EN
57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

57.971 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2025-54917 MED 4.3 microsoft windows_10_1507 Protection mechanism failure in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network. 0,9%
CVE-2023-45284 MED 5.3 golang go On Windows, The IsLocal function does not correctly detect reserved device names in some cases. Reserved names followed by spaces, such as "COM1 ", and reserved names "COM" and "LPT" followed by superscript 1, 2, or 3, are incorrectly reported as local. With f 0,9%
CVE-2023-27871 HIGH 7.5 ibm aspera_faspex IBM Aspera Faspex 4.4.2 could allow a remote attacker to obtain sensitive credential information for an external user, using a specially crafted SQL query. IBM X-Force ID: 249613. 0,9%
CVE-2022-20918 HIGH 7.5 cisco firepower_services_software_for_asa A vulnerability in the Simple Network Management Protocol (SNMP) access controls for Cisco FirePOWER Software for Adaptive Security Appliance (ASA) FirePOWER module, Cisco Firepower Management Center (FMC) Software, and Cisco Next-Generation Intrusion Preventi 0,9%
CVE-2021-44226 HIGH 7.3 razer synapse Razer Synapse before 3.7.0228.022817 allows privilege escalation because it relies on %PROGRAMDATA%\Razer\Synapse3\Service\bin even if %PROGRAMDATA%\Razer has been created by any unprivileged user before Synapse is installed. The unprivileged user may have pla 0,9%
CVE-2021-24010 HIGH 8.1 fortinet fortisandbox Improper limitation of a pathname to a restricted directory vulnerabilities in FortiSandbox 3.2.0 through 3.2.2, and 3.1.0 through 3.1.4 may allow an authenticated user to obtain unauthorized access to files and data via specifially crafted web requests. 0,9%
CVE-2021-33767 HIGH 8.2 microsoft open_enclave_software_development_kit Open Enclave SDK Elevation of Privilege Vulnerability 0,9%
CVE-2020-0697 HIGH 7.8 microsoft office_365_proplus An elevation of privilege vulnerability exists in Microsoft Office OLicenseHeartbeat task, where an attacker who successfully exploited this vulnerability could run this task as SYSTEM.To exploit the vulnerability, an authenticated attacker would need to place 0,9%
CVE-2019-1018 HIGH 7.0 microsoft windows_10 An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delet 0,9%
CVE-2019-1017 HIGH 7.0 microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install pr 0,9%
CVE-2019-1014 HIGH 7.0 microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install pr 0,9%
CVE-2019-0984 HIGH 7.0 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context. To exploit the vuln 0,9%
CVE-2019-0960 HIGH 7.0 microsoft windows_7 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install pr 0,9%
CVE-2018-0255 HIGH 8.8 cisco ios A vulnerability in the device manager web interface of Cisco Industrial Ethernet Switches could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of an affected system. The vulnerability is due to in 0,9%
CVE-2017-3005 HIGH 7.8 adobe photoshop_cc Adobe Photoshop versions CC 2017 (18.0.1) and earlier, CC 2015.5.1 (17.0.1) and earlier have an unquoted search path vulnerability. 0,9%
CVE-2013-1199 MED 4.9 cisco adaptive_security_appliance Race condition in the CIFS implementation in the rewriter module in the Clientless SSL VPN component on Cisco Adaptive Security Appliances (ASA) devices allows remote authenticated users to cause a denial of service (device reload) by accessing resources withi 0,9%
CVE-2026-42779 CRIT 9.8 apache mina The fix for CVE-2026-41635 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: Apache MINA's AbstractIoBuffer.resolveClass() contains two branches, one of them (for static classes or primitive types) does not ch 0,9%
CVE-2025-48824 HIGH 8.8 microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. 0,9%
CVE-2024-33868 CRIT 9.8 linqi linqi An issue was discovered in linqi before 1.4.0.1 on Windows. There is LDAP injection. 0,9%
CVE-2024-21382 MED 4.3 microsoft edge_chromium Microsoft Edge for Android Information Disclosure Vulnerability 0,9%
CVE-2023-20010 HIGH 8.1 cisco unified_communications_manager A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to conduct SQL injecti 0,9%
CVE-2021-26619 HIGH 7.1 bigfile bigfileagent An path traversal vulnerability leading to delete arbitrary files was discovered in BigFileAgent. Remote attackers can use this vulnerability to delete arbitrary files of unspecified number of users. 0,9%
CVE-2021-32591 MED 5.3 fortinet fortiadc A missing cryptographic steps vulnerability in the function that encrypts users' LDAP and RADIUS credentials in FortiSandbox before 4.0.1, FortiWeb before 6.3.12, FortiADC before 6.2.1, FortiMail 7.0.1 and earlier may allow an attacker in possession of the pas 0,9%
CVE-2019-1577 MED 6.3 paloaltonetworks traps Code injection vulnerability in Palo Alto Networks Traps 5.0.5 and earlier may allow an authenticated attacker to inject arbitrary JavaScript or HTML. 0,9%
CVE-2017-4930 MED 5.4 vmware airwatch VMware AirWatch Console 9.x prior to 9.2.0 contains a vulnerability that could allow an authenticated AWC user to add a malicious URL to an enrolled device's 'Links' page. Successful exploitation of this issue could result in an unsuspecting AWC user being red 0,9%