EN
58.046 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.046 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2021-27363 MED 4.4 debian debian_linux An issue was discovered in the Linux kernel through 5.11.3. A kernel pointer leak can be used to determine the address of the iscsi_transport structure. When an iSCSI transport is registered with the iSCSI subsystem, the transport's handle is available to unpr 0,7%
CVE-2020-16989 MED 5.4 microsoft azure_sphere Azure Sphere Elevation of Privilege Vulnerability 0,7%
CVE-2020-12657 HIGH 7.8 linux linux_kernel An issue was discovered in the Linux kernel before 5.6.5. There is a use-after-free in block/bfq-iosched.c related to bfq_idle_slice_timer_body. 0,7%
CVE-2020-1002 HIGH 7.1 microsoft forefront_endpoint_protection_2010 An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Defender Elevation of Privilege Vu 0,7%
CVE-2014-0737 MED 4.3 cisco unified_ip_phone_7960g The Cisco Unified IP Phone 7960G 9.2(1) and earlier allows remote attackers to bypass authentication and change trust relationships by injecting a Certificate Trust List (CTL) file, aka Bug ID CSCuj66795. 0,7%
CVE-2010-3849 MED 4.7 canonical ubuntu_linux The econet_sendmsg function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2, when an econet address is configured, allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a sendmsg call that specifies a NULL value 0,7%
CVE-2026-60005 HIGH 8.2 f5 nginx_gateway_fabric NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause 0,7%
CVE-2026-22153 HIGH 8.1 fortinet fortios An Authentication Bypass by Primary Weakness vulnerability [CWE-305] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4 may allow an unauthenticated attacker to bypass LDAP authentication of Agentless VPN or FSSO policy, when the remote LDAP server is confi 0,7%
CVE-2025-64663 CRIT 9.9 microsoft azure_language Custom Question Answering Elevation of Privilege Vulnerability 0,7%
CVE-2025-23316 CRIT 9.8 nvidia triton_inference_server NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause a remote code execution by manipulating the model name parameter in the model control APIs. A successful exploit of this vulnerab 0,7%
CVE-2024-41178 HIGH 7.5 apache arrow Exposure of temporary credentials in logs in Apache Arrow Rust Object Store (`object_store` crate), version 0.10.1 and earlier on all platforms using AWS WebIdentityTokens.  On certain error conditions, the logs may contain the OIDC token passed to AssumeRol 0,7%
CVE-2024-30382 HIGH 7.5 juniper junos An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based, unauthenticated attacker to send a specific routing update, causing an rpd core due to m 0,7%
CVE-2023-22337 HIGH 7.5 intel unison_software Improper input validation for some Intel Unison software may allow an unauthenticated user to potentially enable denial of service via network access. 0,7%
CVE-2023-37464 HIGH 8.6 cisco cjose OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). The AES GCM decryption routine incorrectly uses the Tag length from the actual Authentication Tag provided in the JWE. The spec says that a fixed length of 16 octet 0,7%
CVE-2022-29135 HIGH 7.0 microsoft windows_server Windows Cluster Shared Volume (CSV) Elevation of Privilege Vulnerability 0,7%
CVE-2021-32585 HIGH 7.2 fortinet fortiwan An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiWAN before 4.5.9 may allow an attacker to perform a stored cross-site scripting attack via specifically crafted HTTP requests. 0,7%
CVE-2021-20337 HIGH 7.5 ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.3.0 to 7.3.3 Patch 8 and 7.4.0 to 7.4.3 GA uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 194448. 0,7%
CVE-2021-20419 HIGH 7.5 ibm security_guardium IBM Security Guardium 11.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 196280. 0,7%
CVE-2021-29694 HIGH 7.5 ibm spectrum_protect_plus IBM Spectrum Protect Plus 10.1.0 through 10.1.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 200258. 0,7%
CVE-2021-26413 MED 6.2 microsoft windows_10 Windows Installer Spoofing Vulnerability 0,7%
CVE-2020-24419 HIGH 7.0 adobe after_effects Adobe After Effects version 17.1.1 (and earlier) for Windows is affected by an uncontrolled search path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that 0,7%
CVE-2018-0364 HIGH 8.8 cisco unified_communications_domain_manager A vulnerability in the web-based management interface of Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The 0,7%
CVE-2018-0270 HIGH 8.8 cisco iot_field_network_director A vulnerability in the web-based management interface of Cisco IoT Field Network Director (IoT-FND) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and alter the data of existing users and groups on an affe 0,7%
CVE-2026-54120 CRIT 9.9 microsoft surface_management_services Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network. 0,7%
CVE-2025-54906 HIGH 7.8 microsoft 365_apps Free of memory not on the heap in Microsoft Office allows an unauthorized attacker to execute code locally. 0,7%