58.306 CVE seguite
790 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.306 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-46586 | HIGH 8.8 | apache ofbiz Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrad | 0,5% | — |
| CVE-2026-31405 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: media: dvb-net: fix OOB access in ULE extension header tables The ule_mandatory_ext_handlers[] and ule_optional_ext_handlers[] tables in handle_one_ule_extension() are declared with 255 elem | 0,5% | — |
| CVE-2026-32169 | CRIT 10.0 | microsoft azure_cloud_shell Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a network. | 0,5% | — |
| CVE-2024-30303 | HIGH 7.8 | adobe acrobat Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victi | 0,5% | — |
| CVE-2023-20232 | MED 5.3 | cisco unified_contact_center_express A vulnerability in the Tomcat implementation for Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to cause a web cache poisoning attack on an affected device. This vulnerability is due to improper input val | 0,5% | — |
| CVE-2023-40283 | HIGH 7.8 | canonical ubuntu_linux An issue was discovered in l2cap_sock_release in net/bluetooth/l2cap_sock.c in the Linux kernel before 6.4.10. There is a use-after-free because the children of an sk are mishandled. | 0,5% | — |
| CVE-2022-41157 | HIGH 8.1 | webcash serp_server_2.0 A specific file on the sERP server if Kyungrinara(ERP solution) has a fixed password with the SYSTEM authority. This vulnerability could allow attackers to leak or steal sensitive information or execute malicious commands. | 0,5% | — |
| CVE-2022-22045 | HIGH 7.8 | microsoft windows_10 Windows.Devices.Picker.dll Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2022-22156 | MED 6.5 | juniper junos An Improper Certificate Validation weakness in the Juniper Networks Junos OS allows an attacker to perform Person-in-the-Middle (PitM) attacks when a system script is fetched from a remote source at a specified HTTPS URL, which may compromise the integrity and | 0,5% | — |
| CVE-2021-38671 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2021-38667 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2020-29012 | MED 5.6 | fortinet fortisandbox An insufficient session expiration vulnerability in FortiSandbox versions 3.2.1 and below may allow an attacker to reuse the unexpired admin user session IDs to gain information about other users configured on the device, should the attacker be able to obtain | 0,5% | — |
| CVE-2021-31973 | HIGH 7.8 | microsoft windows_10 Windows GPSVC Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2021-31953 | HIGH 7.8 | microsoft windows_10 Windows Filter Manager Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2021-3489 | HIGH 7.8 | canonical ubuntu_linux The eBPF RINGBUF bpf_ringbuf_reserve() function in the Linux kernel did not check that the allocated size was smaller than the ringbuf size, allowing an attacker to perform out-of-bounds writes within the kernel and therefore, arbitrary code execution. This is | 0,5% | — |
| CVE-2021-31190 | HIGH 7.8 | microsoft windows_10 Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2021-28436 | HIGH 7.8 | microsoft windows_10 Windows Speech Runtime Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2021-28351 | HIGH 7.8 | microsoft windows_10 Windows Speech Runtime Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2021-28347 | HIGH 7.8 | microsoft windows_10 Windows Speech Runtime Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2021-28320 | HIGH 7.8 | microsoft windows_10 Windows Resource Manager PSM Service Extension Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2021-1137 | HIGH 7.8 | cisco catalyst_sd-wan_manager Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or allow an authenticated, local attacker to gain escalated privileges on an affected system. For more information about these v | 0,5% | — |
| CVE-2020-3963 | MED 5.5 | vmware cloud_foundation VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.2), and Fusion (11.x before 11.5.2) contain a use-after-free vulnerability in PVNVRAM. A malicious actor with | 0,5% | — |
| CVE-2019-1632 | MED 4.6 | cisco integrated_management_controller A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The v | 0,5% | — |
| CVE-2013-1130 | MED 6.8 | cisco anyconnect_secure_mobility_client Cisco AnyConnect Secure Mobility Client on Mac OS X uses weak permissions for a library directory, which allows local users to gain privileges via a crafted library file, aka Bug ID CSCue33619. | 0,5% | — |
| CVE-2005-2553 | LOW 2.1 | linux linux_kernel The find_target function in ptrace32.c in the Linux kernel 2.4.x before 2.4.29 does not properly handle a NULL return value from another function, which allows local users to cause a denial of service (kernel crash/oops) by running a 32-bit ltrace program with | 0,5% | — |