EN
58.306 CVE seguite
790 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.306 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2023-44254 MED 5.0 fortinet fortianalyzer An authorization bypass through user-controlled key [CWE-639] vulnerability in FortiAnalyzer version 7.4.1 and before 7.2.5 and FortiManager version 7.4.1 and before 7.2.5 may allow a remote attacker with low privileges to read sensitive data via a crafted HTT 0,5% —
CVE-2023-20177 MED 4.0 cisco secure_firewall_threat_defense A vulnerability in the SSL file policy implementation of Cisco Firepower Threat Defense (FTD) Software that occurs when the SSL/TLS connection is configured with a URL Category and the Snort 3 detection engine could allow an unauthenticated, remote attacker to 0,5% —
CVE-2023-20261 MED 6.5 cisco catalyst_sd-wan_manager A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to retrieve arbitrary files from an affected system. This vulnerability is due to improper validation of parameters that are sent to the web UI. An 0,5% —
CVE-2023-36790 HIGH 7.8 microsoft windows_server_2008 Windows RDP Encoder Mirror Driver Elevation of Privilege Vulnerability 0,5% —
CVE-2022-44679 MED 6.5 microsoft windows_10 Windows Graphics Component Information Disclosure Vulnerability 0,5% —
CVE-2022-44674 MED 5.5 microsoft windows_10 Windows Bluetooth Driver Information Disclosure Vulnerability 0,5% —
CVE-2022-41074 MED 5.5 microsoft windows_10 Windows Graphics Component Information Disclosure Vulnerability 0,5% —
CVE-2022-35828 HIGH 7.8 microsoft defender_for_endpoint Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability 0,5% —
CVE-2022-20860 HIGH 7.4 cisco nexus_dashboard A vulnerability in the SSL/TLS implementation of Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to alter communications with associated controllers or view sensitive information. This vulnerability exists because SSL server certificates 0,5% —
CVE-2020-3220 MED 6.8 cisco ios_xe A vulnerability in the hardware crypto driver of Cisco IOS XE Software for Cisco 4300 Series Integrated Services Routers and Cisco Catalyst 9800-L Wireless Controllers could allow an unauthenticated, remote attacker to disconnect legitimate IPsec VPN sessions 0,5% —
CVE-2018-7757 MED 5.5 linux linux_kernel Memory leak in the sas_smp_get_phy_events function in drivers/scsi/libsas/sas_expander.c in the Linux kernel through 4.15.7 allows local users to cause a denial of service (memory consumption) via many read accesses to files in the /sys/class/sas_phy directory 0,5% —
CVE-2010-4160 MED 6.9 linux linux_kernel Multiple integer overflows in the (1) pppol2tp_sendmsg function in net/l2tp/l2tp_ppp.c, and the (2) l2tp_ip_sendmsg function in net/l2tp/l2tp_ip.c, in the PPPoL2TP and IPoL2TP implementations in the Linux kernel before 2.6.36.2 allow local users to cause a den 0,5% —
CVE-2008-1514 MED 4.9 linux linux_kernel arch/s390/kernel/ptrace.c in Linux kernel 2.6.9, and other versions before 2.6.27-rc6, on s390 platforms allows local users to cause a denial of service (kernel panic) via the user-area-padding test from the ptrace testsuite in 31-bit mode, which triggers an i 0,5% —
CVE-2026-70105 MED 6.5 microsoft microsoft_365 Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. 0,5% —
CVE-2026-63037 CRIT 9.8 apache inlong Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This appears to allow SQL injection in the ORDER BY clause against the Manager backend database. This issue affects Apache InLong: from 2.0.0 0,5% —
CVE-2026-65796 HIGH 8.1 microsoft windows_10_1607 Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network. 0,5% —
CVE-2026-62873 CRIT 9.8 microsoft windows_admin_center Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network. 0,5% —
CVE-2026-53248 HIGH 8.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: airoha: Fix use-after-free in metadata dst teardown airoha_metadata_dst_free() runs metadata_dst_free() which frees the metadata_dst with kfree() immediately, bypassing the RCU grace pe 0,5% —
CVE-2026-40414 HIGH 7.4 microsoft windows_10_1607 Windows TCP/IP Denial of Service Vulnerability 0,5% —
CVE-2026-20960 HIGH 8.0 microsoft power_apps Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network. 0,5% —
CVE-2025-60704 HIGH 7.5 microsoft windows_10_1607 Missing cryptographic step in Windows Kerberos allows an unauthorized attacker to elevate privileges over a network. 0,5% —
CVE-2025-55699 MED 5.5 microsoft windows_10_1507 Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally. 0,5% —
CVE-2025-38089 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: sunrpc: handle SVC_GARBAGE during svc auth processing as auth error tianshuo han reported a remotely-triggerable crash if the client sends a kernel RPC server a specially crafted packet. If 0,5% —
CVE-2025-26678 HIGH 8.4 microsoft windows_10_1809 Improper access control in Windows Defender Application Control (WDAC) allows an unauthorized attacker to bypass a security feature locally. 0,5% —
CVE-2025-24986 MED 6.5 microsoft azure_promptflow_core Improper isolation or compartmentalization in Azure PromptFlow allows an unauthorized attacker to execute code over a network. 0,5% —