58.254 CVE seguite
789 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.254 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2019-19051 | MED 5.5 | canonical ubuntu_linux A memory leak in the i2400m_op_rfkill_sw_toggle() function in drivers/net/wimax/i2400m/op-rfkill.c in the Linux kernel before 5.3.11 allows attackers to cause a denial of service (memory consumption), aka CID-6f3ef5c25cc7. | 0,6% | — |
| CVE-2026-63039 | CRIT 9.8 | apache inlong Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This allows an attacker to inject the string value into the SQL statement, enabling SQL injection. This issue affects Apache InLong: from 2.0 | 0,6% | — |
| CVE-2026-59242 | MED 5.4 | apache airflow Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal payload through `BaseXCom.deserialize_value` without the `_check_forbidden_xcom_keys` guard, allowing an authenticated API user with XCom write-and-re | 0,6% | — |
| CVE-2026-41608 | HIGH 7.5 | apache thrift Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. | 0,6% | — |
| CVE-2026-56160 | CRIT 9.1 | microsoft azure_red_hat_openshift Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network. | 0,6% | — |
| CVE-2026-32210 | CRIT 9.3 | microsoft dynamics_365 Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network. | 0,6% | — |
| CVE-2026-24015 | CRIT 9.8 | apache iotdb A vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.7, from 2.0.0 before 2.0.7. Users are recommended to upgrade to version 1.3.7 or 2.0.7, which fixes the issue. | 0,6% | — |
| CVE-2025-23331 | HIGH 7.5 | nvidia triton_inference_server NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where a user could cause a memory allocation with excessive size value, leading to a segmentation fault, by providing an invalid request. A successful exploit of this vulnerability m | 0,6% | — |
| CVE-2025-47173 | HIGH 7.8 | microsoft 365_apps Improper input validation in Microsoft Office allows an unauthorized attacker to execute code locally. | 0,6% | — |
| CVE-2025-20256 | MED 6.5 | cisco secure_network_analytics A vulnerability in the web-based management interface of Cisco Secure Network Analytics Manager and Cisco Secure Network Analytics Virtual Manager could allow an authenticated, remote attacker with valid administrative credentials to execute arbitrary commands | 0,6% | — |
| CVE-2025-26675 | HIGH 7.8 | microsoft windows_10_21h2 Out-of-bounds read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally. | 0,6% | — |
| CVE-2025-24044 | HIGH 7.8 | microsoft windows_10_1507 Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally. | 0,6% | — |
| CVE-2024-30347 | LOW 3.3 | foxit pdf_editor Foxit PDF Reader U3D File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this | 0,6% | — |
| CVE-2023-20263 | MED 4.7 | cisco hyperflex_hx_data_platform A vulnerability in the web-based management interface of Cisco HyperFlex HX Data Platform could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of the parameters | 0,6% | — |
| CVE-2023-28286 | MED 6.1 | microsoft edge_chromium Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | 0,6% | — |
| CVE-2022-29138 | HIGH 7.0 | microsoft windows_server Windows Clustered Shared Volume Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2020-7874 | HIGH 8.8 | tobesoft nexacro Download of code without integrity check vulnerability in NEXACRO14 Runtime ActiveX control of tobesoft Co., Ltd allows the attacker to cause an arbitrary file download and execution. This vulnerability is due to incomplete validation of file download URL or f | 0,6% | — |
| CVE-2021-31208 | HIGH 7.8 | microsoft windows_10 Windows Container Manager Service Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2021-29221 | HIGH 7.0 | erlang erlang\/otp A local privilege escalation vulnerability was discovered in Erlang/OTP prior to version 23.2.3. By adding files to an existing installation's directory, a local attacker could hijack accounts of other users running Erlang programs or possibly coerce a service | 0,6% | — |
| CVE-2026-54048 | MED 5.3 | apache impala Specifying tblproperties('avro.schema.url'=' http://...' ) or with a 'file:///' URI on a table in Impala 2.0.0 to 4.5.1 on all platforms allows an attacker to trigger a GET request to internal endpoints they may not have access to but that Impala does and the | 0,6% | — |
| CVE-2026-62826 | MED 4.6 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 0,6% | — |
| CVE-2026-55135 | MED 4.6 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 0,6% | — |
| CVE-2026-55030 | MED 4.6 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 0,6% | — |
| CVE-2026-55020 | MED 4.6 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 0,6% | — |
| CVE-2026-55019 | MED 4.6 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 0,6% | — |