57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.971 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2020-0989 | MED 5.5 | microsoft windows_10 <p>An information disclosure vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions. An attacker who successfully exploited this vulnerability could bypass access restrictions to read files.</p> <p>To exploit | 0,9% | — |
| CVE-2020-0858 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the "Public Account Pictures" folder improperly handles junctions.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Elevation of Privil | 0,9% | — |
| CVE-2017-6675 | MED 6.1 | cisco industrial_network_director A vulnerability in the web interface of Cisco Industrial Network Director could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against an affected system. More Information: CSCvd25405. Known Affected Releases | 0,9% | — |
| CVE-2013-0885 | HIGH 7.5 | google chrome Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly restrict API privileges during interaction with the Chrome Web Store, which has unspecified impact and attack vectors. | 0,9% | — |
| CVE-2026-78445 | CRIT 9.8 | microsoft windows_server_2012 Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network. | 0,9% | — |
| CVE-2026-40379 | CRIT 9.3 | microsoft entra_id Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to perform spoofing over a network. | 0,9% | — |
| CVE-2022-20814 | HIGH 7.4 | cisco telepresence_video_communication_server A vulnerability in the certificate validation of Cisco Expressway-C and Cisco TelePresence VCS could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data. The vulnerability is due to a lack of validation | 0,9% | — |
| CVE-2023-30995 | HIGH 7.5 | ibm aspera_faspex IBM Aspera Faspex 4.0 through 4.4.2 and 5.0 through 5.0.5 could allow a malicious actor to bypass IP whitelist restrictions using a specially crafted HTTP request. IBM X-Force ID: 254268. | 0,9% | — |
| CVE-2022-35822 | HIGH 7.1 | microsoft windows_10 Windows Defender Credential Guard Security Feature Bypass Vulnerability | 0,9% | — |
| CVE-2021-36967 | HIGH 8.0 | microsoft windows_10 Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability | 0,9% | — |
| CVE-2019-1719 | MED 6.1 | cisco identity_services_engine A vulnerability in the web-based guest portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerability is due to | 0,9% | — |
| CVE-2018-0367 | MED 5.4 | cisco registered_envelope_service A vulnerability in the web-based management interface of the Cisco Registered Envelope Service could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the affected ser | 0,9% | — |
| CVE-2018-0003 | MED 6.5 | juniper junos A specially crafted MPLS packet received or processed by the system, on an interface configured with MPLS, will store information in the system memory. Subsequently, if this stored information is accessed, this may result in a kernel crash leading to a denial | 0,9% | — |
| CVE-2017-4940 | MED 6.1 | vmware esxi The ESXi Host Client in VMware ESXi (6.5 before ESXi650-201712103-SG, 5.5 before ESXi600-201711103-SG and 5.5 before ESXi550-201709102-SG) contains a vulnerability that may allow for stored cross-site scripting (XSS). An attacker can exploit this vulnerability | 0,9% | — |
| CVE-2010-4243 | MED 4.9 | linux linux_kernel fs/exec.c in the Linux kernel before 2.6.37 does not enable the OOM Killer to assess use of stack memory by arrays representing the (1) arguments and (2) environment, which allows local users to cause a denial of service (memory consumption) via a crafted exec | 0,9% | — |
| CVE-2010-3858 | MED 4.9 | canonical ubuntu_linux The setup_arg_pages function in fs/exec.c in the Linux kernel before 2.6.36, when CONFIG_STACK_GROWSDOWN is used, does not properly restrict the stack memory consumption of the (1) arguments and (2) environment for a 32-bit application on a 64-bit platform, wh | 0,9% | — |
| CVE-2026-73010 | CRIT 9.8 | microsoft windows_10_1809 Use after free in Windows Failover Cluster allows an unauthorized attacker to execute code over a network. | 0,9% | — |
| CVE-2026-73009 | CRIT 9.8 | microsoft windows_10_1607 Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network. | 0,9% | — |
| CVE-2026-20191 | HIGH 7.5 | cisco catalyst_center A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from a restricted container. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this v | 0,9% | — |
| CVE-2026-32173 | HIGH 8.6 | microsoft azure_sre_agent Improper authentication in Azure SRE Agent allows an unauthorized attacker to disclose information over a network. | 0,9% | — |
| CVE-2025-49752 | CRIT 10.0 | microsoft azure_bastion_developer Azure Bastion Elevation of Privilege Vulnerability | 0,9% | — |
| CVE-2025-58717 | MED 6.5 | microsoft windows_10_1507 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 0,9% | — |
| CVE-2025-55700 | MED 6.5 | microsoft windows_10_1507 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 0,9% | — |
| CVE-2024-47571 | HIGH 8.1 | fortinet fortimanager An operation on a resource after expiration or release in Fortinet FortiManager 6.4.12 through 7.4.0 allows an attacker to gain improper access to FortiGate via valid credentials. | 0,9% | — |
| CVE-2024-3385 | HIGH 7.5 | paloaltonetworks pan-os A packet processing mechanism in Palo Alto Networks PAN-OS software enables a remote attacker to reboot hardware-based firewalls. Repeated attacks eventually cause the firewall to enter maintenance mode, which requires manual intervention to bring the firewall | 0,9% | — |