EN
57.977 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

57.977 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2026-66303 MED 6.5 microsoft skype_for_business_server Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network. 0,8%
CVE-2026-67633 MED 6.5 microsoft sql_server_2017 Out-of-bounds read in SQL Server allows an authorized attacker to deny service over a network. 0,8%
CVE-2025-4615 HIGH 7.2 paloaltonetworks pan-os An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and execute arbitrary commands. The security risk posed by this issu 0,8%
CVE-2024-38198 HIGH 7.5 microsoft windows_10_1507 Windows Print Spooler Elevation of Privilege Vulnerability 0,8%
CVE-2024-38056 MED 5.5 microsoft windows_10_1507 Microsoft Windows Codecs Library Information Disclosure Vulnerability 0,8%
CVE-2024-38055 MED 5.5 microsoft windows_10_1507 Microsoft Windows Codecs Library Information Disclosure Vulnerability 0,8%
CVE-2022-41064 MED 5.8 microsoft .net_framework .NET Framework Information Disclosure Vulnerability 0,8%
CVE-2022-23263 HIGH 7.7 microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 0,8%
CVE-2021-26442 HIGH 7.0 microsoft windows_10 Windows HTTP.sys Elevation of Privilege Vulnerability 0,8%
CVE-2021-3045 MED 4.9 paloaltonetworks pan-os An OS command argument injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator to read any arbitrary file from the file system. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.19; PAN-OS 9.0 0,8%
CVE-2021-26890 HIGH 7.8 microsoft windows_10 Application Virtualization Remote Code Execution Vulnerability 0,8%
CVE-2020-1660 HIGH 8.3 juniper junos When DNS filtering is enabled on Juniper Networks Junos MX Series with one of the following cards MS-PIC, MS-MIC or MS-MPC, an incoming stream of packets processed by the Multiservices PIC Management Daemon (mspmand) process, responsible for managing "URL Filt 0,8%
CVE-2020-3384 HIGH 8.2 cisco data_center_network_manager A vulnerability in specific REST API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to inject arbitrary commands on the underlying operating system with the privileges of the logged-in user. The vulnerabilit 0,8%
CVE-2018-0208 MED 5.4 cisco email_encryption A vulnerability in the web-based management interface of the (cloud based) Cisco Registered Envelope Service could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of th 0,8%
CVE-2026-43499 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: rtmutex: Use waiter::task instead of current in remove_waiter() remove_waiter() is used by the slowlock paths, but it is also used for proxy-lock rollback in rt_mutex_start_proxy_lock() when 0,8%
CVE-2026-40415 HIGH 8.1 microsoft windows_10_1809 Use after free in Windows TCP/IP allows an unauthorized attacker to execute code over a network. 0,8%
CVE-2025-4598 MED 4.7 debian debian_linux A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original's privileged process coredump, allowing the attacker to read sensitive data, such as /etc/ 0,8%
CVE-2024-49996 CRIT 9.4 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: cifs: Fix buffer overflow when parsing NFS reparse points ReparseDataLength is sum of the InodeType size and DataBuffer size. So to get DataBuffer size it is needed to subtract InodeType's s 0,8%
CVE-2022-45412 HIGH 8.8 mozilla firefox When resolving a symlink such as <code>file:///proc/self/fd/1</code>, an error message may be produced where the symlink was resolved to a string containing unitialized memory in the buffer. <br>*This bug only affects Thunderbird on Unix-based operated systems 0,8%
CVE-2005-2973 LOW 2.1 linux linux_kernel The udp_v6_get_port function in udp.c in Linux 2.6 before 2.6.14-rc5, when running IPv6, allows local users to cause a denial of service (infinite loop and crash). 0,8%
CVE-2001-0907 LOW 2.1 linux linux_kernel Linux kernel 2.2.1 through 2.2.19, and 2.4.1 through 2.4.10, allows local users to cause a denial of service via a series of deeply nested symlinks, which causes the kernel to spend extra time when trying to access the link. 0,8%
CVE-2026-23231 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix use-after-free in nf_tables_addchain() nf_tables_addchain() publishes the chain to table->chains via list_add_tail_rcu() (in nft_chain_add()) before registering hoo 0,8%
CVE-2025-55326 HIGH 7.5 microsoft windows_10_1809 Use after free in Connected Devices Platform Service (Cdpsvc) allows an unauthorized attacker to execute code over a network. 0,8%
CVE-2025-24783 HIGH 7.5 apache cocoon ** UNSUPPORTED WHEN ASSIGNED ** Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG) vulnerability in Apache Cocoon. This issue affects Apache Cocoon: all versions. When a continuation is created, it gets a random identifier. Because the random 0,8%
CVE-2024-38183 CRIT 9.8 microsoft groupme An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network. 0,8%