57.921 CVE seguite
783 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.921 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-66808 | HIGH 8.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 1,1% | — |
| CVE-2026-44815 | CRIT 9.8 | microsoft windows_10_1607 Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code over a network. | 1,1% | — |
| CVE-2026-20922 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | 1,1% | — |
| CVE-2026-20854 | HIGH 7.5 | microsoft windows_11_24h2 Use after free in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to execute code over a network. | 1,1% | — |
| CVE-2022-20823 | HIGH 8.6 | cisco nexus_3016_firmware A vulnerability in the OSPF version 3 (OSPFv3) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to incomplete input validation of speci | 1,1% | — |
| CVE-2022-20733 | MED 5.3 | cisco identity_services_engine A vulnerability in the login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to log in without credentials and access all roles without any restrictions. This vulnerability is due to exposed sensitive Security Asser | 1,1% | — |
| CVE-2022-24511 | MED 5.5 | microsoft 365_apps Microsoft Office Word Tampering Vulnerability | 1,1% | — |
| CVE-2021-40130 | MED 4.9 | cisco common_services_platform_collector A vulnerability in the web application of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to specify non-log files as sources for syslog reporting. This vulnerability is due to improper restriction of the syslog co | 1,1% | — |
| CVE-2021-22044 | HIGH 7.5 | vmware spring_cloud_openfeign In Spring Cloud OpenFeign 3.0.0 to 3.0.4, 2.2.0.RELEASE to 2.2.9.RELEASE, and older unsupported versions, applications using type-level `@RequestMapping`annotations over Feign client interfaces, can be involuntarily exposing endpoints corresponding to `@Reques | 1,1% | — |
| CVE-2021-36168 | MED 6.5 | fortinet fortiportal A Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Fortinet FortiPortal 6.x before 6.0.5, FortiPortal 5.3.x before 5.3.6 and any FortiPortal before 6.2.5 allows authenticated attacker to disclosure information via crafted GET r | 1,1% | — |
| CVE-2020-28588 | MED 5.5 | linux linux_kernel An information disclosure vulnerability exists in the /proc/pid/syscall functionality of Linux Kernel 5.1 Stable and 5.4.66. More specifically, this issue has been introduced in v5.1-rc4 (commit 631b7abacd02b88f4b0795c08b54ad4fc3e7c7c0) and is still present in | 1,1% | — |
| CVE-2019-1167 | MED 4.1 | microsoft powershell_core A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement, aka 'Windows Defender Application Control Security Feature Bypass Vulnerability'. | 1,1% | — |
| CVE-2007-1000 | HIGH 7.2 | linux linux_kernel The ipv6_getsockopt_sticky function in net/ipv6/ipv6_sockglue.c in the Linux kernel before 2.6.20.2 allows local users to read arbitrary kernel memory via certain getsockopt calls that trigger a NULL dereference. | 1,1% | — |
| CVE-2026-50515 | CRIT 9.9 | microsoft azure_service_bus Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network. | 1,1% | — |
| CVE-2025-49735 | HIGH 8.1 | microsoft windows_server_2012 Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network. | 1,1% | — |
| CVE-2025-20309 | CRIT 10.0 | cisco unified_communications_manager A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to log in to an affected device using the root account, wh | 1,1% | — |
| CVE-2024-43574 | HIGH 8.3 | microsoft windows_10_21h2 Microsoft Speech Application Programming Interface (SAPI) Remote Code Execution Vulnerability | 1,1% | — |
| CVE-2023-21783 | HIGH 7.8 | microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability | 1,1% | — |
| CVE-2019-1278 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the unistore.dll handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1215, CVE-2019-1253, CVE-2019-1303. | 1,1% | — |
| CVE-2018-15387 | CRIT 9.8 | cisco sd-wan A vulnerability in the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to bypass certificate validation on an affected device. The vulnerability is due to improper certificate validation. An attacker could exploit this vulnerability by su | 1,1% | — |
| CVE-2017-3833 | MED 6.1 | cisco unified_communications_manager A vulnerability in the web framework of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of the affected software. More Information: CSCvb959 | 1,1% | — |
| CVE-2024-49115 | HIGH 8.1 | microsoft windows_server_2016 Windows Remote Desktop Services Remote Code Execution Vulnerability | 1,1% | — |
| CVE-2024-43480 | MED 6.6 | microsoft azure_service_fabric Azure Service Fabric for Linux Remote Code Execution Vulnerability | 1,1% | — |
| CVE-2024-20483 | HIGH 7.2 | cisco ios_xr Multiple vulnerabilities in Cisco Routed PON Controller Software, which runs as a docker container on hardware that is supported by Cisco IOS XR Software, could allow an authenticated, remote attacker with Administrator-level privileges on the PON Manager or d | 1,1% | — |
| CVE-2020-1030 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system. An attacker who successfully exploited this vulnerability could run arbitrary code with elevated system privileges. | 1,1% | — |