56.635 CVE seguite
776 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.635 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più basso | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-27906 | MED 4.4 | microsoft windows_10_21h2 Improper input validation in Windows Hello allows an authorized attacker to bypass a security feature locally. | 0,4% | — |
| CVE-2026-21901 | MED 4.4 | juniper junos A NULL Pointer Dereference vulnerability in the management daemon (mgd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, high-privileged attacker setting or deactivating a specific SSH configuration parameter to create a Denial of Service (DoS | 0,2% | — |
| CVE-2026-20962 | MED 4.4 | microsoft windows_10_1809 Use of uninitialized resource in Dynamic Root of Trust for Measurement (DRTM) allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-20825 | MED 4.4 | microsoft windows_10_1809 Improper access control in Windows Hyper-V allows an authorized attacker to disclose information locally. | 0,5% | — |
| CVE-2026-0268 | MED 4.4 | paloaltonetworks prisma_access_agent A security control bypass vulnerability in Prisma Access Agent for Linux allows a local attacker to route network traffic outside the VPN tunnel. This does not impact Prisma Access Agent on Windows, macOS, iOS, Android, or ChromeOS. | 0,1% | — |
| CVE-2026-0232 | MED 4.4 | paloaltonetworks cortex_xdr_agent A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows allows a local Windows administrator to disable the agent. This issue may be leveraged by malware to perform malicious activity without detection. | 0,1% | — |
| CVE-2025-53765 | MED 4.4 | microsoft azure_app_service_on_azure_stack Exposure of private personal information to an unauthorized actor in Azure Stack allows an authorized attacker to disclose information locally. | 0,5% | — |
| CVE-2025-47969 | MED 4.4 | microsoft windows_11_22h2 Exposure of sensitive information to an unauthorized actor in Windows Hello allows an authorized attacker to disclose information locally. | 0,6% | — |
| CVE-2025-46752 | MED 4.4 | fortinet fortidlp_agent A insertion of sensitive information into log file in Fortinet FortiDLP 12.0.0 through 12.0.5, 11.5.1, 11.4.6, 11.4.5 allows attacker to information disclosure via re-using the enrollment code. | 0,1% | — |
| CVE-2025-33104 | MED 4.4 | ibm websphere_application_server IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a | 0,2% | — |
| CVE-2025-30413 | MED 4.4 | acronis agent Credentials are not deleted from Acronis Agent after plan revocation. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 40497, Acronis Cyber Protect 17 (Linux, macOS, Windows) before build 41186. | 0,2% | — |
| CVE-2025-24997 | MED 4.4 | microsoft windows_10_21h2 Null pointer dereference in Windows Kernel Memory allows an authorized attacker to deny service locally. | 0,6% | — |
| CVE-2025-24795 | MED 4.4 | snowflake snowflake_connector The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. On Linux s | 0,1% | — |
| CVE-2025-24791 | MED 4.4 | snowflake snowflake_connector snowflake-connector-nodejs is a NodeJS driver for Snowflake. Snowflake discovered and remediated a vulnerability in the Snowflake NodeJS Driver. File permissions checks of the temporary credential cache could be bypassed by an attacker with write access to the | 0,1% | — |
| CVE-2025-24790 | MED 4.4 | snowflake snowflake_jdbc Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connect to Snowflake. Snowflake discovered and remediated a vulnerability in the Snowflake JDBC Driver. On Linux systems, when temporary credential caching | 0,2% | — |
| CVE-2025-23413 | MED 4.4 | f5 big-ip_next_central_manager When users log in through the webUI or API using local authentication, BIG-IP Next Central Manager may log sensitive information in the pgaudit log files. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0,2% | — |
| CVE-2025-23336 | MED 4.4 | nvidia triton_inference_server NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause a denial of service by loading a misconfigured model. A successful exploit of this vulnerability might lead to denial of service. | 0,3% | — |
| CVE-2025-23335 | MED 4.4 | nvidia triton_inference_server NVIDIA Triton Inference Server for Windows and Linux and the Tensor RT backend contain a vulnerability where an attacker could cause an underflow by a specific model configuration and a specific input. A successful exploit of this vulnerability might lead to d | 0,5% | — |
| CVE-2025-23247 | MED 4.4 | nvidia cuda_toolkit NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the cuobjdump binary, where a failure to check the length of a buffer could allow a user to cause the tool to crash or execute arbitrary code by passing in a malformed ELF file. A successful exp | 0,3% | — |
| CVE-2025-21590 | MED 4.4 | juniper junos An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to compromise the integrity of the device. A local attacker with access to the shell is able to inject arbitrar | 1,7% | |
| CVE-2025-21267 | MED 4.4 | microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability | 0,6% | — |
| CVE-2025-20158 | MED 4.4 | cisco desk_phone_9841_firmware A vulnerability in the debug shell of Cisco Video Phone 8875 and Cisco Desk Phone 9800 Series could allow an authenticated, local attacker to access sensitive information on an affected device. To exploit this vulnerability, the attacker must have valid admini | 0,2% | — |
| CVE-2025-20118 | MED 4.4 | cisco application_policy_infrastructure_controller A vulnerability in the implementation of the internal system processes of Cisco APIC could allow an authenticated, local attacker to access sensitive information on an affected device. To exploit this vulnerability, the attacker must have valid administrative | 0,2% | — |
| CVE-2025-13635 | MED 4.4 | google chrome Inappropriate implementation in Downloads in Google Chrome prior to 143.0.7499.41 allowed a local attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low) | 0,1% | — |
| CVE-2025-13634 | MED 4.4 | google chrome Inappropriate implementation in Downloads in Google Chrome on Windows prior to 143.0.7499.41 allowed a local attacker to bypass mark of the web via a crafted HTML page. (Chromium security severity: Medium) | 0,2% | — |