58.165 CVE seguite
789 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.165 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2023-40714 | CRIT 9.9 | fortinet fortisiem A relative path traversal in Fortinet FortiSIEM versions 7.0.0, 6.7.0 through 6.7.2, 6.6.0 through 6.6.3, 6.5.1, 6.5.0 allows attacker to escalate privilege via uploading certain GUI elements | 0,6% | — |
| CVE-2024-47678 | CRIT 9.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: icmp: change the order of rate limits ICMP messages are ratelimited : After the blamed commits, the two rate limiters are applied in this order: 1) host wide ratelimit (icmp_global_allow() | 0,6% | — |
| CVE-2024-30059 | MED 6.1 | microsoft intune_mobile_application_management Microsoft Intune for Android Mobile Application Management Tampering Vulnerability | 0,6% | — |
| CVE-2024-26864 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tcp: Fix refcnt handling in __inet_hash_connect(). syzbot reported a warning in sk_nulls_del_node_init_rcu(). The commit 66b60b0c8c4a ("dccp/tcp: Unhash sk from ehash for tb2 alloc failure | 0,6% | — |
| CVE-2023-26607 | HIGH 7.1 | linux linux_kernel In the Linux kernel 6.0.8, there is an out-of-bounds read in ntfs_attr_find in fs/ntfs/attrib.c. | 0,6% | — |
| CVE-2022-41123 | HIGH 7.8 | microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2021-34487 | HIGH 7.0 | microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2020-29370 | HIGH 7.0 | linux linux_kernel An issue was discovered in kmem_cache_alloc_bulk in mm/slub.c in the Linux kernel before 5.5.11. The slowpath lacks the required TID increment, aka CID-fd4d9c7d0c71. | 0,6% | — |
| CVE-2019-19602 | MED 6.1 | canonical ubuntu_linux fpregs_state_valid in arch/x86/include/asm/fpu/internal.h in the Linux kernel before 5.4.2, when GCC 9 is used, allows context-dependent attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact because of incorrect f | 0,6% | — |
| CVE-2018-10854 | MED 5.4 | redhat cloudforms_management_engine cloudforms version, cloudforms 5.8 and cloudforms 5.9, is vulnerable to a cross-site-scripting. A flaw was found in CloudForms's v2v infrastructure mapping delete feature. A stored cross-site scripting due to improper sanitization of user input in Name field. | 0,6% | — |
| CVE-2017-12279 | MED 4.3 | cisco aironet_ap_firmware A vulnerability in the packet processing code of Cisco IOS Software for Cisco Aironet Access Points could allow an unauthenticated, adjacent attacker to retrieve content from memory on an affected device, which could lead to the disclosure of confidential info | 0,6% | — |
| CVE-2017-4924 | HIGH 8.8 | vmware esxi VMware ESXi (ESXi 6.5 without patch ESXi650-201707101-SG), Workstation (12.x before 12.5.7) and Fusion (8.x before 8.5.8) contain an out-of-bounds write vulnerability in SVGA device. This issue may allow a guest to execute code on the host. | 0,6% | — |
| CVE-2026-82435 | CRIT 9.8 | Description The worker's Netty message decoder is installed ahead of the SASL authentication handlers in the pipeline and acts on frames before any authentication has taken place. It allocated buffers sized from a length field carried in the frame, so a singl | 0,6% | — |
| CVE-2026-80080 | HIGH 8.8 | microsoft 365_apps Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | 0,6% | — |
| CVE-2026-80077 | HIGH 8.8 | microsoft remote_desktop_client Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 0,6% | — |
| CVE-2026-80074 | HIGH 8.8 | microsoft remote_desktop_client Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 0,6% | — |
| CVE-2026-70336 | HIGH 8.8 | microsoft visual_studio_code Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network. | 0,6% | — |
| CVE-2026-62795 | HIGH 8.8 | microsoft windows_10_1607 Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network. | 0,6% | — |
| CVE-2026-58389 | HIGH 7.5 | apache thrift Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. | 0,6% | — |
| CVE-2026-55968 | HIGH 7.5 | apache thrift Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Node.js bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the iss | 0,6% | — |
| CVE-2026-43871 | HIGH 7.5 | apache thrift Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. | 0,6% | — |
| CVE-2026-56188 | CRIT 9.8 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized attacker to execute code over a network. | 0,6% | — |
| CVE-2026-33414 | HIGH 7.8 | podman_project podman Podman is a tool for managing OCI containers and pods. Versions 4.8.0 through 5.8.1 contain a command injection vulnerability in the HyperV machine backend in pkg/machine/hyperv/stubber.go, where the VM image path is inserted into a PowerShell double-quoted st | 0,6% | — |
| CVE-2026-23969 | MED 6.5 | apache superset Apache Superset utilizes a configurable dictionary, DISALLOWED_SQL_FUNCTIONS, to restrict the execution of potentially sensitive SQL functions within SQL Lab and charts. While this feature included restrictions for engines like PostgreSQL, a vulnerability was | 0,6% | — |
| CVE-2025-10226 | CRIT 9.8 | axxonsoft axxon_one Dependency on Vulnerable Third-Party Component (CWE-1395) in the PostgreSQL backend in AxxonSoft Axxon One (C-Werk) 2.0.8 and earlier on Windows and Linux allows a remote attacker to escalate privileges, execute arbitrary code, or cause denial-of-service via e | 0,6% | — |