57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.971 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2022-35639 | HIGH 7.5 | ibm sterling_partner_engagement_manager IBM Sterling Partner Engagement Manager 6.1, 6.2, and Cloud 22.2 do not limit the length of a connection which could cause the server to become unresponsive. IBM X-Force ID: 230932. | 1,0% | — |
| CVE-2021-26884 | MED 5.5 | microsoft windows_10 Windows Media Photo Codec Information Disclosure Vulnerability | 1,0% | — |
| CVE-2021-26869 | MED 5.5 | microsoft windows_10 Windows ActiveX Installer Service Information Disclosure Vulnerability | 1,0% | — |
| CVE-2021-24107 | MED 5.5 | microsoft windows_10 Windows Event Tracing Information Disclosure Vulnerability | 1,0% | — |
| CVE-2021-27364 | HIGH 7.1 | canonical ubuntu_linux An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_iscsi.c is adversely affected by the ability of an unprivileged user to craft Netlink messages. | 1,0% | — |
| CVE-2024-30033 | HIGH 7.0 | microsoft windows_10_21h2 Windows Search Service Elevation of Privilege Vulnerability | 1,0% | — |
| CVE-2022-43641 | HIGH 7.8 | foxit pdf_editor This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 12.0.1.12430. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicio | 1,0% | — |
| CVE-2022-45786 | HIGH 8.1 | apache age There are issues with the AGE drivers for Golang and Python that enable SQL injections to occur. This impacts AGE for PostgreSQL 11 & AGE for PostgreSQL 12, all versions up-to-and-including 1.1.0, when using those drivers. The fix is to update to the latest G | 1,0% | — |
| CVE-2020-1122 | MED 5.5 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Language Pack Installer improperly handles file operations. An attacker who successfully exploited this vulnerability could run processes in an elevated context.</p> <p>An attacker could exploi | 1,0% | — |
| CVE-2013-5539 | MED 6.0 | cisco identity_services_engine The upload-dialog implementation in Cisco Identity Services Engine (ISE) allows remote authenticated users to upload files with an arbitrary file type, and consequently conduct attacks against unspecified other systems, via a crafted file, aka Bug ID CSCui6751 | 1,0% | — |
| CVE-2026-56196 | HIGH 8.8 | microsoft windows_admin_center Relative path traversal in Windows Admin Center allows an authorized attacker to execute code over a network. | 1,0% | — |
| CVE-2025-49757 | HIGH 8.8 | microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | 1,0% | — |
| CVE-2023-36029 | MED 4.3 | microsoft edge Microsoft Edge (Chromium-based) Spoofing Vulnerability | 1,0% | — |
| CVE-2023-45757 | MED 6.1 | apache brpc Security vulnerability in Apache bRPC <=1.6.0 on all platforms allows attackers to inject XSS code to the builtin rpcz page. An attacker that can send http request to bRPC server with rpcz enabled can inject arbitrary XSS code to the builtin rpcz page. Soluti | 1,0% | — |
| CVE-2023-36702 | HIGH 7.8 | microsoft windows_10_1507 Microsoft DirectMusic Remote Code Execution Vulnerability | 1,0% | — |
| CVE-2023-20017 | MED 6.5 | cisco intersight_private_virtual_appliance Multiple vulnerabilities in Cisco Intersight Private Virtual Appliance could allow an authenticated, remote attacker to execute arbitrary commands using root-level privileges. The attacker would need to have Administrator privileges on the affected device to e | 1,0% | — |
| CVE-2023-20013 | MED 6.5 | cisco intersight_private_virtual_appliance Multiple vulnerabilities in Cisco Intersight Private Virtual Appliance could allow an authenticated, remote attacker to execute arbitrary commands using root-level privileges. The attacker would need to have Administrator privileges on the affected device to e | 1,0% | — |
| CVE-2021-41030 | MED 5.4 | fortinet forticlient_enterprise_management_server An authentication bypass by capture-replay vulnerability [CWE-294] in FortiClient EMS versions 7.0.1 and below and 6.4.4 and below may allow an unauthenticated attacker to impersonate an existing user by intercepting and re-using valid SAML authentication mess | 1,0% | — |
| CVE-2020-16908 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists in Windows Setup in the way it handles directories.</p> <p>A locally authenticated attacker could run arbitrary code with elevated system privileges. After successfully exploiting the vulnerability, an attacker | 1,0% | — |
| CVE-2020-3506 | HIGH 8.8 | cisco 8000p_ip_camera_firmware Multiple vulnerabilities in the Cisco Discovery Protocol implementation for Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to execute code remotely or cause a reload of an affected IP camera. These vulnerabili | 1,0% | — |
| CVE-2015-6404 | MED 4.0 | cisco hosted_collaboration_solution Cisco Hosted Collaboration Mediation Fulfillment 10.6(3) does not use RBAC, which allows remote authenticated users to obtain sensitive credential information by leveraging admin access and making SOAP API requests, aka Bug ID CSCuw84374. | 1,0% | — |
| CVE-2026-20307 | CRIT 9.9 | A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have at le | 1,0% | — |
| CVE-2026-78510 | CRIT 9.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | 1,0% | — |
| CVE-2026-78509 | CRIT 9.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. | 1,0% | — |
| CVE-2026-77493 | CRIT 9.8 | microsoft windows_10_1607 Double free in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. | 1,0% | — |