58.046 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.046 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-48582 | CRIT 9.6 | microsoft exchange_online Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. | 0,7% | — |
| CVE-2026-47341 | MED 6.5 | apache apisix Authentication Bypass by Capture-replay vulnerability in Apache APISIX. Attacker can benefit from certain configurations in hmac-auth to re-use a token forever, bypassing expiry. This issue affects Apache APISIX: from 3.11.0 through 3.16.0. Users are recomme | 0,7% | — |
| CVE-2026-20932 | MED 5.5 | microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | 0,7% | — |
| CVE-2024-44088 | MED 6.1 | apache geode Malicious script injection ('Cross-site Scripting') vulnerability in Apache Geode web-api (REST). This vulnerability allows an attacker that tricks a logged-in user into clicking a specially-crafted link to execute code on the returned page, which could lead t | 0,7% | — |
| CVE-2024-26012 | MED 6.7 | fortinet fortiap A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiAP-S 6.2 all verisons, and 6.4.0 through 6.4.9, FortiAP-W2 6.4 all versions, 7.0 all versions, 7.2.0 through 7.2.3, and 7.4.0 through 7.4.2, FortiAP 6 | 0,7% | — |
| CVE-2024-26882 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: ip_tunnel: make sure to pull inner header in ip_tunnel_rcv() Apply the same fix than ones found in : 8d975c15c0cd ("ip6_tunnel: make sure to pull inner header in __ip6_tnl_rcv()") 1ca1 | 0,7% | — |
| CVE-2024-21432 | HIGH 7.0 | microsoft windows_10_1507 Windows Update Stack Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2022-48199 | HIGH 8.8 | softperfect networx SoftPerfect NetWorx 7.1.1 on Windows allows an attacker to execute a malicious binary with potentially higher privileges via a low-privileged user account that abuses the Notifications function. The Notifications function allows for arbitrary binary execution | 0,7% | — |
| CVE-2022-20940 | MED 5.3 | cisco secure_firewall_threat_defense A vulnerability in the TLS handler of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to gain access to sensitive information. This vulnerability is due to improper implementation of countermeasures against a Bl | 0,7% | — |
| CVE-2020-7878 | CRIT 9.8 | 4nb videooffice An arbitrary file download and execution vulnerability was found in the VideoOffice X2.9 and earlier versions (CVE-2020-7878). This issue is due to missing support for integrity check. | 0,7% | — |
| CVE-2020-16981 | MED 6.1 | microsoft azure_sphere Azure Sphere Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2020-7808 | HIGH 8.7 | raonwiz raon_k_upload In RAONWIZ K Upload v2018.0.2.51 and prior, automatic update processing without integrity check on update module(web.js) allows an attacker to modify arguments which causes downloading a random DLL and injection on it. | 0,7% | — |
| CVE-2026-29167 | CRIT 9.8 | apache http_server Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue. | 0,7% | — |
| CVE-2025-37928 | HIGH 7.8 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: dm-bufio: don't schedule in atomic context A BUG was reported as below when CONFIG_DEBUG_ATOMIC_SLEEP and try_verify_in_tasklet are enabled. [ 129.444685][ T934] BUG: sleeping function cal | 0,7% | — |
| CVE-2025-23251 | HIGH 7.6 | nvidia nemo NVIDIA NeMo Framework contains a vulnerability where a user could cause an improper control of generation of code by remote code execution. A successful exploit of this vulnerability might lead to code execution and data tampering. | 0,7% | — |
| CVE-2024-42256 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: cifs: Fix server re-repick on subrequest retry When a subrequest is marked for needing retry, netfs will call cifs_prepare_write() which will make cifs repick the server for the op before re | 0,7% | — |
| CVE-2023-44155 | HIGH 7.5 | acronis cyber_protect Sensitive information leak through log files. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979. | 0,7% | — |
| CVE-2023-35374 | HIGH 7.8 | microsoft paint_3d Paint 3D Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2023-24944 | MED 6.5 | microsoft windows_10_1809 Windows Bluetooth Driver Information Disclosure Vulnerability | 0,7% | — |
| CVE-2022-40615 | MED 6.3 | ibm sterling_partner_engagement_manager IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM | 0,7% | — |
| CVE-2011-4667 | MED 5.9 | cisco ios The encryption library in Cisco IOS Software 15.2(1)T, 15.2(1)T1, and 15.2(2)T, Cisco NX-OS in Cisco MDS 9222i Multiservice Modular Switch, Cisco MDS 9000 18/4-Port Multiservice Module, and Cisco MDS 9000 Storage Services Node module before 5.2(6), and Cisco I | 0,7% | — |
| CVE-2013-4277 | LOW 3.3 | apache subversion Svnserve in Apache Subversion 1.4.0 through 1.7.12 and 1.8.0 through 1.8.1 allows local users to overwrite arbitrary files or kill arbitrary processes via a symlink attack on the file specified by the --pid-file option. | 0,7% | — |
| CVE-2026-42537 | CRIT 9.8 | apache ranger Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue. | 0,7% | — |
| CVE-2026-45481 | HIGH 7.3 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 0,7% | — |
| CVE-2025-29823 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0,7% | — |