57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.971 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2020-0779 | MED 5.5 | microsoft windows_10 An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0798, CVE-2020-0814, CVE-2020-0842, CVE-2020-084 | 1,0% | — |
| CVE-2019-1090 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the dnsrslvr.dll handles objects in memory, aka 'Windows dnsrlvr.dll Elevation of Privilege Vulnerability'. | 1,0% | — |
| CVE-2019-1067 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. | 1,0% | — |
| CVE-2019-0999 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation of Privilege Vulnerability'. | 1,0% | — |
| CVE-2017-8581 | HIGH 7.0 | microsoft windows_10 Win32k in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability when it fails to | 1,0% | — |
| CVE-2016-3196 | MED 5.4 | fortinet fortianalyzer_firmware Cross-site scripting (XSS) vulnerability in Fortinet FortiAnalyzer 5.x before 5.0.12 and 5.2.x before 5.2.6 and FortiManager 5.x before 5.0.12 and 5.2.x before 5.2.6 allows remote authenticated users to inject arbitrary web script or HTML via the filename of a | 1,0% | — |
| CVE-2012-5427 | MED 4.0 | cisco ios Cisco IOS Unified Border Element (CUBE) in Cisco IOS before 15.3(2)T allows remote authenticated users to cause a denial of service (input queue wedge) via a crafted series of RTCP packets, aka Bug ID CSCuc42518. | 1,0% | — |
| CVE-2013-0683 | HIGH 7.1 | cogentdatahub cascade_datahub The DataSim and DataPid demonstration clients in Cogent Real-Time Systems Cogent DataHub before 7.3.0, OPC DataHub before 6.4.22, Cascade DataHub before 6.4.22 on Windows, and DataHub QuickTrend before 7.3.0 allow remote servers to cause a denial of service (i | 1,0% | — |
| CVE-2011-2837 | HIGH 7.5 | google chrome Google Chrome before 14.0.835.163 on Linux does not use the PIC and PIE compiler options for position-independent code, which has unspecified impact and attack vectors. | 1,0% | — |
| CVE-2005-4826 | MED 6.1 | cisco ios Unspecified vulnerability in the VLAN Trunking Protocol (VTP) feature in Cisco IOS 12.1(22)EA3 on Catalyst 2950T switches allows remote attackers to cause a denial of service (device reboot) via a crafted Subset-Advert message packet, a different issue than CV | 1,0% | — |
| CVE-2026-72979 | CRIT 9.8 | microsoft windows_10_1607 Use after free in Windows DHCP Server allows an unauthorized attacker to execute code over a network. | 1,0% | — |
| CVE-2026-23655 | MED 6.5 | microsoft confidential_sidecar_containers Cleartext storage of sensitive information in Azure Compute Gallery allows an authorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2024-30048 | HIGH 7.6 | microsoft dynamics_365_customer_insights Dynamics 365 Customer Insights Spoofing Vulnerability | 1,0% | — |
| CVE-2024-30047 | HIGH 7.6 | microsoft dynamics_365_customer_insights Dynamics 365 Customer Insights Spoofing Vulnerability | 1,0% | — |
| CVE-2023-36803 | MED 5.5 | microsoft windows_10_1607 Windows Kernel Information Disclosure Vulnerability | 1,0% | — |
| CVE-2020-36401 | HIGH 7.8 | mruby mruby mruby 2.1.2 has a double free in mrb_default_allocf (called from mrb_free and obj_free). | 1,0% | — |
| CVE-2020-3197 | MED 5.3 | cisco meeting_server A vulnerability in the API subsystem of Cisco Meetings App could allow an unauthenticated, remote attacker to retain and reuse the Traversal Using Relay NAT (TURN) server credentials that are configured in an affected system. The vulnerability is due to insuff | 1,0% | — |
| CVE-2015-4458 | MED 4.3 | cisco adaptive_security_appliance_software The TLS implementation in the Cavium cryptographic-module firmware, as distributed with Cisco Adaptive Security Appliance (ASA) Software 9.1(5.21) and other products, does not verify the MAC field, which allows man-in-the-middle attackers to spoof TLS content | 1,0% | — |
| CVE-2005-2709 | MED 4.6 | linux linux_kernel The sysctl functionality (sysctl.c) in Linux kernel before 2.6.14.1 allows local users to cause a denial of service (kernel oops) and possibly execute code by opening an interface file in /proc/sys/net/ipv4/conf/, waiting until the interface is unregistered, t | 1,0% | — |
| CVE-2025-49681 | MED 6.5 | microsoft windows_server_2008 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2025-49671 | MED 6.5 | microsoft windows_server_2008 Exposure of sensitive information to an unauthorized actor in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2022-31686 | CRIT 9.8 | vmware workspace_one_assist VMware Workspace ONE Assist prior to 22.10 contains a Broken Authentication Method vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application. | 1,0% | — |
| CVE-2021-29728 | MED 4.9 | ibm sterling_external_authentication_server IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal da | 1,0% | — |
| CVE-2020-16853 | HIGH 7.1 | microsoft onedrive <p>An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links. An attacker who successfully exploited this vulnerability could overwrite a targeted file with an elevated status.</p> <p>To | 1,0% | — |
| CVE-2019-12415 | MED 5.5 | apache poi In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External En | 1,0% | — |