57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.971 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2019-16009 | HIGH 8.8 | cisco ios A vulnerability in the web UI of Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the | 1,0% | — |
| CVE-2019-1982 | MED 5.3 | cisco firepower_services_software_for_asa A vulnerability in the HTTP traffic filtering component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an unauthenticated, remote attacker to bypass filtering pr | 1,0% | — |
| CVE-2019-1980 | MED 5.3 | cisco firepower_services_software_for_asa A vulnerability in the protocol detection component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an unauthenticated, remote attacker to bypass filtering protec | 1,0% | — |
| CVE-2017-8467 | HIGH 7.0 | microsoft windows_10 Graphics in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability due to the way it han | 1,0% | — |
| CVE-2013-4689 | MED 5.1 | juniper junos J-Web in Juniper Junos before 10.4R13, 11.4 before 11.4R7, 12.1R before 12.1R6, 12.1X44 before 12.1X44-D15, 12.1x45 before 12.1X45-D10, 12.2 before 12.2R3, 12.3 before 12.3R2, and 13.1 before 13.1R3 allow remote attackers to bypass the cross-site request forge | 1,0% | — |
| CVE-2026-8476 | CRIT 9.9 | langflow langflow IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching mechanism. The AsyncDiskCache class uses Python's unsafe pickle.loads() function to deserialize cached objects from disk without validation, | 1,0% | — |
| CVE-2026-56190 | CRIT 9.8 | microsoft windows_10_1607 Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network. | 1,0% | — |
| CVE-2026-56159 | CRIT 9.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network. | 1,0% | — |
| CVE-2026-55010 | CRIT 9.8 | microsoft minecraft_bedrock_dedicated_server Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to execute code over a network. | 1,0% | — |
| CVE-2026-50518 | CRIT 9.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network. | 1,0% | — |
| CVE-2026-50447 | CRIT 9.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network. | 1,0% | — |
| CVE-2026-49172 | CRIT 9.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network. | 1,0% | — |
| CVE-2026-42990 | CRIT 9.8 | microsoft windows_10_1607 Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network. | 1,0% | — |
| CVE-2023-52699 | MED 5.3 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: sysv: don't call sb_bread() with pointers_lock held syzbot is reporting sleep in atomic context in SysV filesystem [1], for sb_bread() is called with rw_spinlock held. A "write_lock(&pointe | 1,0% | — |
| CVE-2022-20851 | MED 5.5 | cisco ios_xe A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to perform an injection attack against an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this v | 1,0% | — |
| CVE-2021-34766 | MED 5.4 | cisco smart_software_manager_on-prem A vulnerability in the web UI of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to elevate privileges and create, read, update, or delete records and settings in multiple functions. This vulnerability is due to | 1,0% | — |
| CVE-2021-20508 | MED 4.3 | ibm security_secret_server IBM Security Secret Server up to 11.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 199322 | 1,0% | — |
| CVE-2021-33760 | MED 5.5 | microsoft windows_10 Media Foundation Information Disclosure Vulnerability | 1,0% | — |
| CVE-2020-26079 | MED 4.9 | cisco iot_field_network_director A vulnerability in the web UI of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to obtain hashes of user passwords on an affected device. The vulnerability is due to insufficient protection of user credentials. An attacker | 1,0% | — |
| CVE-2019-1904 | HIGH 8.8 | cisco ios_xe A vulnerability in the web-based UI (web UI) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the | 1,0% | — |
| CVE-2019-0659 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists when the Storage Service improperly handles file operations, aka 'Windows Storage Service Elevation of Privilege Vulnerability'. | 1,0% | — |
| CVE-2014-0736 | MED 6.8 | cisco unified_communications_manager Cross-site request forgery (CSRF) vulnerability in the Call Detail Records Analysis and Reporting (CAR) page in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote attackers to hijack the authentication of arbitrary users for re | 1,0% | — |
| CVE-2025-50171 | CRIT 9.1 | microsoft windows_server_2022 Missing authorization in Remote Desktop Server allows an unauthorized attacker to perform spoofing over a network. | 1,0% | — |
| CVE-2024-54181 | HIGH 7.2 | ibm websphere_automation IBM WebSphere Automation 1.7.5 could allow a remote privileged user, who has authorized access to the swagger UI, to execute arbitrary code. Using specially crafted input, the user could exploit this vulnerability to execute arbitrary code on the system. | 1,0% | — |
| CVE-2024-26592 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix UAF issue in ksmbd_tcp_new_connection() The race is between the handling of a new TCP connection and its disconnection. It leads to UAF on `struct tcp_transport` in ksmbd_tcp_new_ | 1,0% | — |