EN
57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

57.971 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2026-45584 HIGH 8.1 microsoft malware_protection_engine Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network. 0,9%
CVE-2025-49670 MED 6.5 microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. 0,9%
CVE-2023-30867 MED 4.9 apache streampark In the Streampark platform, when users log in to the system and use certain features, some pages provide a name-based fuzzy search, such as job names, role names, etc. The sql syntax :select * from table where jobName like '%jobName%'. However, the jobName fie 0,9%
CVE-2023-36030 MED 6.1 microsoft dynamics_365 Microsoft Dynamics 365 Sales Spoofing Vulnerability 0,9%
CVE-2021-26428 MED 4.4 microsoft azure_sphere Azure Sphere Information Disclosure Vulnerability 0,9%
CVE-2021-34462 HIGH 7.0 microsoft windows_10 Windows AppX Deployment Extensions Elevation of Privilege Vulnerability 0,9%
CVE-2021-20486 MED 6.5 ibm cloud_pak_for_data IBM Cloud Pak for Data 3.0 could allow an authenticated user to obtain sensitive information when installed with additional plugins. IBM X-Force ID: 197668. 0,9%
CVE-2021-22113 MED 5.3 vmware spring_cloud_netflix_zuul Applications using the “Sensitive Headers” functionality in Spring Cloud Netflix Zuul 2.2.6.RELEASE and below may be vulnerable to bypassing the “Sensitive Headers” restriction when executing requests with specially constructed URLs. Applications that use Spri 0,9%
CVE-2021-1695 HIGH 7.8 microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability 0,9%
CVE-2019-18654 MED 6.1 avg anti-virus A Cross Site Scripting (XSS) issue exists in AVG AntiVirus (Internet Security Edition) 19.3.3084 build 19.3.4241.440 in the Network Notification Popup, allowing an attacker to execute JavaScript code via an SSID Name. 0,9%
CVE-2019-18653 MED 6.1 avast antivirus A Cross Site Scripting (XSS) issue exists in Avast AntiVirus (Free, Internet Security, and Premiere Edition) 19.3.2369 build 19.3.4241.440 in the Network Notification Popup, allowing an attacker to execute JavaScript code via an SSID Name. 0,9%
CVE-2011-1898 HIGH 7.4 citrix xen Xen 4.1 before 4.1.1 and 4.0 before 4.0.2, when using PCI passthrough on Intel VT-d chipsets that do not have interrupt remapping, allows guest OS users to gain host OS privileges by "using DMA to generate MSI interrupts by writing to the interrupt injection r 0,9%
CVE-2009-3043 MED 4.9 linux linux_kernel The tty_ldisc_hangup function in drivers/char/tty_ldisc.c in the Linux kernel 2.6.31-rc before 2.6.31-rc8 allows local users to cause a denial of service (system crash, sometimes preceded by a NULL pointer dereference) or possibly gain privileges via certain p 0,9%
CVE-2026-78456 HIGH 8.8 microsoft sql_server_2022 Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. 0,9%
CVE-2023-36728 MED 5.5 microsoft odbc_driver_for_sql_server Microsoft SQL Server Denial of Service Vulnerability 0,9%
CVE-2022-26803 HIGH 7.8 microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability 0,9%
CVE-2022-26798 HIGH 7.8 microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability 0,9%
CVE-2020-16998 HIGH 7.0 microsoft windows_10 DirectX Elevation of Privilege Vulnerability 0,9%
CVE-2020-12815 MED 5.4 fortinet fortianalyzer An improper neutralization of input vulnerability in FortiTester before 3.9.0 may allow a remote authenticated attacker to inject script related HTML tags via IPv4/IPv6 address fields. 0,9%
CVE-2017-5051 HIGH 8.8 google chrome An integer overflow in FFmpeg in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to perform an out of bounds memory write via a crafted video file, related to ChunkDemuxer. 0,9%
CVE-2025-25006 MED 5.3 microsoft exchange_server Improper handling of additional special element in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. 0,9%
CVE-2025-21323 MED 5.5 microsoft windows_10_1507 Windows Kernel Memory Information Disclosure Vulnerability 0,9%
CVE-2025-21317 MED 5.5 microsoft windows_10_21h2 Windows Kernel Memory Information Disclosure Vulnerability 0,9%
CVE-2024-32117 MED 4.9 fortinet fortianalyzer An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.4.0 through 7.4.2 and below 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and below 7.2.5 & FortiAnalyzer-BigData ver 0,9%
CVE-2021-31937 HIGH 8.2 microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 0,9%