58.046 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.046 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2017-5646 | MED 6.8 | apache knox For versions of Apache Knox from 0.2.0 to 0.11.0 - an authenticated user may use a specially crafted URL to impersonate another user while accessing WebHDFS through Apache Knox. This may result in escalated privileges and unauthorized data access. While this a | 0,8% | — |
| CVE-2026-77906 | HIGH 8.8 | microsoft visual_studio_2026 Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network. | 0,8% | — |
| CVE-2026-49163 | HIGH 8.8 | microsoft application_insights_profiler Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network. | 0,8% | — |
| CVE-2025-21264 | HIGH 7.1 | microsoft visual_studio_code Files or directories accessible to external parties in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | 0,8% | — |
| CVE-2024-41036 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: ks8851: Fix deadlock with the SPI chip variant When SMP is enabled and spinlocks are actually functional then there is a deadlock with the 'statelock' spinlock between ks8851_start_xmit | 0,8% | — |
| CVE-2024-30341 | HIGH 7.8 | foxit pdf_editor Foxit PDF Reader Doc Object Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability i | 0,8% | — |
| CVE-2023-27497 | CRIT 10.0 | sap diagnostics_agent Due to missing authentication and input sanitization of code the EventLogServiceCollector of SAP Diagnostics Agent - version 720, allows an attacker to execute malicious scripts on all connected Diagnostics Agents running on Windows. On successful exploitation | 0,8% | — |
| CVE-2012-2853 | MED 6.8 | google chrome The webRequest API in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, does not properly interact with the Chrome Web Store, which allows remote attackers to cause a denial of service or possibly hav | 0,8% | — |
| CVE-2012-2847 | MED 4.3 | google chrome Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, does not request user confirmation before continuing a large series of downloads, which allows user-assisted remote attackers to cause a denial of ser | 0,8% | — |
| CVE-2026-40021 | MED 5.3 | apache log4net Apache Log4net's XmlLayout https://logging.apache.org/log4net/manual/configuration/layouts.html#layout-list and XmlLayoutSchemaLog4J https://logging.apache.org/log4net/manual/configuration/layouts.html#layout-list , in versions before 3.3.0, fail to sanitiz | 0,8% | — |
| CVE-2026-25903 | MED 6.6 | apache nifi Apache NiFi 1.1.0 through 2.7.2 are missing authorization when updating configuration properties on extension components that have specific Required Permissions based on the Restricted annotation. The Restricted annotation indicates additional privileges requi | 0,8% | — |
| CVE-2026-20834 | MED 4.6 | microsoft windows_10_1607 Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a physical attack. | 0,8% | — |
| CVE-2024-49044 | MED 6.7 | microsoft visual_studio_2022 Visual Studio Elevation of Privilege Vulnerability | 0,8% | — |
| CVE-2024-38166 | HIGH 8.2 | microsoft dynamics_crm_service_portal_web_resource An unauthenticated attacker can exploit improper neutralization of input during web page generation in Microsoft Dynamics 365 to spoof over a network by tricking a user to click on a link. | 0,8% | — |
| CVE-2024-36288 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Fix loop termination condition in gss_free_in_token_pages() The in_token->pages[] array is not NULL terminated. This results in the following KASAN splat: KASAN: maybe wild-memory | 0,8% | — |
| CVE-2024-36471 | HIGH 7.5 | apache allura Import functionality is vulnerable to DNS rebinding attacks between verification and processing of the URL. Project administrators can run these imports, which could cause Allura to read from internal services and expose them. This issue affects Apache Allur | 0,8% | — |
| CVE-2023-32051 | HIGH 7.8 | microsoft raw_image_extension Raw Image Extension Remote Code Execution Vulnerability | 0,8% | — |
| CVE-2023-20030 | MED 6.0 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access sensitive information, conduct a server-side request forgery (SSRF) attack through an affected device, or nega | 0,8% | — |
| CVE-2022-28716 | HIGH 7.5 | f5 big-ip_advanced_firewall_manager On 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x 11.6.x, a DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page o | 0,8% | — |
| CVE-2022-22415 | MED 6.5 | ibm robotic_process_automation A vulnerability exists where an IBM Robotic Process Automation 21.0.1 regular user is able to obtain view-only access to some admin pages in the Control Center IBM X-Force ID: 223029. | 0,8% | — |
| CVE-2021-43246 | MED 5.6 | microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability | 0,8% | — |
| CVE-2021-24023 | HIGH 7.8 | fortinet fortiai_firmware An improper input validation in FortiAI v1.4.0 and earlier may allow an authenticated user to gain system shell access via a malicious payload in the "diagnose" command. | 0,8% | — |
| CVE-2009-0746 | MED 4.9 | linux linux_kernel The make_indexed_dir function in fs/ext4/namei.c in the Linux kernel 2.6.27 before 2.6.27.19 and 2.6.28 before 2.6.28.7 does not validate a certain rec_len field, which allows local users to cause a denial of service (OOPS) by attempting to mount a crafted ext | 0,8% | — |
| CVE-1999-0720 | MED 4.6 | linux linux_kernel The pt_chown command in Linux allows local users to modify TTY terminal devices that belong to other users. | 0,8% | — |
| CVE-2026-70306 | CRIT 9.3 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | 0,7% | — |