EN
57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

57.971 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2026-47289 HIGH 8.8 microsoft windows_10_1607 Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. 1,0%
CVE-2024-52279 MED 5.3 apache zeppelin Improper Input Validation vulnerability in Apache Zeppelin. The fix for JDBC URL validation in CVE-2024-31864 did not account for URL encoded input. This issue affects Apache Zeppelin: from 0.11.1 before 0.12.0. Users are recommended to upgrade to version 0. 1,0%
CVE-2024-45033 HIGH 8.1 apache apache-airflow-providers-fab Insufficient Session Expiration vulnerability in Apache Airflow Fab Provider. This issue affects Apache Airflow Fab Provider: before 1.5.2. When user password has been changed with admin CLI, the sessions for that user have not been cleared, leading to insuf 1,0%
CVE-2024-43596 MED 6.5 microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability 1,0%
CVE-2023-35634 HIGH 8.0 microsoft windows_11_21h2 Windows Bluetooth Driver Remote Code Execution Vulnerability 1,0%
CVE-2023-36886 HIGH 7.6 microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability 1,0%
CVE-2022-4543 MED 5.5 linux linux_kernel A flaw named "EntryBleed" was found in the Linux Kernel Page Table Isolation (KPTI). This issue could allow a local attacker to leak KASLR base via prefetch side-channels based on TLB timing for Intel systems. 1,0%
CVE-2019-9818 HIGH 8.3 mozilla firefox A race condition is present in the crash generation server used to generate data for the crash reporter. This issue can lead to a use-after-free in the main process, resulting in a potentially exploitable crash and a sandbox escape. *Note: this vulnerability o 1,0%
CVE-2026-69636 MED 6.5 microsoft sharepoint_server Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. 1,0%
CVE-2026-69409 MED 6.5 microsoft sharepoint_server Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. 1,0%
CVE-2026-50432 MED 5.3 microsoft windows_10_1607 Use after free in Windows Virtual Filtering Platform (VFP) allows an authorized attacker to deny service over a network. 1,0%
CVE-2024-30053 MED 6.5 microsoft azure_migrate Azure Migrate Cross-Site Scripting Vulnerability 1,0%
CVE-2021-47103 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: inet: fully convert sk->sk_rx_dst to RCU rules syzbot reported various issues around early demux, one being included in this changelog [1] sk->sk_rx_dst is using RCU protection without clea 1,0%
CVE-2024-24772 MED 4.3 apache superset A guest user could exploit a chart data REST API and send arbitrary SQL statements that on error could leak information from the underlying analytics database.This issue affects Apache Superset: before 3.0.4, from 3.1.0 before 3.1.1. Users are recommended to 1,0%
CVE-2023-29485 CRIT 9.8 heimdalsecurity thor An issue was discovered in Heimdal Thor agent versions 3.4.2 and before on Windows and 2.6.9 and before on macOS, allows attackers to bypass network filtering, execute arbitrary code, and obtain sensitive information via DarkLayer Guard threat prevention modul 1,0%
CVE-2023-24948 HIGH 7.4 microsoft windows_10_1507 Windows Bluetooth Driver Elevation of Privilege Vulnerability 1,0%
CVE-2022-22390 HIGH 7.5 ibm db2 IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an information disclosure caused by improper privilege management when table function is used. IBM X-Force ID: 221973. 1,0%
CVE-2017-14191 MED 5.9 fortinet fortiweb An Improper Access Control vulnerability in Fortinet FortiWeb 5.6.0 up to but not including 6.1.0 under "Signed Security Mode", allows attacker to bypass the signed user cookie protection by removing the FortiWeb own protection session cookie. 1,0%
CVE-2026-67390 MED 6.5 microsoft sql_server_2017 Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network. 1,0%
CVE-2026-67383 MED 6.5 microsoft sql_server_2025 Generation of error message containing sensitive information in SQL Server allows an authorized attacker to disclose information over a network. 1,0%
CVE-2025-26630 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Access allows an unauthorized attacker to execute code locally. 1,0%
CVE-2025-24057 HIGH 7.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. 1,0%
CVE-2024-38164 CRIT 9.6 microsoft groupme An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network by convincing a user to click on a malicious link. 1,0%
CVE-2024-21341 MED 6.8 microsoft windows_10_1809 Windows Kernel Remote Code Execution Vulnerability 1,0%
CVE-2023-34121 MED 4.1 zoom rooms Improper input validation in the Zoom for Windows, Zoom Rooms, Zoom VDI Windows Meeting clients before 5.14.0 may allow an authenticated user to potentially enable an escalation of privilege via network access. 1,0%