58.015 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.015 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2024-49027 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 0,8% | — |
| CVE-2024-49021 | HIGH 7.8 | microsoft sql_server_2016 Microsoft SQL Server Remote Code Execution Vulnerability | 0,8% | — |
| CVE-2021-47397 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: sctp: break out if skb_header_pointer returns NULL in sctp_rcv_ootb We should always check if skb_header_pointer's return is NULL before using it, otherwise it may cause null-ptr-deref, as s | 0,8% | — |
| CVE-2022-44687 | HIGH 7.8 | microsoft raw_image_extension Raw Image Extension Remote Code Execution Vulnerability | 0,8% | — |
| CVE-2022-44668 | HIGH 7.8 | microsoft windows_10 Windows Media Remote Code Execution Vulnerability | 0,8% | — |
| CVE-2022-44667 | HIGH 7.8 | microsoft windows_10 Windows Media Remote Code Execution Vulnerability | 0,8% | — |
| CVE-2021-3864 | HIGH 7.0 | debian debian_linux A flaw was found in the way the dumpable flag setting was handled when certain SUID binaries executed its descendants. The prerequisite is a SUID binary that sets real UID equal to effective UID, and real GID equal to effective GID. The descendant will then ha | 0,8% | — |
| CVE-2022-22953 | MED 6.5 | vmware vmware_hcx VMware HCX update addresses an information disclosure vulnerability. A malicious actor with network user access to the VMware HCX appliance may be able to gain access to sensitive information. | 0,8% | — |
| CVE-2021-23055 | MED 6.5 | f5 nginx_ingress_controller On version 2.x before 2.0.3 and 1.x before 1.12.3, the command line restriction that controls snippet use with NGINX Ingress Controller does not apply to Ingress objects. Note: Software versions which have reached End of Technical Support (EoTS) are not evalua | 0,8% | — |
| CVE-2022-26791 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0,8% | — |
| CVE-2022-26789 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0,8% | — |
| CVE-2021-43243 | MED 5.5 | microsoft vp9_video_extensions VP9 Video Extensions Information Disclosure Vulnerability | 0,8% | — |
| CVE-2021-43235 | MED 5.5 | microsoft windows_10 Storage Spaces Controller Information Disclosure Vulnerability | 0,8% | — |
| CVE-2021-43227 | MED 5.5 | microsoft windows_10 Storage Spaces Controller Information Disclosure Vulnerability | 0,8% | — |
| CVE-2021-28317 | MED 5.5 | microsoft windows_10 Microsoft Windows Codecs Library Information Disclosure Vulnerability | 0,8% | — |
| CVE-2017-3877 | MED 6.5 | cisco unified_communications_manager A vulnerability in the web framework of Cisco Unified Communications Manager (CallManager) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of the web interface of the affected software. More | 0,8% | — |
| CVE-2010-4685 | MED 4.0 | cisco ios Cisco IOS before 15.0(1)XA1 does not clear the public key cache upon a change to a certificate map, which allows remote authenticated users to bypass a certificate ban by connecting with a banned certificate that had previously been valid, aka Bug ID CSCta7903 | 0,8% | — |
| CVE-2026-69875 | HIGH 8.0 | microsoft windows_10_1809 Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network. | 0,8% | — |
| CVE-2026-69505 | HIGH 8.0 | microsoft windows_10_1607 Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges over a network. | 0,8% | — |
| CVE-2026-69503 | HIGH 8.0 | microsoft windows_10_1809 Stack-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges over a network. | 0,8% | — |
| CVE-2026-69461 | HIGH 8.8 | microsoft windows_10_1607 Stack-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code over a network. | 0,8% | — |
| CVE-2025-47162 | HIGH 8.4 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | 0,8% | — |
| CVE-2024-39462 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: clk: bcm: dvp: Assign ->num before accessing ->hws Commit f316cdff8d67 ("clk: Annotate struct clk_hw_onecell_data with __counted_by") annotated the hws member of 'struct clk_hw_onecell_data' | 0,8% | — |
| CVE-2021-47064 | MED 5.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mt76: fix potential DMA mapping leak With buf uninitialized in mt76_dma_tx_queue_skb_raw, its field skip_unmap could potentially inherit a non-zero value from stack garbage. If this happens, | 0,8% | — |
| CVE-2022-45934 | HIGH 7.8 | debian debian_linux An issue was discovered in the Linux kernel through 6.0.10. l2cap_config_req in net/bluetooth/l2cap_core.c has an integer wraparound via L2CAP_CONF_REQ packets. | 0,8% | — |