EN
58.046 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.046 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2024-43638 MED 6.8 microsoft windows_10_1507 Windows USB Video Class System Driver Elevation of Privilege Vulnerability 0,7%
CVE-2024-43637 MED 6.8 microsoft windows_10_1507 Windows USB Video Class System Driver Elevation of Privilege Vulnerability 0,7%
CVE-2024-43634 MED 6.8 microsoft windows_10_1507 Windows USB Video Class System Driver Elevation of Privilege Vulnerability 0,7%
CVE-2024-43449 MED 6.8 microsoft windows_10_1507 Windows USB Video Class System Driver Elevation of Privilege Vulnerability 0,7%
CVE-2022-48655 HIGH 7.8 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Harden accesses to the reset domains Accessing reset domains descriptors by the index upon the SCMI drivers requests through the SCMI reset operations interface can poten 0,7%
CVE-2021-47001 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: xprtrdma: Fix cwnd update ordering After a reconnect, the reply handler is opening the cwnd (and thus enabling more RPC Calls to be sent) /before/ rpcrdma_post_recvs() can post enough Receiv 0,7%
CVE-2023-20111 MED 6.5 cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access sensitive information. This vulnerability is due to the improper storage of sensitive information within th 0,7%
CVE-2022-22192 HIGH 7.5 juniper junos_os_evolved An Improper Validation of Syntactic Correctness of Input vulnerability in the kernel of Juniper Networks Junos OS Evolved on PTX series allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). When an incoming TCP packet destined to 0,7%
CVE-2021-1561 MED 5.4 cisco secure_email_and_web_manager A vulnerability in the spam quarantine feature of Cisco Secure Email and Web Manager, formerly Cisco Security Management Appliance (SMA), could allow an authenticated, remote attacker to gain unauthorized access and modify the spam quarantine settings of anoth 0,7%
CVE-2015-6932 MED 5.8 vmware vcenter_server VMware vCenter Server 5.5 before u3 and 6.0 before u1 does not verify X.509 certificates from TLS LDAP servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. 0,7%
CVE-2008-5713 MED 4.9 linux linux_kernel The __qdisc_run function in net/sched/sch_generic.c in the Linux kernel before 2.6.25 on SMP machines allows local users to cause a denial of service (soft lockup) by sending a large amount of network traffic, as demonstrated by multiple simultaneous invocatio 0,7%
CVE-2026-50505 HIGH 7.5 microsoft windows_10_1607 Use after free in Windows Message Queuing allows an authorized attacker to execute code over a network. 0,7%
CVE-2026-50500 HIGH 7.5 microsoft windows_10_1607 Use after free in Windows Netlogon allows an authorized attacker to elevate privileges over a network. 0,7%
CVE-2026-50340 HIGH 8.5 microsoft windows_11_24h2 Use after free in Windows Runtime allows an authorized attacker to elevate privileges over a network. 0,7%
CVE-2025-54090 MED 6.3 apache http_server A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true". Users are recommended to upgrade to version 2.4.65, which fixes the issue. 0,7%
CVE-2024-42516 HIGH 7.5 apache http_server HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type response headers of applications hosted or proxied by the server can split the HTTP response. This vulnerability was described as CVE-2023-38709 b 0,7%
CVE-2024-49114 HIGH 7.8 microsoft windows_10_1809 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability 0,7%
CVE-2024-45217 HIGH 8.1 apache solr Insecure Default Initialization of Resource vulnerability in Apache Solr. New ConfigSets that are created via a Restore command, which copy a configSet from the backup and give it a new name, are created without setting the "trusted" metadata. ConfigSets that 0,7%
CVE-2023-28295 HIGH 7.8 microsoft 365_apps Microsoft Publisher Remote Code Execution Vulnerability 0,7%
CVE-2023-28287 HIGH 7.8 microsoft 365_apps Microsoft Publisher Remote Code Execution Vulnerability 0,7%
CVE-2022-20868 MED 4.7 cisco asyncos A vulnerability in the web-based management interface of Cisco Email Security Appliance, Cisco Secure Email and Web Manager and Cisco Secure Web Appliance could allow an authenticated, remote attacker to elevate privileges on an affected system. The attacker n 0,7%
CVE-2022-34167 MED 5.4 ibm cics_tx IBM CICS TX Standard and Advanced 11.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within 0,7%
CVE-2022-34166 MED 5.4 ibm cics_tx IBM CICS TX Standard and Advanced 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trust 0,7%
CVE-2021-44750 MED 6.4 f-secure client_security An arbitrary code execution vulnerability was found in the F-Secure Support Tool. A standard user can craft a special configuration file, which when run by administrator can execute any commands. 0,7%
CVE-2019-1186 HIGH 7.0 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the wcmsvc.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally authenticate 0,7%