58.306 CVE seguite
790 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.306 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2023-27470 | HIGH 7.0 | n-able take_control BASupSrvcUpdater.exe in N-able Take Control Agent through 7.0.41.1141 before 7.0.43 has a TOCTOU Race Condition via a pseudo-symlink at %PROGRAMDATA%\GetSupportService_N-Central\PushUpdates, leading to arbitrary file deletion. | 0,5% | — |
| CVE-2022-1734 | HIGH 7.0 | debian debian_linux A flaw in Linux Kernel found in nfcmrvl_nci_unregister_dev() in drivers/nfc/nfcmrvl/main.c can lead to use after free both read or write when non synchronized between cleanup routine and firmware download routine. | 0,5% | — |
| CVE-2019-0067 | MED 6.5 | juniper junos Receipt of a specific link-local IPv6 packet destined to the RE may cause the system to crash and restart (vmcore). By continuously sending a specially crafted IPv6 packet, an attacker can repeatedly crash the system causing a prolonged Denial of Service (DoS) | 0,5% | — |
| CVE-2018-1980 | HIGH 8.4 | ibm db2 IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-ForceID: 154078. | 0,5% | — |
| CVE-2018-8822 | HIGH 7.8 | canonical ubuntu_linux Incorrect buffer length handling in the ncp_read_kernel function in fs/ncpfs/ncplib_kernel.c in the Linux kernel through 4.15.11, and in drivers/staging/ncpfs/ncplib_kernel.c in the Linux kernel 4.16-rc through 4.16-rc6, could be exploited by malicious NCPFS s | 0,5% | — |
| CVE-2008-2365 | MED 4.7 | linux linux_kernel Race condition in the ptrace and utrace support in the Linux kernel 2.6.9 through 2.6.25, as used in Red Hat Enterprise Linux (RHEL) 4, allows local users to cause a denial of service (oops) via a long series of PTRACE_ATTACH ptrace calls to another user's pro | 0,5% | — |
| CVE-2026-68569 | HIGH 8.1 | apache tomcat Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm. This issue affects Apache Tomcat: from 11.0.0-M1 thr | 0,5% | — |
| CVE-2026-65811 | HIGH 8.8 | microsoft power_bi_report_server Improper input validation in Power BI allows an authorized attacker to execute code over a network. | 0,5% | — |
| CVE-2026-55145 | MED 6.3 | microsoft copilot Improper neutralization of special elements used in a command ('command injection') in Outlook Copilot allows an authorized attacker to perform tampering over a network. | 0,5% | — |
| CVE-2026-55122 | HIGH 7.1 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | 0,5% | — |
| CVE-2026-49875 | CRIT 9.8 | apache cxf Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to upgrade to versions 4.2.2 o | 0,5% | — |
| CVE-2026-46119 | CRIT 9.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: libceph: Fix slab-out-of-bounds access in auth message processing If a (potentially corrupted) message of type CEPH_MSG_AUTH_REPLY contains a positive value in its result field, it is treate | 0,5% | — |
| CVE-2026-40411 | CRIT 9.9 | microsoft azure_virtual_network_gateway Improper input validation in Azure Virtual Network Gateway allows an authorized attacker to execute code over a network. | 0,5% | — |
| CVE-2026-31995 | MED 5.3 | openclaw openclaw OpenClaw versions 2026.1.21 prior to 2026.2.19 contain a command injection vulnerability in the Lobster extension's Windows shell fallback mechanism that allows attackers to inject arbitrary commands through tool-provided arguments. When spawn failures trigger | 0,5% | — |
| CVE-2025-24853 | HIGH 7.5 | apache jspwiki A carefully crafted request when creating a header link using the wiki markup syntax, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Further research by the JSPWiki team s | 0,5% | — |
| CVE-2022-20632 | MED 6.1 | cisco enterprise_chat_and_email A vulnerability in the web-based management interface of Cisco ECE could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface of an affected device. The vulnerability exists because the web-based management i | 0,5% | — |
| CVE-2024-45112 | HIGH 7.8 | adobe acrobat Acrobat Reader versions 24.002.21005, 24.001.30159, 20.005.30655, 24.003.20054 and earlier are affected by a Type Confusion vulnerability that could result in arbitrary code execution in the context of the current user. This issue occurs when a resource is acc | 0,5% | — |
| CVE-2023-28597 | HIGH 8.3 | zoom rooms Zoom clients prior to 5.13.5 contain an improper trust boundary implementation vulnerability. If a victim saves a local recording to an SMB location and later opens it using a link from Zoom’s web portal, an attacker positioned on an adjacent network to the vi | 0,5% | — |
| CVE-2023-20062 | MED 6.5 | cisco packaged_contact_center_enterprise Multiple vulnerabilities in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to collect sensitive information or perform a server-side request forgery (SSRF) attack on an affected system. Cisco plans to release software updates t | 0,5% | — |
| CVE-2022-20820 | MED 5.4 | cisco webex_meetings Multiple vulnerabilities in the web interface of Cisco Webex Meetings could allow a remote attacker to conduct a cross-site scripting (XSS) attack or a frame hijacking attack against a user of the web interface. For more information about these vulnerabilities | 0,5% | — |
| CVE-2021-44167 | MED 6.8 | fortinet forticlient An incorrect permission assignment for critical resource vulnerability [CWE-732] in FortiClient for Linux version 6.0.8 and below, 6.2.9 and below, 6.4.7 and below, 7.0.2 and below may allow an unauthenticated attacker to access sensitive information in log fi | 0,5% | — |
| CVE-2021-36927 | HIGH 7.8 | microsoft windows_7 Windows Digital TV Tuner device registration application Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2021-34461 | HIGH 7.8 | microsoft windows_10 Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2021-34459 | HIGH 7.8 | microsoft windows_10 Windows AppContainer Elevation Of Privilege Vulnerability | 0,5% | — |
| CVE-2021-34455 | HIGH 7.8 | microsoft windows_10 Windows File History Service Elevation of Privilege Vulnerability | 0,5% | — |