58.165 CVE seguite
789 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.165 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-23980 | MED 6.5 | apache superset Improper Neutralization of Special Elements used in a SQL Command ('SQL Injection') vulnerability in Apache Superset allows an authenticated user with read access to conduct error-based SQL injection via the sqlExpression or where parameters. This issue affec | 0,6% | — |
| CVE-2024-41177 | MED 6.1 | apache zeppelin Incomplete Blacklist to Cross-Site Scripting vulnerability in Apache Zeppelin. This issue affects Apache Zeppelin: before 0.12.0. Users are recommended to upgrade to version 0.12.0, which fixes the issue. | 0,6% | — |
| CVE-2025-29976 | HIGH 7.8 | microsoft sharepoint_server Improper privilege management in Microsoft Office SharePoint allows an authorized attacker to elevate privileges locally. | 0,6% | — |
| CVE-2024-49043 | HIGH 7.8 | microsoft sql_server_2016 Microsoft.SqlServer.XEvent.Configuration.dll Remote Code Execution Vulnerability | 0,6% | — |
| CVE-2024-43457 | HIGH 7.8 | microsoft windows_11_24h2 Windows Setup and Deployment Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2024-33879 | CRIT 9.8 | virtosoftware sharepoint_bulk_file_download An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileDownloader/Api/Download.ashx isCompleted method allows arbitrary file download and deletion via absolute path traversal in the path parameter | 0,6% | — |
| CVE-2024-5692 | MED 6.5 | mozilla firefox On Windows 10, when using the 'Save As' functionality, an attacker could have tricked the browser into saving the file with a disallowed extension such as `.url` by including an invalid character in the extension. *Note:* This issue only affected Windows opera | 0,6% | — |
| CVE-2024-22240 | MED 4.9 | vmware aria_operations_for_networks Aria Operations for Networks contains a local file read vulnerability. A malicious actor with admin privileges may exploit this vulnerability leading to unauthorized access to sensitive information. | 0,6% | — |
| CVE-2024-22099 | MED 6.3 | linux linux_kernel NULL Pointer Dereference vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (net, bluetooth modules) allows Overflow Buffers. This vulnerability is associated with program files /net/bluetooth/rfcomm/core.C. This issue affects Linux kernel: v2.6.12 | 0,6% | — |
| CVE-2022-29151 | HIGH 7.0 | microsoft windows_server Windows Cluster Shared Volume (CSV) Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2022-29150 | HIGH 7.0 | microsoft windows_server Windows Cluster Shared Volume (CSV) Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2022-29126 | HIGH 7.0 | microsoft windows_10 Tablet Windows User Interface Application Core Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2021-1399 | MED 4.3 | cisco unified_communications_manager A vulnerability in the Self Care Portal of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to modify data on an affected system | 0,6% | — |
| CVE-2021-1239 | MED 4.8 | cisco secure_firewall_management_center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected system. | 0,6% | — |
| CVE-2021-1238 | MED 4.8 | cisco secure_firewall_management_center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected system. | 0,6% | — |
| CVE-2019-1690 | MED 6.5 | cisco application_policy_infrastructure_controller A vulnerability in the management interface of Cisco Application Policy Infrastructure Controller (APIC) software could allow an unauthenticated, adjacent attacker to gain unauthorized access on an affected device. The vulnerability is due to a lack of proper | 0,6% | — |
| CVE-2017-3847 | MED 5.4 | cisco secure_firewall_management_center A vulnerability in the web framework of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface. More Information: CSCvc72741. Known Affected Releases: 6 | 0,6% | — |
| CVE-2007-0005 | MED 6.9 | omnikey.aaitg omnikey_cardman_4040 Multiple buffer overflows in the (1) read and (2) write handlers in the Omnikey CardMan 4040 driver in the Linux kernel before 2.6.21-rc3 allow local users to gain privileges. | 0,6% | — |
| CVE-2026-35422 | MED 6.5 | microsoft windows_10_1607 Authentication bypass using an alternate path or channel in Windows TCP/IP allows an authorized attacker to bypass a security feature over a network. | 0,6% | — |
| CVE-2025-62563 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0,6% | — |
| CVE-2024-20520 | MED 6.5 | cisco rv042_firmware A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, Administrator-level, remote attacker to execute arbitrary code as the root user. To exploit this vulnerability, | 0,6% | — |
| CVE-2024-20519 | MED 6.5 | cisco rv042_firmware A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, Administrator-level, remote attacker to execute arbitrary code as the root user. To exploit this vulnerability, | 0,6% | — |
| CVE-2024-20518 | MED 6.5 | cisco rv042_firmware A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, Administrator-level, remote attacker to execute arbitrary code as the root user. To exploit this vulnerability, | 0,6% | — |
| CVE-2024-40907 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ionic: fix kernel panic in XDP_TX action In the XDP_TX path, ionic driver sends a packet to the TX path with rx page and corresponding dma address. After tx is done, ionic_tx_clean() frees t | 0,6% | — |
| CVE-2024-6292 | HIGH 8.8 | fedoraproject fedora Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 0,6% | — |