EN
58.007 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.007 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2009-0876 MED 6.9 sun xvm_virtualbox Sun xVM VirtualBox 2.0.0, 2.0.2, 2.0.4, 2.0.6r39760, 2.1.0, 2.1.2, and 2.1.4r42893 on Linux allows local users to gain privileges via a hardlink attack, which preserves setuid/setgid bits on Linux, related to DT_RPATH:$ORIGIN. 0,8%
CVE-2026-20176 CRIT 9.1 A vulnerability in Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid high-privileged administrative creden 0,8%
CVE-2025-66168 MED 5.4 apache activemq WARNING: Users of 6.x should upgrade to 6.2.4 or later as the fix was missed in previous 6.x releases. See the  following for more details: https://activemq.apache.org/security-advisories.data/CVE-2026-40046-announcement.txt https://www.cve.org/CVERecord? 0,8%
CVE-2025-50168 HIGH 7.8 microsoft windows_11_22h2 Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. 0,8%
CVE-2024-54021 MED 6.5 fortinet fortios An Improper Neutralization of CRLF Sequences in HTTP Headers ('http response splitting') vulnerability [CWE-113] in Fortinet FortiOS 7.2.0 through 7.6.0, FortiProxy 7.2.0 through 7.4.5 may allow a remote unauthenticated attacker to bypass the file filter via c 0,8%
CVE-2024-38170 HIGH 7.1 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 0,8%
CVE-2024-30068 HIGH 8.8 microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability 0,8%
CVE-2023-27525 LOW 3.1 apache superset An authenticated user with Gamma role authorization could have access to metadata information using non trivial methods in Apache Superset up to and including 2.0.1 0,8%
CVE-2022-36280 MED 6.3 debian debian_linux An out-of-bounds(OOB) memory access vulnerability was found in vmwgfx driver in drivers/gpu/vmxgfx/vmxgfx_kms.c in GPU component in the Linux kernel with device file '/dev/dri/renderD128 (or Dxxx)'. This flaw allows a local attacker with a user account on the 0,8%
CVE-2022-22998 HIGH 8.0 westerndigital my_cloud_home_duo_firmware Implemented protections on AWS credentials that were not properly protected. 0,8%
CVE-2022-22152 HIGH 7.7 juniper contrail_service_orchestration A Protection Mechanism Failure vulnerability in the REST API of Juniper Networks Contrail Service Orchestration allows one tenant on the system to view confidential configuration details of another tenant on the same system. By utilizing the REST API, one tena 0,8%
CVE-2020-2035 LOW 3.0 paloaltonetworks pan-os When SSL/TLS Forward Proxy Decryption mode has been configured to decrypt the web transactions, the PAN-OS URL filtering feature inspects the HTTP Host and URL path headers for policy enforcement on the decrypted HTTPS web transactions but does not consider Se 0,8%
CVE-2011-3355 HIGH 7.3 gnome evolution-data-server3 evolution-data-server3 3.0.3 through 3.2.1 used insecure (non-SSL) connection when attempting to store sent email messages into the Sent folder, when the Sent folder was located on the remote server. An attacker could use this flaw to obtain login credentials 0,8%
CVE-2017-5035 HIGH 8.1 debian debian_linux Google Chrome prior to 57.0.2987.98 for Windows and Mac had a race condition, which could cause Chrome to display incorrect certificate information for a site. 0,8%
CVE-2016-8395 MED 4.7 linux linux_kernel A denial of service vulnerability in the NVIDIA camera driver could enable an attacker to cause a local permanent denial of service, which may require reflashing the operating system to repair the device. This issue is rated as High due to the possibility of l 0,8%
CVE-2014-3820 MED 4.3 juniper junos_pulse_access_control_service Cross-site scripting (XSS) vulnerability in the SSL VPN/UAC web server in the Juniper Junos Pulse Secure Access Service (SSL VPN) devices with IVE OS 7.1 before 7.1r16, 7.4 before 7.4r3, and 8.0 before 8.0r1 and the Juniper Junos Pulse Access Control Service d 0,8%
CVE-2009-0058 MED 6.1 cisco 4400_wireless_lan_controller The Cisco Wireless LAN Controller (WLC), Cisco Catalyst 6500 Wireless Services Module (WiSM), and Cisco Catalyst 3750 Integrated Wireless LAN Controller with software 4.x before 4.2.176.0 and 5.x before 5.2 allow remote attackers to cause a denial of service ( 0,8%
CVE-2026-69724 HIGH 8.8 microsoft sharepoint_server Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 0,8%
CVE-2026-71257 HIGH 7.5 apache wicket Apache Wicket enforces the upload limits configured on a form or upload field while parsing a multipart request with Apache Commons FileUpload. If the request body has already been consumed by another component, Commons FileUpload returns no items and Wicket f 0,8%
CVE-2026-65927 HIGH 7.5 apache tomcat Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag on the rewrite valves causes rewrite processing to restart at the second rule rather than the first rule. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1. 0,8%
CVE-2026-67260 HIGH 7.3 apache airflow Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That sweep deserializes the task instance's `next_kwargs` without an allow-list, so a Dag author — who controls that value throug 0,8%
CVE-2024-56180 CRIT 9.8 apache eventmesh CWE-502 Deserialization of Untrusted Data at the eventmesh-meta-raft plugin module in Apache EventMesh master branch without release version on windows\linux\mac os e.g. platforms allows attackers to send controlled message and remote code execute via hessian 0,8%
CVE-2024-24773 MED 4.9 apache superset Improper parsing of nested SQL statements on SQLLab would allow authenticated users to surpass their data authorization scope. This issue affects Apache Superset: before 3.0.4, from 3.1.0 before 3.1.1. Users are recommended to upgrade to version 3.1.1, which 0,8%
CVE-2022-24513 HIGH 7.8 microsoft visual_studio_2019 Visual Studio Elevation of Privilege Vulnerability 0,8%
CVE-2020-0912 HIGH 7.0 microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Function Discovery SSDP Provider improperly handles memory.</p> <p>To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run 0,8%