57.977 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.977 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-66303 | MED 6.5 | microsoft skype_for_business_server Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network. | 0,8% | — |
| CVE-2026-67633 | MED 6.5 | microsoft sql_server_2017 Out-of-bounds read in SQL Server allows an authorized attacker to deny service over a network. | 0,8% | — |
| CVE-2025-4615 | HIGH 7.2 | paloaltonetworks pan-os An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and execute arbitrary commands. The security risk posed by this issu | 0,8% | — |
| CVE-2024-38198 | HIGH 7.5 | microsoft windows_10_1507 Windows Print Spooler Elevation of Privilege Vulnerability | 0,8% | — |
| CVE-2024-38056 | MED 5.5 | microsoft windows_10_1507 Microsoft Windows Codecs Library Information Disclosure Vulnerability | 0,8% | — |
| CVE-2024-38055 | MED 5.5 | microsoft windows_10_1507 Microsoft Windows Codecs Library Information Disclosure Vulnerability | 0,8% | — |
| CVE-2022-41064 | MED 5.8 | microsoft .net_framework .NET Framework Information Disclosure Vulnerability | 0,8% | — |
| CVE-2022-23263 | HIGH 7.7 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 0,8% | — |
| CVE-2021-26442 | HIGH 7.0 | microsoft windows_10 Windows HTTP.sys Elevation of Privilege Vulnerability | 0,8% | — |
| CVE-2021-3045 | MED 4.9 | paloaltonetworks pan-os An OS command argument injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator to read any arbitrary file from the file system. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.19; PAN-OS 9.0 | 0,8% | — |
| CVE-2021-26890 | HIGH 7.8 | microsoft windows_10 Application Virtualization Remote Code Execution Vulnerability | 0,8% | — |
| CVE-2020-1660 | HIGH 8.3 | juniper junos When DNS filtering is enabled on Juniper Networks Junos MX Series with one of the following cards MS-PIC, MS-MIC or MS-MPC, an incoming stream of packets processed by the Multiservices PIC Management Daemon (mspmand) process, responsible for managing "URL Filt | 0,8% | — |
| CVE-2020-3384 | HIGH 8.2 | cisco data_center_network_manager A vulnerability in specific REST API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to inject arbitrary commands on the underlying operating system with the privileges of the logged-in user. The vulnerabilit | 0,8% | — |
| CVE-2018-0208 | MED 5.4 | cisco email_encryption A vulnerability in the web-based management interface of the (cloud based) Cisco Registered Envelope Service could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of th | 0,8% | — |
| CVE-2026-43499 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: rtmutex: Use waiter::task instead of current in remove_waiter() remove_waiter() is used by the slowlock paths, but it is also used for proxy-lock rollback in rt_mutex_start_proxy_lock() when | 0,8% | — |
| CVE-2026-40415 | HIGH 8.1 | microsoft windows_10_1809 Use after free in Windows TCP/IP allows an unauthorized attacker to execute code over a network. | 0,8% | — |
| CVE-2025-4598 | MED 4.7 | debian debian_linux A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original's privileged process coredump, allowing the attacker to read sensitive data, such as /etc/ | 0,8% | — |
| CVE-2024-49996 | CRIT 9.4 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: cifs: Fix buffer overflow when parsing NFS reparse points ReparseDataLength is sum of the InodeType size and DataBuffer size. So to get DataBuffer size it is needed to subtract InodeType's s | 0,8% | — |
| CVE-2022-45412 | HIGH 8.8 | mozilla firefox When resolving a symlink such as <code>file:///proc/self/fd/1</code>, an error message may be produced where the symlink was resolved to a string containing unitialized memory in the buffer. <br>*This bug only affects Thunderbird on Unix-based operated systems | 0,8% | — |
| CVE-2005-2973 | LOW 2.1 | linux linux_kernel The udp_v6_get_port function in udp.c in Linux 2.6 before 2.6.14-rc5, when running IPv6, allows local users to cause a denial of service (infinite loop and crash). | 0,8% | — |
| CVE-2001-0907 | LOW 2.1 | linux linux_kernel Linux kernel 2.2.1 through 2.2.19, and 2.4.1 through 2.4.10, allows local users to cause a denial of service via a series of deeply nested symlinks, which causes the kernel to spend extra time when trying to access the link. | 0,8% | — |
| CVE-2026-23231 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix use-after-free in nf_tables_addchain() nf_tables_addchain() publishes the chain to table->chains via list_add_tail_rcu() (in nft_chain_add()) before registering hoo | 0,8% | — |
| CVE-2025-55326 | HIGH 7.5 | microsoft windows_10_1809 Use after free in Connected Devices Platform Service (Cdpsvc) allows an unauthorized attacker to execute code over a network. | 0,8% | — |
| CVE-2025-24783 | HIGH 7.5 | apache cocoon ** UNSUPPORTED WHEN ASSIGNED ** Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG) vulnerability in Apache Cocoon. This issue affects Apache Cocoon: all versions. When a continuation is created, it gets a random identifier. Because the random | 0,8% | — |
| CVE-2024-38183 | CRIT 9.8 | microsoft groupme An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network. | 0,8% | — |