EN
58.306 CVE seguite
789 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.306 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2026-20211 CRIT 9.1 A vulnerability in Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid high-privileged administrative creden 0,6% —
CVE-2026-68834 HIGH 8.0 microsoft windows_10_1607 Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network. 0,6% —
CVE-2026-50426 MED 6.8 microsoft windows_10_1607 Relative path traversal in DNS Server allows an authorized attacker to execute code over an adjacent network. 0,6% —
CVE-2026-35438 HIGH 8.3 microsoft windows_admin_center Missing authorization in Windows Admin Center allows an authorized attacker to elevate privileges over a network. 0,6% —
CVE-2026-21537 HIGH 8.8 microsoft defender_for_endpoint Improper control of generation of code ('code injection') in Microsoft Defender for Linux allows an unauthorized attacker to execute code over an adjacent network. 0,6% —
CVE-2025-62556 HIGH 7.8 microsoft 365_apps Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0,6% —
CVE-2022-40231 MED 4.3 ibm sterling_b2b_integrator IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.0 could allow an authenticated user to perform unauthorized actions due to improper access controls. IBM X-Force ID: 235533. 0,6% —
CVE-2023-23784 MED 5.7 fortinet fortiweb A relative path traversal in Fortinet FortiWeb version 7.0.0 through 7.0.2, FortiWeb version 6.3.6 through 6.3.20, FortiWeb 6.4 all versions allows attacker to information disclosure via specially crafted web requests. 0,6% —
CVE-2023-21694 MED 6.8 microsoft windows_10 Windows Fax Service Remote Code Execution Vulnerability 0,6% —
CVE-2015-10010 LOW 3.1 cisco openresolve A vulnerability was found in OpenDNS OpenResolve. It has been rated as problematic. Affected by this issue is the function get of the file resolverapi/endpoints.py of the component API. The manipulation leads to cross site scripting. The attack may be launched 0,6% —
CVE-2022-20938 MED 4.3 cisco secure_firewall_management_center A vulnerability in the module import function of the administrative interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to view sensitive information. This vulnerability is due to insufficient validati 0,6% —
CVE-2022-31679 LOW 3.7 vmware spring_data_rest Applications that allow HTTP PATCH access to resources exposed by Spring Data REST in versions 3.6.0 - 3.5.5, 3.7.0 - 3.7.2, and older unsupported versions, if an attacker knows about the structure of the underlying domain model, they can craft HTTP requests t 0,6% —
CVE-2021-42319 MED 4.7 microsoft visual_studio_2017 Visual Studio Elevation of Privilege Vulnerability 0,6% —
CVE-2019-6692 HIGH 7.8 fortinet forticlient A malicious DLL preload vulnerability in Fortinet FortiClient for Windows 6.2.0 and below allows a privileged attacker to perform arbitrary code execution via forging that DLL. 0,6% —
CVE-2017-18549 MED 5.5 linux linux_kernel An issue was discovered in drivers/scsi/aacraid/commctrl.c in the Linux kernel before 4.13. There is potential exposure of kernel stack memory because aac_send_raw_srb does not initialize the reply structure. 0,6% —
CVE-2018-14889 HIGH 7.8 apache couchdb CouchDB in Vectra Networks Cognito Brain and Sensor before 4.3 contains a local code execution vulnerability. 0,6% —
CVE-2004-1072 HIGH 7.2 linux linux_kernel The binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, may create an interpreter name string that is not NULL terminated, which could cause strings longer than PATH_MAX to be used, leading to buffer overflows that allow 0,6% —
CVE-2026-67593 CRIT 9.1 apache artemis A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a queue on the Artemis broker before the connection authentication and authorization stage or at any time thereafter. This issue affects Apache Artemis: from 2. 0,6% —
CVE-2026-78442 HIGH 8.8 microsoft sql_server_2017 Heap-based buffer overflow in Windows OLE DB allows an unauthorized attacker to execute code over a network. 0,6% —
CVE-2026-69414 HIGH 7.8 microsoft malware_protection_engine Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ". 0,6% —
CVE-2026-33006 MED 4.8 apache http_server A timing attack against mod_auth_digest in Apache HTTP Server 2.4.66 allows a bypass of Digest authentication by a remote attacker. Users are recommended to upgrade to version 2.4.67, which fixes this issue. 0,6% —
CVE-2026-40542 HIGH 7.3 apache httpclient Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification. Users are recommended to upgrade to version 5.6.1, which fixes thi 0,6% —
CVE-2025-53192 HIGH 8.8 apache commons_ognl ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Expression/Command Delimiters vulnerability in Apache Commons OGNL. This issue affects Apache Commons OGNL: all versions. When using the API Ognl.getValue​, the OGNL engine parses and evaluates the 0,6% —
CVE-2025-49812 HIGH 7.4 apache http_server In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows a man-in-the-middle attacker to hijack an HTTP session via a TLS upgrade. Only configurations using "SSLEngine optional" to enable TLS upg 0,6% —
CVE-2023-52885 HIGH 8.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Fix UAF in svc_tcp_listen_data_ready() After the listener svc_sock is freed, and before invoking svc_tcp_accept() for the established child sock, there is a window that the newsock r 0,6% —