58.046 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.046 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-68476 | CRIT 9.8 | In the Linux kernel, the following vulnerability has been resolved: ipvs: reload ip header after head reallocation __ip_vs_get_out_rt() calls skb_ensure_writable() which may reallocate skb->head. | 0,7% | — |
| CVE-2026-70468 | HIGH 8.1 | fortinet fortimanager A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7.4.3 through 7.4.5, FortiManager Cloud 7. | 0,7% | — |
| CVE-2026-59113 | HIGH 8.8 | microsoft visual_studio_code Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network. | 0,7% | — |
| CVE-2025-69219 | HIGH 8.8 | apache airflow_providers_http A user with access to the DB could craft a database entry that would result in executing code on Triggerer - which gives anyone who have access to DB the same permissions as Dag Author. Since direct DB access is not usual and recommended for Airflow, the likel | 0,7% | — |
| CVE-2026-20837 | HIGH 7.8 | microsoft windows_10_1809 Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally. | 0,7% | — |
| CVE-2025-55674 | MED 6.5 | apache superset A bypass of the DISALLOWED_SQL_FUNCTIONS security feature in Apache Superset allows for the execution of blocked SQL functions. An attacker can use a special inline block to circumvent the denylist. This allows a user with SQL Lab access to execute functions t | 0,7% | — |
| CVE-2025-21206 | HIGH 7.3 | microsoft visual_studio_2017 Visual Studio Installer Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2024-38247 | HIGH 7.8 | microsoft windows_10_1507 Windows Graphics Component Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2024-38046 | HIGH 7.8 | microsoft windows_10_1507 PowerShell Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2024-23662 | MED 5.3 | fortinet fortios An exposure of sensitive information to an unauthorized actor in Fortinet FortiOS at least version at least 7.4.0 through 7.4.1 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.15 and 6.4.0 through 6.4.15 allows attacker to information disclosure via HTTP request | 0,7% | — |
| CVE-2024-22371 | LOW 2.9 | apache camel Exposure of sensitive data by by crafting a malicious EventFactory and providing a custom ExchangeCreatedEvent that exposes sensitive data. Vulnerability in Apache Camel.This issue affects Apache Camel: from 3.21.X through 3.21.3, from 3.22.X through 3.22.0, f | 0,7% | — |
| CVE-2023-20258 | MED 6.5 | cisco evolved_programmable_network_manager A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. This vulnerability is due to improper processing of serialized J | 0,7% | — |
| CVE-2024-21614 | HIGH 7.5 | juniper junos An Improper Check for Unusual or Exceptional Conditions vulnerability in Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based, unauthenticated attacker to cause rpd to crash, leading to Denial of Service (DoS) | 0,7% | — |
| CVE-2023-36868 | MED 6.5 | microsoft azure_service_fabric Azure Service Fabric on Windows Information Disclosure Vulnerability | 0,7% | — |
| CVE-2023-23375 | HIGH 7.8 | microsoft odbc Microsoft ODBC and OLE DB Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2019-16784 | HIGH 7.0 | pyinstaller pyinstaller In PyInstaller before version 3.6, only on Windows, a local privilege escalation vulnerability is present in this particular case: If a software using PyInstaller in "onefile" mode is launched by a privileged user (at least more than the current one) which hav | 0,7% | — |
| CVE-2019-1828 | MED 5.9 | cisco rv320_firmware A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to access administrative credentials. The vulnerability exists because affected devices u | 0,7% | — |
| CVE-2026-20340 | HIGH 8.8 | A vulnerability in Cisco Secure FMC Software could allow an authenticated, remote attacker to execute arbitrary commands at the root privilege level. This vulnerability is due to unsecured deserialization of web-management user-controlled data. An atta | 0,7% | — |
| CVE-2026-41870 | HIGH 8.8 | apache nutch Missing Authorization, Improper Control of Generation of Code ('Code Injection'), Improper Control of Dynamically-Managed Code Resources, Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Nutch Server ( | 0,7% | — |
| CVE-2026-64303 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: spi: fsl-lpspi: terminate the RX channel on TX prepare failure path When dmaengine_prep_slave_sg() fails for the TX channel, the error path terminates the TX DMA channel but leaves the RX ch | 0,7% | — |
| CVE-2026-44930 | CRIT 9.8 | apache cxf An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository. Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix th | 0,7% | — |
| CVE-2025-25247 | MED 6.1 | apache felix_webconsole Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix Webconsole. This issue affects Apache Felix Webconsole 4.x up to 4.9.8 and 5.x up to 5.0.8. Users are recommended to upgrade to version 4.9.10 | 0,7% | — |
| CVE-2024-56644 | HIGH 7.5 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: net/ipv6: release expired exception dst cached in socket Dst objects get leaked in ip6_negative_advice() when this function is executed for an expired IPv6 route located in the exception tab | 0,7% | — |
| CVE-2024-30392 | HIGH 7.5 | juniper junos A Stack-based Buffer Overflow vulnerability in Flow Processing Daemon (flowd) of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause Denial of Service (DoS). On all Junos OS MX Series platforms with SPC3 and MS-MPC/-MIC, when | 0,7% | — |
| CVE-2023-6105 | MED 5.5 | zohocorp manageengine_access_manager_plus An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed | 0,7% | — |