58.254 CVE seguite
789 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.254 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2020-24562 | HIGH 7.8 | trendmicro officescan A vulnerability in Trend Micro OfficeScan XG SP1 on Microsoft Windows may allow an attacker to create a hard link to any file on the system, which then could be manipulated to gain a privilege escalation and code execution. An attacker must first obtain the ab | 0,6% | — |
| CVE-2019-19480 | MED 4.6 | opensc_project opensc An issue was discovered in OpenSC through 0.19.0 and 0.20.x through 0.20.0-rc3. libopensc/pkcs15-prkey.c has an incorrect free operation in sc_pkcs15_decode_prkdf_entry. | 0,6% | — |
| CVE-2019-5694 | MED 6.5 | nvidia gpu_driver NVIDIA Windows GPU Display Driver, R390 driver version, contains a vulnerability in NVIDIA Control Panel in which it incorrectly loads Windows system DLLs without validating the path or signature (also known as a binary planting or DLL preloading attack), whic | 0,6% | — |
| CVE-2012-6026 | MED 6.1 | cisco aironet_access_point_software The HTTP Profiler on the Cisco Aironet Access Point with software 15.2 and earlier does not properly manage buffers, which allows remote attackers to cause a denial of service (device reload) via crafted HTTP requests, aka Bug ID CSCuc62460. | 0,6% | — |
| CVE-2026-73016 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. | 0,6% | — |
| CVE-2026-71328 | HIGH 8.8 | microsoft .net Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network. | 0,6% | — |
| CVE-2026-8505 | CRIT 9.8 | langflow langflow IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthenticated users to trigger the execution of any flow. The system incorrectly bypasses API key validation when the WEBHOOK_AUTH_ENABLE configuratio | 0,6% | — |
| CVE-2025-59286 | CRIT 9.3 | microsoft 365_copilot_chat Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network. | 0,6% | — |
| CVE-2025-59272 | CRIT 9.3 | microsoft 365_copilot_chat Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to perform information disclosure locally. | 0,6% | — |
| CVE-2025-59252 | CRIT 9.3 | microsoft 365_word_copilot Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network. | 0,6% | — |
| CVE-2025-26688 | HIGH 7.8 | microsoft windows_10_1507 Stack-based buffer overflow in Microsoft Virtual Hard Drive allows an authorized attacker to elevate privileges locally. | 0,6% | — |
| CVE-2025-24995 | HIGH 7.8 | microsoft windows_10_1507 Heap-based buffer overflow in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally. | 0,6% | — |
| CVE-2025-21267 | MED 4.4 | microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability | 0,6% | — |
| CVE-2024-33510 | MED 4.3 | fortinet fortios An improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability [CWE-74] in FortiOS version 7.4.3 and below, version 7.2.8 and below, version 7.0.16 and below; FortiProxy version 7.4.3 and below, version 7.2. | 0,6% | — |
| CVE-2024-49999 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: afs: Fix the setting of the server responding flag In afs_wait_for_operation(), we set transcribe the call responded flag to the server record that we used after doing the fileserver iterati | 0,6% | — |
| CVE-2023-6794 | MED 5.5 | paloaltonetworks pan-os An arbitrary file upload vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write administrator with access to the web interface to disrupt system processes and potentially execute arbitrary code with limited privileges on the fi | 0,6% | — |
| CVE-2016-1203 | HIGH 8.1 | saat netizen Improper file verification vulnerability in SaAT Netizen installer ver.1.2.0.424 and earlier, and SaAT Netizen ver.1.2.0.8 (Build427) and earlier allows a remote unauthenticated attacker to conduct a man-in-the-middle attack. A successful exploitation may resu | 0,6% | — |
| CVE-2023-1048 | MED 5.3 | techpowerup dram_calculator_for_ryzen A vulnerability, which was classified as critical, has been found in TechPowerUp Ryzen DRAM Calculator 1.2.0.5. This issue affects some unknown processing in the library WinRing0x64.sys. The manipulation leads to improper initialization. Local access is requir | 0,6% | — |
| CVE-2022-43719 | HIGH 8.8 | apache superset Two legacy REST API endpoints for approval and request access are vulnerable to cross site request forgery. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0. | 0,6% | — |
| CVE-2022-22750 | MED 6.5 | mozilla firefox By generally accepting and passing resource handles across processes, a compromised content process might have confused higher privileged processes to interact with handles that the unprivileged process should not have access to.<br>*This bug only affects Fire | 0,6% | — |
| CVE-2021-32593 | MED 6.5 | fortinet fortiwan A use of a broken or risky cryptographic algorithm vulnerability [CWE-327] in the Dynamic Tunnel Protocol of FortiWAN before 4.5.9 may allow an unauthenticated remote attacker to decrypt and forge protocol communication messages. | 0,6% | — |
| CVE-2021-36167 | MED 4.3 | fortinet forticlient An improper authorization vulnerabiltiy [CWE-285] in FortiClient Windows versions 7.0.0 and 6.4.6 and below and 6.2.8 and below may allow an unauthenticated attacker to bypass the webfilter control via modifying the session-id paramater. | 0,6% | — |
| CVE-2021-22035 | MED 4.3 | vmware cloud_foundation VMware vRealize Log Insight (8.x prior to 8.6) contains a CSV(Comma Separated Value) injection vulnerability in interactive analytics export function. An authenticated malicious actor with non-administrative privileges may be able to embed untrusted data prior | 0,6% | — |
| CVE-2021-23001 | MED 4.3 | f5 big-ip_access_policy_manager On versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, the upload functionality in BIG-IP Advanced WAF and BIG-IP ASM allows an authenticated user to upload | 0,6% | — |
| CVE-2021-1733 | HIGH 7.8 | microsoft psexec Sysinternals PsExec Elevation of Privilege Vulnerability | 0,6% | — |