58.254 CVE seguite
789 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.254 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2025-53795 | CRIT 9.1 | microsoft pc_manager Improper authorization in Microsoft PC Manager allows an unauthorized attacker to elevate privileges over a network. | 0,6% | — |
| CVE-2025-4613 | HIGH 8.8 | google web_designer Path traversal in Google Web Designer's template handling versions prior to 16.3.0.0407 on Windows allows attacker to achieve remote code execution by tricking users into downloading a malicious ad template | 0,6% | — |
| CVE-2022-48985 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: mana: Fix race on per-CQ variable napi work_done After calling napi_complete_done(), the NAPIF_STATE_SCHED bit may be cleared, and another CPU can start napi thread and access per-CQ va | 0,6% | — |
| CVE-2024-20393 | HIGH 8.8 | cisco rv340_dual_wan_gigabit_vpn_router_firmware A vulnerability in the web-based management interface of Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an authenticated, remote attacker to elevate privileges on an affected device. This vulnerability exists | 0,6% | — |
| CVE-2023-52801 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: iommufd: Fix missing update of domains_itree after splitting iopt_area In iopt_area_split(), if the original iopt_area has filled a domain and is linked to domains_itree, pages_nodes have to | 0,6% | — |
| CVE-2024-23307 | MED 4.4 | linux linux_kernel Integer Overflow or Wraparound vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (md, raid, raid5 modules) allows Forced Integer Overflow. | 0,6% | — |
| CVE-2023-38161 | HIGH 7.8 | microsoft windows_10_1507 Windows GDI Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2022-22746 | MED 5.9 | mozilla firefox A race condition could have allowed bypassing the fullscreen notification which could have lead to a fullscreen window spoof being unnoticed.<br>*This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Fi | 0,6% | — |
| CVE-2022-39959 | HIGH 7.8 | panini everest_engine Panini Everest Engine 2.0.4 allows unprivileged users to create a file named Everest.exe in the %PROGRAMDATA%\Panini folder. This leads to privilege escalation because a service, running as SYSTEM, uses the unquoted path of %PROGRAMDATA%\Panini\Everest Engine\ | 0,6% | — |
| CVE-2022-39842 | MED 6.1 | debian debian_linux An issue was discovered in the Linux kernel before 5.19. In pxa3xx_gcu_write in drivers/video/fbdev/pxa3xx-gcu.c, the count parameter has a type conflict of size_t versus int, causing an integer overflow and bypassing the size check. After that, because it is | 0,6% | — |
| CVE-2021-27064 | HIGH 7.8 | microsoft visual_studio_2017 Visual Studio Installer Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2020-6175 | MED 5.9 | citrix citrix_sd-wan_center Citrix SD-WAN 10.2.x before 10.2.6 and 11.0.x before 11.0.3 has Missing SSL Certificate Validation. | 0,6% | — |
| CVE-2016-1467 | MED 6.5 | cisco videoscape_session_resource_manager Cisco Videoscape Session Resource Manager (VSRM) allows remote attackers to cause a denial of service (device restart) by sending a traffic flood to upstream devices, aka Bug ID CSCva01813. | 0,6% | — |
| CVE-2015-5652 | HIGH 7.2 | python python Untrusted search path vulnerability in python.exe in Python through 3.5.0 on Windows allows local users to gain privileges via a Trojan horse readline.pyd file in the current working directory. NOTE: the vendor says "It was determined that this is a longtime | 0,6% | — |
| CVE-2026-42987 | HIGH 8.1 | microsoft windows_server_2012 Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network. | 0,6% | — |
| CVE-2025-54656 | MED 6.5 | apache struts_extras ** UNSUPPORTED WHEN ASSIGNED ** Improper Output Neutralization for Logs vulnerability in Apache Struts. This issue affects Apache Struts Extras: before 2. When using LookupDispatchAction, in some cases, Struts may print untrusted input to the logs without an | 0,6% | — |
| CVE-2020-17163 | HIGH 7.8 | microsoft python Visual Studio Code Python Extension Remote Code Execution Vulnerability | 0,6% | — |
| CVE-2023-36729 | HIGH 7.8 | microsoft windows_10_1507 Named Pipe File System Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2023-20034 | HIGH 7.5 | cisco sd-wan Vulnerability in the Elasticsearch database used in the of Cisco SD-WAN vManage software could allow an unauthenticated, remote attacker to access the Elasticsearch configuration database of an affected device with the privileges of the elasticsearch user. | 0,6% | — |
| CVE-2023-4335 | HIGH 7.5 | broadcom raid_controller_web_interface Broadcom RAID Controller Web server (nginx) is serving private server-side files without any authentication on Linux | 0,6% | — |
| CVE-2022-38043 | MED 5.5 | microsoft windows_10 Windows Security Support Provider Interface Information Disclosure Vulnerability | 0,6% | — |
| CVE-2022-38026 | MED 5.5 | microsoft windows_10 Windows DHCP Client Information Disclosure Vulnerability | 0,6% | — |
| CVE-2022-38025 | MED 5.5 | microsoft windows_11 Windows Distributed File System (DFS) Information Disclosure Vulnerability | 0,6% | — |
| CVE-2022-37996 | MED 5.5 | microsoft windows_10 Windows Kernel Memory Information Disclosure Vulnerability | 0,6% | — |
| CVE-2021-33762 | HIGH 7.0 | microsoft azure_cyclecloud Azure CycleCloud Elevation of Privilege Vulnerability | 0,6% | — |