58.047 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.047 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2025-55672 | MED 5.4 | apache superset A stored Cross-Site Scripting (XSS) vulnerability exists in Apache Superset's chart visualization. An authenticated user with permissions to edit charts can inject a malicious payload into a column's label. The payload is not properly sanitized and gets execut | 0,7% | — |
| CVE-2025-49747 | CRIT 9.9 | microsoft azure_machine_learning Missing authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network. | 0,7% | — |
| CVE-2025-27528 | CRIT 9.1 | apache inlong Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability allows attackers to bypass the security mechanisms of InLong JDBC and leads to arbitrary file reading. Users ar | 0,7% | — |
| CVE-2025-22041 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in ksmbd_sessions_deregister() In multichannel mode, UAF issue can occur in session_deregister when the second channel sets up a session through the connection of t | 0,7% | — |
| CVE-2022-31764 | HIGH 8.5 | apache shardingsphere_elasticjob-ui The Lite UI of Apache ShardingSphere ElasticJob-UI allows an attacker to perform RCE by constructing a special JDBC URL of H2 database. This issue affects Apache ShardingSphere ElasticJob-UI version 3.0.1 and prior versions. This vulnerability has been fixed i | 0,7% | — |
| CVE-2024-0100 | MED 6.5 | nvidia triton_inference_server NVIDIA Triton Inference Server for Linux contains a vulnerability in the tracing API, where a user can corrupt system files. A successful exploit of this vulnerability might lead to denial of service and data tampering. | 0,7% | — |
| CVE-2023-33174 | MED 5.5 | microsoft windows_10_1507 Windows Cryptographic Information Disclosure Vulnerability | 0,7% | — |
| CVE-2022-26793 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2020-9681 | MED 6.5 | adobe genuine_service Adobe Genuine Service version 6.6 (and earlier) is affected by an Uncontrolled Search Path element vulnerability. An authenticated attacker could exploit this to rewrite the file of the administrator, which may lead to elevated permissions. Exploitation of thi | 0,7% | — |
| CVE-2020-1629 | MED 5.9 | juniper junos A race condition vulnerability on Juniper Network Junos OS devices may cause the routing protocol daemon (RPD) process to crash and restart while processing a BGP NOTIFICATION message. This issue affects Juniper Networks Junos OS: 16.1 versions prior to 16.1R7 | 0,7% | — |
| CVE-2018-18690 | MED 5.5 | canonical ubuntu_linux In the Linux kernel before 4.17, a local attacker able to set attributes on an xfs filesystem could make this filesystem non-operational until the next mount by triggering an unchecked error condition during an xfs attribute change, because xfs_attr_shortform_ | 0,7% | — |
| CVE-2017-6655 | MED 6.5 | cisco mds_9000_nx-os A vulnerability in the Fibre Channel over Ethernet (FCoE) protocol implementation in Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition when an FCoE-related process unexpectedly reloads. This vul | 0,7% | — |
| CVE-2010-5153 | MED 5.3 | avira premium_security_suite Race condition in Avira Premium Security Suite 10.0.0.536 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via ce | 0,7% | — |
| CVE-2026-49086 | MED 6.5 | apache camel Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in Apache Camel DAPR component. The camel-dapr Dapr Pub/Sub consumer (DaprPubSubConsumer) copied two fields from each inbound CloudEvent - its Pub/Sub component name | 0,7% | — |
| CVE-2026-50628 | CRIT 9.8 | apache cxf A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address. Enabling this security feature inadvertently creates an inverse security check. Users are recomme | 0,7% | — |
| CVE-2025-55320 | MED 6.8 | microsoft configuration_manager_2403 Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over an adjacent network. | 0,7% | — |
| CVE-2025-37879 | CRIT 9.8 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: 9p/net: fix improper handling of bogus negative read/write replies In p9_client_write() and p9_client_read_once(), if the server incorrectly replies with success but a negative write/read co | 0,7% | — |
| CVE-2025-23249 | HIGH 7.6 | nvidia nemo NVIDIA NeMo Framework contains a vulnerability where a user could cause a deserialization of untrusted data by remote code execution. A successful exploit of this vulnerability might lead to code execution and data tampering. | 0,7% | — |
| CVE-2024-38203 | MED 6.2 | microsoft windows_10_1507 Windows Package Library Manager Information Disclosure Vulnerability | 0,7% | — |
| CVE-2024-43497 | HIGH 8.4 | microsoft deepspeed DeepSpeed Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2024-22234 | HIGH 7.4 | vmware spring_security In Spring Security, versions 6.1.x prior to 6.1.7 and versions 6.2.x prior to 6.2.2, an application is vulnerable to broken access control when it directly uses the AuthenticationTrustResolver.isFullyAuthenticated(Authentication) method. Specifically, an appl | 0,7% | — |
| CVE-2023-44253 | MED 5.0 | fortinet fortianalyzer An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiManager version 7.4.0 through 7.4.1 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.1 and before 7.2.5 and FortiAnalyzer-BigData before 7.2.5 allow | 0,7% | — |
| CVE-2023-36773 | HIGH 7.8 | microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2023-36772 | HIGH 7.8 | microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2023-36771 | HIGH 7.8 | microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability | 0,7% | — |