EN
57.921 CVE seguite
783 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

57.921 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2026-66808 HIGH 8.8 microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 1,1%
CVE-2026-44815 CRIT 9.8 microsoft windows_10_1607 Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code over a network. 1,1%
CVE-2026-20922 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. 1,1%
CVE-2026-20854 HIGH 7.5 microsoft windows_11_24h2 Use after free in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to execute code over a network. 1,1%
CVE-2022-20823 HIGH 8.6 cisco nexus_3016_firmware A vulnerability in the OSPF version 3 (OSPFv3) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to incomplete input validation of speci 1,1%
CVE-2022-20733 MED 5.3 cisco identity_services_engine A vulnerability in the login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to log in without credentials and access all roles without any restrictions. This vulnerability is due to exposed sensitive Security Asser 1,1%
CVE-2022-24511 MED 5.5 microsoft 365_apps Microsoft Office Word Tampering Vulnerability 1,1%
CVE-2021-40130 MED 4.9 cisco common_services_platform_collector A vulnerability in the web application of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to specify non-log files as sources for syslog reporting. This vulnerability is due to improper restriction of the syslog co 1,1%
CVE-2021-22044 HIGH 7.5 vmware spring_cloud_openfeign In Spring Cloud OpenFeign 3.0.0 to 3.0.4, 2.2.0.RELEASE to 2.2.9.RELEASE, and older unsupported versions, applications using type-level `@RequestMapping`annotations over Feign client interfaces, can be involuntarily exposing endpoints corresponding to `@Reques 1,1%
CVE-2021-36168 MED 6.5 fortinet fortiportal A Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Fortinet FortiPortal 6.x before 6.0.5, FortiPortal 5.3.x before 5.3.6 and any FortiPortal before 6.2.5 allows authenticated attacker to disclosure information via crafted GET r 1,1%
CVE-2020-28588 MED 5.5 linux linux_kernel An information disclosure vulnerability exists in the /proc/pid/syscall functionality of Linux Kernel 5.1 Stable and 5.4.66. More specifically, this issue has been introduced in v5.1-rc4 (commit 631b7abacd02b88f4b0795c08b54ad4fc3e7c7c0) and is still present in 1,1%
CVE-2019-1167 MED 4.1 microsoft powershell_core A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement, aka 'Windows Defender Application Control Security Feature Bypass Vulnerability'. 1,1%
CVE-2007-1000 HIGH 7.2 linux linux_kernel The ipv6_getsockopt_sticky function in net/ipv6/ipv6_sockglue.c in the Linux kernel before 2.6.20.2 allows local users to read arbitrary kernel memory via certain getsockopt calls that trigger a NULL dereference. 1,1%
CVE-2026-50515 CRIT 9.9 microsoft azure_service_bus Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network. 1,1%
CVE-2025-49735 HIGH 8.1 microsoft windows_server_2012 Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network. 1,1%
CVE-2025-20309 CRIT 10.0 cisco unified_communications_manager A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to log in to an affected device using the root account, wh 1,1%
CVE-2024-43574 HIGH 8.3 microsoft windows_10_21h2 Microsoft Speech Application Programming Interface (SAPI) Remote Code Execution Vulnerability 1,1%
CVE-2023-21783 HIGH 7.8 microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability 1,1%
CVE-2019-1278 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the unistore.dll handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1215, CVE-2019-1253, CVE-2019-1303. 1,1%
CVE-2018-15387 CRIT 9.8 cisco sd-wan A vulnerability in the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to bypass certificate validation on an affected device. The vulnerability is due to improper certificate validation. An attacker could exploit this vulnerability by su 1,1%
CVE-2017-3833 MED 6.1 cisco unified_communications_manager A vulnerability in the web framework of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of the affected software. More Information: CSCvb959 1,1%
CVE-2024-49115 HIGH 8.1 microsoft windows_server_2016 Windows Remote Desktop Services Remote Code Execution Vulnerability 1,1%
CVE-2024-43480 MED 6.6 microsoft azure_service_fabric Azure Service Fabric for Linux Remote Code Execution Vulnerability 1,1%
CVE-2024-20483 HIGH 7.2 cisco ios_xr Multiple vulnerabilities in Cisco Routed PON Controller Software, which runs as a docker container on hardware that is supported by Cisco IOS XR Software, could allow an authenticated, remote attacker with Administrator-level privileges on the PON Manager or d 1,1%
CVE-2020-1030 HIGH 7.8 microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system. An attacker who successfully exploited this vulnerability could run arbitrary code with elevated system privileges. 1,1%