57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.971 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2022-26117 | HIGH 8.8 | fortinet fortinac An empty password in configuration file vulnerability [CWE-258] in FortiNAC version 8.3.7 and below, 8.5.2 and below, 8.5.4, 8.6.0, 8.6.5 and below, 8.7.6 and below, 8.8.11 and below, 9.1.5 and below, 9.2.3 and below may allow an authenticated attacker to acce | 0,9% | — |
| CVE-2016-15003 | MED 6.3 | filezilla-project filezilla_client A vulnerability has been found in FileZilla Client 3.17.0.0 and classified as problematic. This vulnerability affects unknown code of the file C:\Program Files\FileZilla FTP Client\uninstall.exe of the component Installer. The manipulation leads to unquoted se | 0,9% | — |
| CVE-2021-42280 | MED 5.5 | microsoft windows_10 Windows Feedback Hub Elevation of Privilege Vulnerability | 0,9% | — |
| CVE-2021-37969 | HIGH 7.8 | debian debian_linux Inappropriate implementation in Google Updater in Google Chrome on Windows prior to 94.0.4606.54 allowed a remote attacker to perform local privilege escalation via a crafted file. | 0,9% | — |
| CVE-2020-0554 | HIGH 7.0 | intel ac_3165_firmware Race condition in software installer for some Intel(R) Wireless Bluetooth(R) products on Windows* 7, 8.1 and 10 may allow an unprivileged user to potentially enable escalation of privilege via local access. | 0,9% | — |
| CVE-2020-0776 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles file operations.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Elevation of Privilege Vu | 0,9% | — |
| CVE-2020-0769 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows CSC Service improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows CSC Service Elevation of Privilege Vulnerabil | 0,9% | — |
| CVE-2019-19922 | MED 5.5 | canonical ubuntu_linux kernel/sched/fair.c in the Linux kernel before 5.3.9, when cpu.cfs_quota_us is used (e.g., with Kubernetes), allows attackers to cause a denial of service against non-cpu-bound applications by generating a workload that triggers unwanted slice expiration, aka | 0,9% | — |
| CVE-2016-6516 | HIGH 7.4 | linux linux_kernel Race condition in the ioctl_file_dedupe_range function in fs/ioctl.c in the Linux kernel through 4.7 allows local users to cause a denial of service (heap-based buffer overflow) or possibly gain privileges by changing a certain count value, aka a "double fetch | 0,9% | — |
| CVE-2013-0216 | MED 5.2 | linux linux_kernel The Xen netback functionality in the Linux kernel before 3.7.8 allows guest OS users to cause a denial of service (loop) by triggering ring pointer corruption. | 0,9% | — |
| CVE-2025-49758 | HIGH 8.8 | microsoft sql_server_2016 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | 0,9% | — |
| CVE-2023-46715 | MED 5.0 | fortinet fortios An origin validation error [CWE-346] vulnerability in Fortinet FortiOS IPSec VPN version 7.4.0 through 7.4.1 and version 7.2.6 and below allows an authenticated IPSec VPN user with dynamic IP addressing to send (but not receive) packets spoofing the IP of ano | 0,9% | — |
| CVE-2022-38010 | HIGH 7.8 | microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability | 0,9% | — |
| CVE-2022-24479 | HIGH 7.8 | microsoft windows_10 Connected User Experiences and Telemetry Elevation of Privilege Vulnerability | 0,9% | — |
| CVE-2020-17014 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0,9% | — |
| CVE-2020-1527 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Custom Protocol Engine improperly handles memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted | 0,9% | — |
| CVE-2009-0754 | LOW 2.1 | php php PHP 4.4.4, 5.1.6, and other versions, when running on Apache, allows local users to modify behavior of other sites hosted on the same web server by modifying the mbstring.func_overload setting within .htaccess, which causes this setting to be applied to other | 0,9% | — |
| CVE-2024-49079 | HIGH 7.8 | microsoft windows_10_1507 Input Method Editor (IME) Remote Code Execution Vulnerability | 0,9% | — |
| CVE-2024-30096 | MED 5.5 | microsoft windows_10_1809 Windows Cryptographic Services Information Disclosure Vulnerability | 0,9% | — |
| CVE-2022-38019 | HIGH 7.8 | microsoft av1_video_extension AV1 Video Extension Remote Code Execution Vulnerability | 0,9% | — |
| CVE-2020-17101 | HIGH 7.8 | microsoft heif_image_extension HEIF Image Extensions Remote Code Execution Vulnerability | 0,9% | — |
| CVE-2020-3598 | MED 6.5 | cisco vision_dynamic_signage_director A vulnerability in the web-based management interface of Cisco Vision Dynamic Signage Director could allow an unauthenticated, remote attacker to access confidential information or make configuration changes. The vulnerability is due to missing authentication | 0,9% | — |
| CVE-2019-0707 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists in the Network Driver Interface Specification (NDIS) when ndis.sys fails to check the length of a buffer prior to copying memory to it.To exploit the vulnerability, in a local attack scenario, an attacker could ru | 0,9% | — |
| CVE-2016-7469 | MED 5.4 | f5 big-ip_access_policy_manager A stored cross-site scripting (XSS) vulnerability in the Configuration utility device name change page in BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, GTM, Link Controller, PEM, PSM, WebAccelerator, WOM and WebSafe version 12.0.0 - 12.1.2, 11. | 0,9% | — |
| CVE-2016-1275 | MED 6.5 | juniper junos Juniper Junos OS before 13.3R9, 14.1R6 before 14.1R6-S1, and 14.1 before 14.1R7, when configured with VPLS routing-instances, allows remote attackers to obtain sensitive mbuf information by injecting a flood of Ethernet frames with IPv6 MAC addresses directly | 0,9% | — |