58.165 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.165 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2023-44154 | HIGH 8.1 | acronis cyber_protect Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979. | 0,6% | — |
| CVE-2023-28291 | HIGH 8.4 | microsoft raw_image_extension Raw Image Extension Remote Code Execution Vulnerability | 0,6% | — |
| CVE-2023-23398 | HIGH 7.1 | microsoft 365_apps Microsoft Excel Spoofing Vulnerability | 0,6% | — |
| CVE-2022-38170 | MED 4.7 | apache airflow In Apache Airflow prior to 2.3.4, an insecure umask was configured for numerous Airflow components when running with the `--daemon` flag which could result in a race condition giving world-writable files in the Airflow home directory and allowing local users t | 0,6% | — |
| CVE-2021-42300 | MED 6.0 | microsoft azure_sphere Azure Sphere Tampering Vulnerability | 0,6% | — |
| CVE-2021-25252 | MED 5.5 | trendmicro apex_central Trend Micro's Virus Scan API (VSAPI) and Advanced Threat Scan Engine (ATSE) - are vulnerable to a memory exhaustion vulnerability that may lead to denial-of-service or system freeze if exploited by an attacker using a specially crafted file. | 0,6% | — |
| CVE-2020-26083 | MED 4.8 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative credentials to conduct a cross-site scripting (XSS) attack against a user of the interface. The vuln | 0,6% | — |
| CVE-2020-3589 | MED 4.8 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker with administrative credentials to conduct a cross-site scripting (XSS) attack against a user of the interface. | 0,6% | — |
| CVE-2020-3491 | MED 5.5 | cisco vision_dynamic_signage_director A vulnerability in the web-based management interface of Cisco Vision Dynamic Signage Director could allow an authenticated, remote attacker with administrative privileges to conduct a cross-site scripting (XSS) attack against a user of the interface on an aff | 0,6% | — |
| CVE-2020-3464 | MED 4.8 | cisco ucs_director A vulnerability in the web-based management interface of Cisco UCS Director could allow an authenticated, remote attacker with administrative credentials to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability exists b | 0,6% | — |
| CVE-2020-10732 | LOW 3.3 | canonical ubuntu_linux A flaw was found in the Linux kernel's implementation of Userspace core dumps. This flaw allows an attacker with a local account to crash a trivial program and exfiltrate private kernel data. | 0,6% | — |
| CVE-2020-7053 | HIGH 7.8 | linux linux_kernel In the Linux kernel 4.14 longterm through 4.14.165 and 4.19 longterm through 4.19.96 (and 5.x before 5.2), there is a use-after-free (write) in the i915_ppgtt_close function in drivers/gpu/drm/i915/i915_gem_gtt.c, aka CID-7dc40713618c. This is related to i915_ | 0,6% | — |
| CVE-2016-6375 | MED 5.3 | cisco wireless_lan_controller_software Cisco Wireless LAN Controller (WLC) devices before 8.0.140.0, 8.1.x and 8.2.x before 8.2.121.0, and 8.3.x before 8.3.102.0 allow remote attackers to cause a denial of service (device reload) by sending crafted Inter-Access Point Protocol (IAPP) packets and the | 0,6% | — |
| CVE-2004-2013 | HIGH 7.8 | linux linux_kernel Integer overflow in the SCTP_SOCKOPT_DEBUG_NAME SCTP socket option in socket.c in the Linux kernel 2.4.25 and earlier allows local users to execute arbitrary code via an optlen value of -1, which causes kmalloc to allocate 0 bytes of memory. | 0,6% | — |
| CVE-2026-81381 | MED 6.5 | microsoft visual_studio_code Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network. | 0,6% | — |
| CVE-2025-50213 | CRIT 9.8 | apache apache-airflow-providers-snowflake Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) vulnerability in Apache Airflow Providers Snowflake. This issue affects Apache Airflow Providers Snowflake: before 6.4.0. Sanitation of table and stage parameters were ad | 0,6% | — |
| CVE-2025-32702 | HIGH 7.8 | microsoft visual_studio_2019 Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an unauthorized attacker to execute code locally. | 0,6% | — |
| CVE-2024-49072 | HIGH 7.8 | microsoft windows_10_1507 Windows Task Scheduler Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2024-20470 | HIGH 7.2 | cisco rv340_dual_wan_gigabit_vpn_router_firmware A vulnerability in the web-based management interface of Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device. In order to exploit this | 0,6% | — |
| CVE-2024-20429 | MED 6.5 | cisco asyncos A vulnerability in the web-based management interface of Cisco AsyncOS for Secure Email Gateway could allow an authenticated, remote attacker to execute arbitrary system commands on an affected device. This vulnerability is due to insufficient input validat | 0,6% | — |
| CVE-2021-47232 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: can: j1939: fix Use-after-Free, hold skb ref while in use This patch fixes a Use-after-Free found by the syzbot. The problem is that a skb is taken from the per-session skb queue, without i | 0,6% | — |
| CVE-2023-42525 | HIGH 7.5 | withsecure atlant Certain WithSecure products allow an infinite loop in a scanning engine via unspecified file types. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 a | 0,6% | — |
| CVE-2023-42524 | HIGH 7.5 | withsecure atlant Certain WithSecure products allow an infinite loop in a scanning engine via unspecified file types. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 a | 0,6% | — |
| CVE-2023-42523 | HIGH 7.5 | withsecure atlant Certain WithSecure products allow a remote crash of a scanning engine via unpacking of a PE file. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and | 0,6% | — |
| CVE-2023-42522 | HIGH 7.5 | withsecure atlant Certain WithSecure products allow a remote crash of a scanning engine via processing of an import struct in a PE file. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpo | 0,6% | — |