58.089 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.089 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-65098 | HIGH 8.1 | nvidia nemoclaw NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause weak authentication. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering. | 0,7% | — |
| CVE-2026-70329 | HIGH 8.8 | microsoft 365_apps Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. | 0,7% | — |
| CVE-2026-47298 | HIGH 8.0 | microsoft sharepoint_server Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 0,7% | — |
| CVE-2026-20946 | HIGH 7.8 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0,7% | — |
| CVE-2025-24988 | MED 6.6 | microsoft windows_10_1507 Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack. | 0,7% | — |
| CVE-2025-24987 | MED 6.6 | microsoft windows_10_1507 Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack. | 0,7% | — |
| CVE-2022-49260 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/sec - fix the aead software fallback for engine Due to the subreq pointer misuse the private context memory. The aead soft crypto occasionally casues the OS panic as settin | 0,7% | — |
| CVE-2025-21284 | MED 5.5 | microsoft windows_10_1507 Windows Virtual Trusted Platform Module Denial of Service Vulnerability | 0,7% | — |
| CVE-2025-21280 | MED 5.5 | microsoft windows_10_1507 Windows Virtual Trusted Platform Module Denial of Service Vulnerability | 0,7% | — |
| CVE-2024-43524 | MED 6.8 | microsoft windows_10_1809 Windows Mobile Broadband Driver Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2024-43523 | MED 6.8 | microsoft windows_10_1809 Windows Mobile Broadband Driver Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2024-30092 | HIGH 8.0 | microsoft windows_10_1507 Windows Hyper-V Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2023-20155 | HIGH 7.5 | cisco secure_firewall_management_center A vulnerability in a logging API in Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to cause the device to become unresponsive or trigger an unexpected reload. This vulnerability could also allow an attacker wit | 0,7% | — |
| CVE-2022-21914 | HIGH 7.8 | microsoft windows_10 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2022-21885 | HIGH 7.8 | microsoft windows_10 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2022-21884 | HIGH 7.8 | microsoft windows_server Local Security Authority Subsystem Service Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2022-21835 | HIGH 7.8 | microsoft windows_10 Microsoft Cryptographic Services Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2026-67370 | HIGH 8.8 | microsoft sql_server_2017 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | 0,7% | — |
| CVE-2026-62817 | HIGH 8.8 | microsoft windows_10_1809 Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network. | 0,7% | — |
| CVE-2026-42527 | HIGH 8.1 | apache camel Deserialization of Untrusted Data vulnerability in Apache Camel. The default ObjectInputFilter pattern shipped with several Apache Camel components for defense-in-depth deserialization filtering ('java.**;javax.**;org.apache.camel.**;!*', or the no-'javax.**' | 0,7% | — |
| CVE-2026-24266 | MED 5.9 | nvidia triton_inference_server NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a use-after-free issue. A successful exploit of this vulnerability might lead to denial of service. | 0,7% | — |
| CVE-2024-41783 | CRIT 9.1 | ibm sterling_secure_proxy IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow a privileged user to inject commands into the underlying operating system due to improper validation of a specified type of input. | 0,7% | — |
| CVE-2024-45031 | MED 6.1 | apache syncope When editing objects in the Syncope Console, incomplete HTML tags could be used to bypass HTML sanitization. This made it possible to inject stored XSS payloads which would trigger for other users during ordinary usage of the application. XSS payloads could al | 0,7% | — |
| CVE-2024-20459 | MED 6.5 | cisco ata_191_firmware A vulnerability in the web-based management interface of Cisco ATA 190 Multiplatform Series Analog Telephone Adapter firmware could allow an authenticated, remote attacker with high privileges to execute arbitrary commands as the root user on the underlying op | 0,7% | — |
| CVE-2023-22285 | HIGH 7.5 | intel unison_software Improper access control for some Intel Unison software may allow an unauthenticated user to potentially enable denial of service via network access. | 0,7% | — |