EN
58.015 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.015 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2024-49027 HIGH 7.8 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 0,8%
CVE-2024-49021 HIGH 7.8 microsoft sql_server_2016 Microsoft SQL Server Remote Code Execution Vulnerability 0,8%
CVE-2021-47397 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: sctp: break out if skb_header_pointer returns NULL in sctp_rcv_ootb We should always check if skb_header_pointer's return is NULL before using it, otherwise it may cause null-ptr-deref, as s 0,8%
CVE-2022-44687 HIGH 7.8 microsoft raw_image_extension Raw Image Extension Remote Code Execution Vulnerability 0,8%
CVE-2022-44668 HIGH 7.8 microsoft windows_10 Windows Media Remote Code Execution Vulnerability 0,8%
CVE-2022-44667 HIGH 7.8 microsoft windows_10 Windows Media Remote Code Execution Vulnerability 0,8%
CVE-2021-3864 HIGH 7.0 debian debian_linux A flaw was found in the way the dumpable flag setting was handled when certain SUID binaries executed its descendants. The prerequisite is a SUID binary that sets real UID equal to effective UID, and real GID equal to effective GID. The descendant will then ha 0,8%
CVE-2022-22953 MED 6.5 vmware vmware_hcx VMware HCX update addresses an information disclosure vulnerability. A malicious actor with network user access to the VMware HCX appliance may be able to gain access to sensitive information. 0,8%
CVE-2021-23055 MED 6.5 f5 nginx_ingress_controller On version 2.x before 2.0.3 and 1.x before 1.12.3, the command line restriction that controls snippet use with NGINX Ingress Controller does not apply to Ingress objects. Note: Software versions which have reached End of Technical Support (EoTS) are not evalua 0,8%
CVE-2022-26791 HIGH 7.8 microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability 0,8%
CVE-2022-26789 HIGH 7.8 microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability 0,8%
CVE-2021-43243 MED 5.5 microsoft vp9_video_extensions VP9 Video Extensions Information Disclosure Vulnerability 0,8%
CVE-2021-43235 MED 5.5 microsoft windows_10 Storage Spaces Controller Information Disclosure Vulnerability 0,8%
CVE-2021-43227 MED 5.5 microsoft windows_10 Storage Spaces Controller Information Disclosure Vulnerability 0,8%
CVE-2021-28317 MED 5.5 microsoft windows_10 Microsoft Windows Codecs Library Information Disclosure Vulnerability 0,8%
CVE-2017-3877 MED 6.5 cisco unified_communications_manager A vulnerability in the web framework of Cisco Unified Communications Manager (CallManager) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of the web interface of the affected software. More 0,8%
CVE-2010-4685 MED 4.0 cisco ios Cisco IOS before 15.0(1)XA1 does not clear the public key cache upon a change to a certificate map, which allows remote authenticated users to bypass a certificate ban by connecting with a banned certificate that had previously been valid, aka Bug ID CSCta7903 0,8%
CVE-2026-69875 HIGH 8.0 microsoft windows_10_1809 Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network. 0,8%
CVE-2026-69505 HIGH 8.0 microsoft windows_10_1607 Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges over a network. 0,8%
CVE-2026-69503 HIGH 8.0 microsoft windows_10_1809 Stack-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges over a network. 0,8%
CVE-2026-69461 HIGH 8.8 microsoft windows_10_1607 Stack-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code over a network. 0,8%
CVE-2025-47162 HIGH 8.4 microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. 0,8%
CVE-2024-39462 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: clk: bcm: dvp: Assign ->num before accessing ->hws Commit f316cdff8d67 ("clk: Annotate struct clk_hw_onecell_data with __counted_by") annotated the hws member of 'struct clk_hw_onecell_data' 0,8%
CVE-2021-47064 MED 5.3 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mt76: fix potential DMA mapping leak With buf uninitialized in mt76_dma_tx_queue_skb_raw, its field skip_unmap could potentially inherit a non-zero value from stack garbage. If this happens, 0,8%
CVE-2022-45934 HIGH 7.8 debian debian_linux An issue was discovered in the Linux kernel through 6.0.10. l2cap_config_req in net/bluetooth/l2cap_core.c has an integer wraparound via L2CAP_CONF_REQ packets. 0,8%