58.046 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.046 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2024-20478 | MED 6.5 | cisco application_policy_infrastructure_controller A vulnerability in the software upgrade component of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Network Controller, formerly Cisco Cloud APIC, could allow an authenticated, remote attacker with Administrator-level privileges | 0,7% | — |
| CVE-2021-46955 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: openvswitch: fix stack OOB read while fragmenting IPv4 packets running openvswitch on kernels built with KASAN, it's possible to see the following splat while testing fragmentation of IPv4 p | 0,7% | — |
| CVE-2023-20231 | HIGH 8.8 | cisco ios_xe A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to perform an injection attack against an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulner | 0,7% | — |
| CVE-2023-27730 | HIGH 7.5 | f5 njs Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_lvlhsh_find at src/njs_lvlhsh.c. | 0,7% | — |
| CVE-2023-27728 | HIGH 7.5 | f5 njs Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_dump_is_recursive at src/njs_vmcode.c. | 0,7% | — |
| CVE-2023-21718 | HIGH 7.8 | microsoft sql_server Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2022-33876 | MED 5.4 | fortinet fortiadc Multiple instances of improper input validation vulnerability in Fortinet FortiADC version 7.1.0, version 7.0.0 through 7.0.2 and version 6.2.4 and below allows an authenticated attacker to retrieve files with specific extension from the underlying Linux syste | 0,7% | — |
| CVE-2022-21962 | MED 6.8 | microsoft windows_10 Windows Resilient File System (ReFS) Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2022-21961 | MED 6.8 | microsoft windows_10 Windows Resilient File System (ReFS) Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2022-21960 | MED 6.8 | microsoft windows_10 Windows Resilient File System (ReFS) Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2022-21959 | MED 6.8 | microsoft windows_10 Windows Resilient File System (ReFS) Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2022-21958 | MED 6.8 | microsoft windows_10 Windows Resilient File System (ReFS) Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2022-21892 | MED 6.8 | microsoft windows_10 Windows Resilient File System (ReFS) Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2021-34712 | MED 5.4 | cisco catalyst_sd-wan_manager A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct cypher query language injection attacks on an affected system. This vulnerability is due to insufficient input valid | 0,7% | — |
| CVE-2021-1642 | HIGH 7.8 | microsoft windows_10 Windows AppX Deployment Extensions Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2020-9498 | MED 6.7 | apache guacamole Apache Guacamole 1.1.0 and older may mishandle pointers involved inprocessing data received via RDP static virtual channels. If a userconnects to a malicious or compromised RDP server, a series ofspecially-crafted PDUs could result in memory corruption, possib | 0,7% | — |
| CVE-2017-0302 | MED 5.3 | f5 big-ip_access_policy_manager In F5 BIG-IP APM 12.0.0 through 12.1.2 and 13.0.0, an authenticated user with an established access session to the BIG-IP APM system may be able to cause a traffic disruption if the length of the requested URL is less than 16 characters. | 0,7% | — |
| CVE-2026-31987 | HIGH 7.5 | apache airflow JWT Tokens used by tasks were exposed in logs. This could allow UI users to act as Dag Authors. Users are advised to upgrade to Airflow version that contains fix. Users are recommended to upgrade to version 3.2.0, which fixes this issue. | 0,7% | — |
| CVE-2026-23653 | MED 5.7 | microsoft github_copilot_chat Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an authorized attacker to disclose information over a network. | 0,7% | — |
| CVE-2026-22998 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: fix NULL pointer dereferences in nvmet_tcp_build_pdu_iovec Commit efa56305908b ("nvmet-tcp: Fix a kernel panic when host sends an invalid H2C PDU length") added ttag bounds checkin | 0,7% | — |
| CVE-2021-47482 | MED 5.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: batman-adv: fix error handling Syzbot reported ODEBUG warning in batadv_nc_mesh_free(). The problem was in wrong error handling in batadv_mesh_init(). Before this patch batadv_mesh_ini | 0,7% | — |
| CVE-2024-26800 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tls: fix use-after-free on failed backlog decryption When the decrypt request goes to the backlog and crypto_aead_decrypt returns -EBUSY, tls_do_decryption will wait until all async decrypti | 0,7% | — |
| CVE-2024-20699 | MED 5.5 | microsoft windows_10_1809 Windows Hyper-V Denial of Service Vulnerability | 0,7% | — |
| CVE-2022-43929 | MED 4.9 | ibm db2 IBM Db2 for Linux, UNIX and Windows 11.1 and 11.5 may be vulnerable to a Denial of Service when executing a specially crafted 'Load' command. IBM X-Force ID: 241676. | 0,7% | — |
| CVE-2022-30607 | MED 6.5 | ibm robotic_process_automation IBM Robotic Process Automation 20.10.0, 20.12.5, 21.0.0, 21.0.1, and 21.0.2 contains a vulnerability that could allow a user to obtain sensitive information due to information properly masked in the control center UI. IBM X-Force ID: 227294. | 0,7% | — |