EN
58.046 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.046 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2024-26172 MED 5.5 microsoft windows_10_1809 Windows DWM Core Library Information Disclosure Vulnerability 0,7%
CVE-2024-21387 MED 5.3 microsoft edge_chromium Microsoft Edge for Android Spoofing Vulnerability 0,7%
CVE-2023-32028 HIGH 7.8 microsoft ole_db_driver_for_sql_server Microsoft SQL OLE DB Remote Code Execution Vulnerability 0,7%
CVE-2023-32026 HIGH 7.8 microsoft odbc_driver_for_sql_server Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability 0,7%
CVE-2022-41092 HIGH 7.8 microsoft windows_10 Windows Win32k Elevation of Privilege Vulnerability 0,7%
CVE-2021-0270 HIGH 7.5 juniper junos On PTX Series and QFX10k Series devices with the "inline-jflow" feature enabled, a use after free weakness in the Packet Forwarding Engine (PFE) microkernel architecture of Juniper Networks Junos OS may allow an attacker to cause a Denial of Service (DoS) cond 0,7%
CVE-2021-1474 MED 6.5 cisco umbrella Multiple vulnerabilities in the Admin audit log export feature and Scheduled Reports feature of Cisco Umbrella could allow an authenticated, remote attacker to perform formula and link injection attacks on an affected device. For more information about these v 0,7%
CVE-2020-11494 MED 4.4 canonical ubuntu_linux An issue was discovered in slc_bump in drivers/net/can/slcan.c in the Linux kernel 3.16 through 5.6.2. It allows attackers to read uninitialized can_frame data, potentially containing sensitive information from kernel stack memory, if the configuration lacks C 0,7%
CVE-2019-17387 HIGH 7.8 aviatrix vpn_client An authentication flaw in the AVPNC_RP service in Aviatrix VPN Client through 2.2.10 allows an attacker to gain elevated privileges through arbitrary code execution on Windows, Linux, and macOS. 0,7%
CVE-2015-0708 MED 6.1 cisco ios Cisco IOS 15.4S, 15.4SN, and 15.5S and IOS XE 3.13S and 3.14S allow remote attackers to cause a denial of service (device crash) by including an IA_NA option in a DHCPv6 Solicit message on the local network, aka Bug ID CSCur29956. 0,7%
CVE-2026-56165 CRIT 9.8 microsoft account Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network. 0,7%
CVE-2026-64606 CRIT 9.8 apache fory Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lambda deserialization. Only lambda capture class is affected This issue affects Apache Fory: from before 1.4.0. Users are recommended to upg 0,7%
CVE-2026-48347 HIGH 7.7 adobe animate Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user intera 0,7%
CVE-2026-47897 HIGH 7.5 apache lucene.net Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library). This issue affects Apache Lucene.Net.Replicator: from 4.8.0-beta00005 before 4.8.0-beta00018. Users are recomme 0,7%
CVE-2026-24264 HIGH 7.5 nvidia triton_inference_server NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause improper handling of highly compressed data. A successful exploit of this vulnerability might lead to denial of service. 0,7%
CVE-2024-47252 HIGH 7.5 apache http_server Insufficient escaping of user-supplied data in mod_ssl in Apache HTTP Server 2.4.63 and earlier allows an untrusted SSL/TLS client to insert escape characters into log files in some configurations. In a logging configuration where CustomLog is used with "%{va 0,7%
CVE-2025-26864 HIGH 7.5 apache iotdb Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in the OpenIdAuthorizer of Apache IoTDB. This issue affects Apache IoTDB: from 0.10.0 through 1.3.3, from 2.0.1-beta before 2.0.2. User 0,7%
CVE-2025-26795 HIGH 7.5 apache iotdb Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in Apache IoTDB JDBC driver. This issue affects iotdb-jdbc: from 0.10.0 through 1.3.3, from 2.0.1-beta before 2.0.2. Users are recommen 0,7%
CVE-2025-21356 HIGH 7.8 microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability 0,7%
CVE-2024-47248 MED 6.3 apache nimble Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. Specially crafted MESH message could result in memory corruption when non-default build configuration is used. This issue affects Apache NimBLE: through 1.7 0,7%
CVE-2021-47477 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: comedi: dt9812: fix DMA buffers on stack USB transfer buffers are typically mapped for DMA and must not be allocated on the stack or transfers will fail. Allocate proper transfer buffers in 0,7%
CVE-2024-28922 MED 4.1 microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability 0,7%
CVE-2024-21436 HIGH 7.8 microsoft windows_10_1507 Windows Installer Elevation of Privilege Vulnerability 0,7%
CVE-2022-22043 HIGH 7.8 microsoft windows_10 Windows Fast FAT File System Driver Elevation of Privilege Vulnerability 0,7%
CVE-2022-24465 LOW 3.3 microsoft intune_company_portal Microsoft Intune Portal for iOS Security Feature Bypass Vulnerability 0,7%