successful exploit of this vulnerability might lead to d 0,5%
CVE-2025-23247 MED 4.4 nvidia cuda_toolkit NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the cuobjdump binary, where a failure to check the length of a buffer could allow a user to cause the tool to crash or execute arbitrary code by passing in a malformed ELF file. A successful exp 0,3%
CVE-2025-21590 MED 4.4 juniper junos An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to compromise the integrity of the device. A local attacker with access to the shell is able to inject arbitrar 1,7%
CVE-2025-21267 MED 4.4 microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability 0,6%
CVE-2025-20158 MED 4.4 cisco desk_phone_9841_firmware A vulnerability in the debug shell of Cisco Video Phone 8875 and Cisco Desk Phone 9800 Series could allow an authenticated, local attacker to access sensitive information on an affected device. To exploit this vulnerability, the attacker must have valid admini 0,2%
CVE-2025-20118 MED 4.4 cisco application_policy_infrastructure_controller A vulnerability in the implementation of the internal system processes of Cisco APIC could allow an authenticated, local attacker to access sensitive information on an affected device. To exploit this vulnerability, the attacker must have valid administrative 0,2%
CVE-2025-13635 MED 4.4 google chrome Inappropriate implementation in Downloads in Google Chrome prior to 143.0.7499.41 allowed a local attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low) 0,1%
CVE-2025-13634 MED 4.4 google chrome Inappropriate implementation in Downloads in Google Chrome on Windows prior to 143.0.7499.41 allowed a local attacker to bypass mark of the web via a crafted HTML page. (Chromium security severity: Medium) 0,2%