57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.971 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2020-0682 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Function Discovery Service handles objects in memory, aka 'Windows Function Discovery Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0679, CVE-2020-0 | 0,9% | — |
| CVE-2020-0678 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles hard links, aka 'Windows Error Reporting Manager Elevation of Privilege Vulnerability'. | 0,9% | — |
| CVE-2013-3694 | MED 6.8 | blackberry blackberry_link BlackBerry Link before 1.2.1.31 on Windows and before 1.1.1 build 39 on Mac OS X does not require authentication for remote file-access folders, which allows remote attackers to read or create arbitrary files via IPv6 WebDAV requests, as demonstrated by a CSRF | 0,9% | — |
| CVE-2026-70449 | MED 5.3 | apache wicket Improper validation of resource URL attributes in Apache Wicket allows an unauthenticated remote attacker to read files from the web application, including files under WEB-INF that the servlet container would not otherwise serve. The locale, style and variati | 0,9% | — |
| CVE-2026-58626 | HIGH 8.8 | microsoft windows_10_21h2 Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network. | 0,9% | — |
| CVE-2026-57092 | CRIT 9.9 | microsoft windows_10_1607 Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network. | 0,9% | — |
| CVE-2026-56647 | HIGH 8.8 | microsoft windows_10_1607 Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized attacker to elevate privileges over a network. | 0,9% | — |
| CVE-2026-56642 | HIGH 8.8 | microsoft fabric_data_warehouse Stack-based buffer overflow in Microsoft Fabric Data Warehouse allows an authorized attacker to execute code over a network. | 0,9% | — |
| CVE-2026-56194 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over a network. | 0,9% | — |
| CVE-2026-50666 | HIGH 8.8 | microsoft windows_10_1607 Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges over a network. | 0,9% | — |
| CVE-2026-49178 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network. | 0,9% | — |
| CVE-2026-48564 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network. | 0,9% | — |
| CVE-2026-48584 | CRIT 9.9 | microsoft azure_synapse Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate privileges over a network. | 0,9% | — |
| CVE-2026-32213 | CRIT 10.0 | microsoft azure_ai_foundry Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network. | 0,9% | — |
| CVE-2025-53136 | MED 5.5 | microsoft windows_10_1507 Exposure of sensitive information to an unauthorized actor in Windows NT OS Kernel allows an authorized attacker to disclose information locally. | 0,9% | — |
| CVE-2023-36712 | HIGH 7.8 | microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability | 0,9% | — |
| CVE-2022-43516 | MED 6.5 | microsoft windows_firewall A Firewall Rule which allows all incoming TCP connections to all programs from any source and to all ports is created in Windows Firewall after Zabbix agent installation (MSI) | 0,9% | — |
| CVE-2021-20488 | MED 6.5 | ibm security_identity_manager IBM Security Identity Manager 6.0.2 could allow an authenticated malicious user to change the passwords of other users in the Windows AD environment when IBM Security Identity Manager Windows Password Synch Plug-in is deployed and configured. IBM X-Force ID: 1 | 0,9% | — |
| CVE-2020-1276 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0986, CVE-2020-1237, CVE-2020-1246, CVE-2020-1262, | 0,9% | — |
| CVE-2020-0845 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Network Connections Service handles objects in memory, aka 'Windows Network Connections Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0778, CVE-2020 | 0,9% | — |
| CVE-2026-23669 | HIGH 8.8 | microsoft windows_10_1607 Use after free in RPC Runtime allows an authorized attacker to execute code over a network. | 0,9% | — |
| CVE-2025-29806 | MED 6.5 | microsoft edge_chromium No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0,9% | — |
| CVE-2022-20747 | MED 6.5 | cisco catalyst_sd-wan_manager A vulnerability in the History API of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain access to sensitive information on an affected system. This vulnerability is due to insufficient API authorization checking on the underly | 0,9% | — |
| CVE-2020-17033 | HIGH 7.8 | microsoft windows_10 Windows Remote Access Elevation of Privilege Vulnerability | 0,9% | — |
| CVE-2020-17032 | HIGH 7.8 | microsoft windows_10 Windows Remote Access Elevation of Privilege Vulnerability | 0,9% | — |