EN
58.306 CVE seguite
790 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.306 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2025-30381 HIGH 7.8 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0,5% —
CVE-2025-30379 HIGH 7.8 microsoft 365_apps Release of invalid pointer or reference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0,5% —
CVE-2022-35749 HIGH 7.8 microsoft windows_10_1507 Windows Digital Media Receiver Elevation of Privilege Vulnerability 0,5% —
CVE-2022-35746 HIGH 7.8 microsoft windows_10_1507 Windows Digital Media Receiver Elevation of Privilege Vulnerability 0,5% —
CVE-2021-26099 MED 4.4 fortinet fortimail Missing cryptographic steps in the Identity-Based Encryption service of FortiMail before 7.0.0 may allow an attacker who comes in possession of the encrypted master keys to compromise their confidentiality by observing a few invariant properties of the ciphert 0,5% —
CVE-2019-4738 MED 6.5 ibm sterling_b2b_integrator IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 and 6.0.0.0 through 6.0.3.1 discloses sensitive information to an authenticated user from the dashboard UI which could be used in further attacks against the system. IBM X-Force ID: 172753. 0,5% —
CVE-2019-6699 MED 5.4 fortinet fortiadc An improper neutralization of input vulnerability in Fortinet FortiADC 5.3.3 and earlier may allow an attacker to execute a stored Cross Site Scripting (XSS) via a field in the traffic group interface. 0,5% —
CVE-2019-1805 MED 4.3 cisco wireless_lan_controller_software A vulnerability in certain access control mechanisms for the Secure Shell (SSH) server implementation for Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, adjacent attacker to access a CLI instance on an affected device. The vulnera 0,5% —
CVE-2017-0448 MED 5.5 google android An information disclosure vulnerability in the NVIDIA video driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user p 0,5% —
CVE-2014-3122 MED 4.9 canonical ubuntu_linux The try_to_unmap_cluster function in mm/rmap.c in the Linux kernel before 3.14.3 does not properly consider which pages must be locked, which allows local users to cause a denial of service (system crash) by triggering a memory-usage pattern that requires remo 0,5% —
CVE-2010-1966 MED 4.6 hp insight_control Unspecified vulnerability in HP Insight Control power management for Windows before 6.1 allows local users to read or modify data, or cause a denial of service, via unknown vectors. 0,5% —
CVE-2026-65789 HIGH 8.1 microsoft windows_10_1607 Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. 0,5% —
CVE-2026-45171 HIGH 8.8 paloaltonetworks idira_privileged_session_manager Incomplete input validation and improperly configured folder permissions within Idira Privileged Session Manager (PSM) versions prior to 15.0.3, 14.6.3, 14.2.5, and 14.0.5, an authenticated, low-privileged user could potentially execute arbitrary code. CyberAr 0,5% —
CVE-2026-30778 HIGH 7.5 apache skywalking The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information of MySQL/PostgreSQL. This issue affects Apache SkyWalking: from 9.7.0 through 10.3.0. Users are recommended to upgrade to version 10.4.0, which fixes the issue. 0,5% —
CVE-2026-21259 HIGH 7.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to elevate privileges locally. 0,5% —
CVE-2024-53146 CRIT 9.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent a potential integer overflow If the tag length is >= U32_MAX - 3 then the "length + 4" addition can result in an integer overflow. Address this by splitting the decoding into s 0,5% —
CVE-2024-30099 HIGH 7.0 microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability 0,5% —
CVE-2023-5808 HIGH 7.6 hitachi vantara_hitachi_network_attached_storage SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in a Storage administrative role are able to access HNAS configuration backup and diagnostic data, that would normally be bar 0,5% —
CVE-2023-45871 HIGH 7.5 debian debian_linux An issue was discovered in drivers/net/ethernet/intel/igb/igb_main.c in the IGB driver in the Linux kernel before 6.5.3. A buffer size may not be adequate for frames larger than the MTU. 0,5% —
CVE-2023-28235 MED 6.8 microsoft windows_10_1809 Windows Lock Screen Security Feature Bypass Vulnerability 0,5% —
CVE-2021-43239 HIGH 7.1 microsoft windows_10 Windows Recovery Environment Agent Elevation of Privilege Vulnerability 0,5% —
CVE-2021-42312 HIGH 7.8 microsoft defender_for_iot Microsoft Defender for IoT Elevation of Privilege Vulnerability 0,5% —
CVE-2020-15935 MED 4.3 fortinet fortiadc A cleartext storage of sensitive information in GUI in FortiADC versions 5.4.3 and below, 6.0.0 and below may allow a remote authenticated attacker to retrieve some sensitive information such as users LDAP passwords and RADIUS shared secret by deobfuscating th 0,5% —
CVE-2021-36968 HIGH 7.8 microsoft windows_7 Windows DNS Elevation of Privilege Vulnerability 0,5% —
CVE-2021-23018 HIGH 7.4 f5 nginx_controller Intra-cluster communication does not use TLS. The services within the NGINX Controller 3.x before 3.4.0 namespace are using cleartext protocols inside the cluster. 0,5% —