58.047 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.047 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2023-20200 | HIGH 7.7 | cisco firepower_4112_firmware A vulnerability in the Simple Network Management Protocol (SNMP) service of Cisco FXOS Software for Firepower 4100 Series and Firepower 9300 Security Appliances and of Cisco UCS 6300 Series Fabric Interconnects could allow an authenticated, remote attacker to | 0,7% | — |
| CVE-2023-24513 | MED 6.5 | arista cloudeos On affected platforms running Arista CloudEOS an issue in the Software Forwarding Engine (Sfe) can lead to a potential denial of service attack by sending malformed packets to the switch. This causes a leak of packet buffers and if enough malformed packets are | 0,7% | — |
| CVE-2022-22246 | HIGH 7.5 | juniper junos A PHP Local File Inclusion (LFI) vulnerability in the J-Web component of Juniper Networks Junos OS may allow a low-privileged authenticated attacker to execute an untrusted PHP file. By chaining this vulnerability with other unspecified vulnerabilities, and by | 0,7% | — |
| CVE-2020-4926 | CRIT 9.1 | ibm elastic_storage_system A vulnerability in the Spectrum Scale 5.1 core component and IBM Elastic Storage System 6.1 could allow unauthorized access to user data or injection of arbitrary data in the communication protocol. IBM X-Force ID: 191600. | 0,7% | — |
| CVE-2022-29132 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2017-0620 | HIGH 7.0 | google android An elevation of privilege vulnerability in the Qualcomm Secure Channel Manager driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a pr | 0,7% | — |
| CVE-2024-38215 | HIGH 7.8 | microsoft windows_10_1809 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2024-38135 | HIGH 7.8 | microsoft windows_11_22h2 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2024-38134 | HIGH 7.8 | microsoft windows_10_1507 Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2021-47478 | CRIT 9.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: isofs: Fix out of bound access for corrupted isofs image When isofs image is suitably corrupted isofs_read_inode() can read data beyond the end of buffer. Sanity-check the directory entry le | 0,7% | — |
| CVE-2024-27439 | MED 6.5 | apache wicket An error in the evaluation of the fetch metadata headers could allow a bypass of the CSRF protection in Apache Wicket. This issue affects Apache Wicket: from 9.1.0 through 9.16.0, and the milestone releases for the 10.0 series. Apache Wicket 8.x does not suppo | 0,7% | — |
| CVE-2023-35315 | HIGH 8.8 | microsoft windows_10_1809 Windows Layer-2 Bridge Network Driver Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2023-28296 | HIGH 7.8 | microsoft visual_studio_2017 Visual Studio Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2022-21967 | HIGH 7.0 | microsoft windows_10 Xbox Live Auth Manager for Windows Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2021-29773 | MED 5.4 | ibm security_guardium IBM Security Guardium 10.6 and 11.3 could allow a remote authenticated attacker to obtain sensitive information or modify user details caused by an insecure direct object vulnerability (IDOR). IBM X-Force ID: 202865. | 0,7% | — |
| CVE-2020-5905 | MED 4.3 | f5 big-ip_access_policy_manager In version 11.6.1-11.6.5.2 of the BIG-IP system Configuration utility Network > WCCP page, the system does not sanitize all user-provided data before display. | 0,7% | — |
| CVE-2020-3199 | HIGH 8.8 | cisco ios Multiple vulnerabilities in the Cisco IOx application environment of Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) and Cisco 1000 Series Connected Grid Routers (CGR1000) that are running Cisco IOS Software could allow an attacker t | 0,7% | — |
| CVE-2026-69510 | HIGH 8.1 | microsoft windows_10_1607 Stack-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network. | 0,7% | — |
| CVE-2026-34884 | CRIT 9.8 | apache skywalking_mcp SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache SkyWalking MCP. This issue affects Apache SkyWalking MCP: 0.1.0. Users are recommended to upgrade to version 0.2.0, which fixes this issue. | 0,7% | — |
| CVE-2025-33211 | HIGH 7.5 | nvidia triton_inference_server NVIDIA Triton Server for Linux contains a vulnerability where an attacker may cause an improper validation of specified quantity in input. A successful exploit of this vulnerability may lead to denial of service. | 0,7% | — |
| CVE-2024-56645 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: can: j1939: j1939_session_new(): fix skb reference counting Since j1939_session_skb_queue() does an extra skb_get() for each new skb, do the same for the initial one in j1939_session_new() t | 0,7% | — |
| CVE-2023-36701 | HIGH 7.8 | microsoft windows_10_1507 Microsoft Resilient File System (ReFS) Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2023-24896 | MED 5.4 | microsoft dynamics_365 Dynamics 365 Finance Spoofing Vulnerability | 0,7% | — |
| CVE-2022-26386 | MED 6.5 | mozilla firefox_esr Previously Firefox for macOS and Linux would download temporary files to a user-specific directory in <code>/tmp</code>, but this behavior was changed to download them to <code>/tmp</code> where they could be affected by other local users. This behavior was re | 0,7% | — |
| CVE-2022-21871 | HIGH 7.0 | microsoft visual_studio_2017 Microsoft Diagnostics Hub Standard Collector Runtime Elevation of Privilege Vulnerability | 0,7% | — |