57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.971 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2021-42327 | MED 6.7 | fedoraproject fedora dp_link_settings_write in drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_debugfs.c in the Linux kernel through 5.14.14 allows a heap-based buffer overflow by an attacker who can write a string to the AMD GPU display drivers debug filesystem. There are no chec | 0,9% | — |
| CVE-2021-0269 | HIGH 8.8 | juniper junos The improper handling of client-side parameters in J-Web of Juniper Networks Junos OS allows an attacker to perform a number of different malicious actions against a target device when a user is authenticated to J-Web. An attacker may be able to supersede exis | 0,9% | — |
| CVE-2021-22995 | HIGH 7.5 | f5 big-iq_centralized_management On all 7.x and 6.x versions (fixed in 8.0.0), BIG-IQ high availability (HA) when using a Quorum device for automatic failover does not implement any form of authentication with the Corosync daemon. Note: Software versions which have reached End of Software Dev | 0,9% | — |
| CVE-2020-16973 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations.</p> <p>To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specia | 0,9% | — |
| CVE-2020-16909 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files. The vulnerability could allow elevation of privilege if an attacker can successfully exploit it.</p> <p>An attacker who successfully exploit | 0,9% | — |
| CVE-2019-1683 | HIGH 7.4 | cisco spa112_firmware A vulnerability in the certificate handling component of the Cisco SPA112, SPA525, and SPA5X5 Series IP Phones could allow an unauthenticated, remote attacker to listen to or control some aspects of a Transport Level Security (TLS)-encrypted Session Initiation | 0,9% | — |
| CVE-2015-4205 | MED 5.7 | cisco ios_xr Cisco IOS XR 5.3.1 on ASR 9000 devices allows remote attackers to cause a denial of service (NPU chip reset or line-card reload) by sending crafted IEEE 802.3x flow-control PAUSE frames on the local network, aka Bug ID CSCut19959. | 0,9% | — |
| CVE-2025-21756 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: vsock: Keep the binding until socket destruction Preserve sockets bindings; this includes both resulting from an explicit bind() and those implicitly bound through autobind during connect(). | 0,9% | — |
| CVE-2024-26016 | MED 4.3 | apache superset A low privilege authenticated user could import an existing dashboard or chart that they do not have access to and then modify its metadata, thereby gaining ownership of the object. However, it's important to note that access to the analytical data of these ch | 0,9% | — |
| CVE-2023-28301 | LOW 3.7 | microsoft edge Microsoft Edge (Chromium-based) Tampering Vulnerability | 0,9% | — |
| CVE-2023-21766 | MED 4.7 | microsoft windows_10 Windows Overlay Filter Information Disclosure Vulnerability | 0,9% | — |
| CVE-2021-38869 | CRIT 9.8 | ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.3, 7.4, and 7.5 in some situations may not automatically log users out after they exceede their idle timeout. IBM X-Force ID: 208341. | 0,9% | — |
| CVE-2021-40126 | MED 4.3 | cisco umbrella A vulnerability in the web-based dashboard of Cisco Umbrella could allow an authenticated, remote attacker to perform an email enumeration attack against the Umbrella infrastructure. This vulnerability is due to an overly descriptive error message on the dashb | 0,9% | — |
| CVE-2021-31350 | HIGH 7.5 | juniper junos An Improper Privilege Management vulnerability in the gRPC framework, used by the Juniper Extension Toolkit (JET) API on Juniper Networks Junos OS and Junos OS Evolved, allows a network-based, low-privileged authenticated attacker to perform operations as root | 0,9% | — |
| CVE-2021-34702 | MED 4.3 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information. This vulnerability is due to improper enforcement of administrator privilege levels for | 0,9% | — |
| CVE-2021-34765 | MED 4.3 | cisco nexus_insights A vulnerability in the web UI for Cisco Nexus Insights could allow an authenticated, remote attacker to view and download files related to the web application. The attacker requires valid device credentials. This vulnerability exists because proper role-based | 0,9% | — |
| CVE-2021-1562 | MED 4.3 | cisco broadworks_application_server A vulnerability in the XSI-Actions interface of Cisco BroadWorks Application Server could allow an authenticated, remote attacker to access sensitive information on an affected system. This vulnerability is due to improper input validation and authorization of | 0,9% | — |
| CVE-2021-26898 | HIGH 7.8 | microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability | 0,9% | — |
| CVE-2018-15310 | MED 4.3 | f5 big-ip_access_policy_manager A vulnerability in BIG-IP APM portal access 11.5.1-11.5.7, 11.6.0-11.6.3, and 12.1.0-12.1.3 discloses the BIG-IP software version in rewritten pages. | 0,9% | — |
| CVE-2014-3379 | MED 6.1 | cisco ios_xr Cisco IOS XR 5.1 and earlier on Network Convergence System 6000 devices allows remote attackers to cause a denial of service (NPU and card hang or reload) via a malformed MPLS packet, aka Bug ID CSCuq10466. | 0,9% | — |
| CVE-2002-1380 | LOW 2.1 | linux linux_kernel Linux kernel 2.2.x allows local users to cause a denial of service (crash) by using the mmap() function with a PROT_READ parameter to access non-readable memory pages through the /proc/pid/mem interface. | 0,9% | — |
| CVE-2026-77890 | HIGH 7.5 | microsoft windows_10_1607 Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | 0,9% | — |
| CVE-2026-77499 | HIGH 7.5 | microsoft windows_10_1607 Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | 0,9% | — |
| CVE-2026-40473 | HIGH 8.8 | apache camel The camel-mina component's MinaConverter.toObjectInput(IoBuffer) type converter wraps an IoBuffer in a java.io.ObjectInputStream without applying any ObjectInputFilter or class-loading restrictions. When a Camel route uses camel-mina as a TCP or UDP consumer a | 0,9% | — |
| CVE-2025-26627 | HIGH 7.0 | microsoft azure_arc Improper neutralization of special elements used in a command ('command injection') in Azure Arc allows an authorized attacker to elevate privileges locally. | 0,9% | — |