EN
58.127 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.127 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2024-38618 MED 5.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ALSA: timer: Set lower bound of start tick time Currently ALSA timer doesn't have the lower limit of the start tick time, and it allows a very small size, e.g. 1 tick with 1ns resolution for 0,6%
CVE-2024-20405 MED 4.8 cisco finesse A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct a stored XSS attack by exploiting an RFI vulnerability. This vulnerability is due to insufficient validation of user-supplied 0,6%
CVE-2023-20862 MED 6.3 netapp active_iq_unified_manager In Spring Security, versions 5.7.x prior to 5.7.8, versions 5.8.x prior to 5.8.3, and versions 6.0.x prior to 6.0.3, the logout support does not properly clean the security context if using serialized versions. Additionally, it is not possible to explicitly sa 0,6%
CVE-2023-23391 MED 5.5 microsoft 365_copilot Office for Android Spoofing Vulnerability 0,6%
CVE-2022-37971 HIGH 7.1 microsoft malware_protection_engine Microsoft Windows Defender Elevation of Privilege Vulnerability 0,6%
CVE-2021-31185 MED 5.5 microsoft windows_10 Windows Desktop Bridge Denial of Service Vulnerability 0,6%
CVE-2021-28443 MED 5.5 microsoft windows_10 Windows Console Driver Denial of Service Vulnerability 0,6%
CVE-2026-55799 CRIT 9.8 apache ranger Remote Code Execution Vulnerability in GraalScriptEngineCreator in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue. 0,6%
CVE-2026-24299 MED 5.3 microsoft 365_copilot Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network. 0,6%
CVE-2026-20862 MED 5.5 microsoft windows_10_1809 Exposure of sensitive information to an unauthorized actor in Windows Management Services allows an authorized attacker to disclose information locally. 0,6%
CVE-2025-47170 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0,6%
CVE-2025-21315 HIGH 7.8 microsoft windows_11_24h2 Microsoft Brokering File System Elevation of Privilege Vulnerability 0,6%
CVE-2024-49074 HIGH 7.8 microsoft windows_10_1809 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability 0,6%
CVE-2024-38201 HIGH 7.0 microsoft azure_stack_hub Azure Stack Hub Elevation of Privilege Vulnerability 0,6%
CVE-2024-35869 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: client: guarantee refcounted children from parent session Avoid potential use-after-free bugs when walking DFS referrals, mounting and performing DFS failover by ensuring that all child 0,6%
CVE-2023-34460 MED 4.8 tauri tauri Tauri is a framework for building binaries for all major desktop platforms. The 1.4.0 release includes a regression on the Filesystem scope check for dotfiles on Unix. Previously dotfiles were not implicitly allowed by the glob wildcard scopes (eg. `$HOME/*`), 0,6%
CVE-2022-43927 MED 5.9 ibm db2 IBM Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 is vulnerable to information Disclosure due to improper privilege management when a specially crafted table access is used. IBM X-Force ID: 241671. 0,6%
CVE-2022-38029 HIGH 7.0 microsoft windows_10 Windows ALPC Elevation of Privilege Vulnerability 0,6%
CVE-2022-20916 MED 6.1 cisco iot_control_center A vulnerability in the web-based management interface of Cisco IoT Control Center could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based ma 0,6%
CVE-2022-25372 HIGH 7.8 pritunl pritunl-client-electron Pritunl Client through 1.2.3019.52 on Windows allows local privilege escalation, related to an ACL entry for CREATOR OWNER in platform_windows.go. 0,6%
CVE-2021-31171 MED 4.1 microsoft sharepoint_foundation Microsoft SharePoint Information Disclosure Vulnerability 0,6%
CVE-2021-0258 MED 5.9 juniper junos A vulnerability in the forwarding of transit TCPv6 packets received on the Ethernet management interface of Juniper Networks Junos OS allows an attacker to trigger a kernel panic, leading to a Denial of Service (DoS). Continued receipt and processing of these 0,6%
CVE-2021-1682 HIGH 7.0 microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability 0,6%
CVE-2018-13375 MED 6.1 fortinet fortianalyzer An Improper Neutralization of Script-Related HTML Tags in Fortinet FortiAnalyzer 5.6.0 and below and FortiManager 5.6.0 and below allows an attacker to send DHCP request containing malicious scripts in the HOSTNAME parameter. The malicious script code is execu 0,6%
CVE-2015-9281 MED 6.1 sas web_infrastructure_platform Logon Manager in SAS Web Infrastructure Platform before 9.4M3 allows reflected XSS on the Timeout page. 0,6%