58.507 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.507 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2022-21882 | HIGH 7.0 | ransomware microsoft windows_10_1809 Win32k Elevation of Privilege Vulnerability | 59,2% | |
| CVE-2025-24054 | MED 6.5 | microsoft windows_10_1507 External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. | 58,9% | |
| CVE-2010-2572 | HIGH 7.8 | microsoft powerpoint Buffer overflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint 95 document, aka "PowerPoint Parsing Buffer Overflow Vulnerability." | 58,6% | |
| CVE-2019-1068 | HIGH 8.8 | microsoft sql_server A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'. | 57,9% | |
| CVE-2016-7262 | HIGH 7.8 | microsoft excel Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Viewer allow user-assisted remote attackers to execute arbitrary commands via a crafted cell that is mishandled upon a click, aka | 57,7% | |
| CVE-2023-6549 | HIGH 8.2 | citrix netscaler_application_delivery_controller Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and Out-Of-Bounds Memory Read | 57,6% | |
| CVE-2016-7193 | HIGH 7.8 | microsoft office Microsoft Word 2007 SP2, Office 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Services on SharePoi | 57,6% | |
| CVE-2017-0101 | HIGH 7.8 | ransomware microsoft windows_7 The kernel-mode drivers in Transaction Manager in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allow local use | 57,5% | |
| CVE-2015-1701 | HIGH 7.8 | ransomware microsoft windows_2003_server Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in April 2015, aka "Win32k Elevation of Privilege Vulnerability | 55,9% | |
| CVE-2025-58034 | HIGH 7.2 | fortinet fortiweb An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2 | 55,6% | |
| CVE-2018-0125 | CRIT 9.8 | cisco rv132w_firmware A vulnerability in the web interface of the Cisco RV132W ADSL2+ Wireless-N VPN and RV134W VDSL2 Wireless-AC VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code and gain full control of an affected system, including issuing com | 55,2% | |
| CVE-2026-2441 | HIGH 8.8 | google chrome Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | 55,1% | |
| CVE-2006-1547 | HIGH 7.5 | apache struts ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a multipart/form-data encoded form with a parameter name that references the public getMultipartRequestHandler method | 54,6% | |
| CVE-2014-4077 | HIGH 7.8 | microsoft office_2007_ime Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Office 2007 SP3, when IMJPDCT.EXE (aka IME for Japanese) is installed, allow remote attackers to bypass a sandbox protection mechanism via a crafted PD | 54,6% | |
| CVE-2024-38812 | CRIT 9.8 | vmware cloud_foundation The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to | 54,6% | |
| CVE-2016-0984 | HIGH 8.8 | adobe air_desktop_runtime Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20. | 54,5% | |
| CVE-2024-43461 | HIGH 8.8 | microsoft windows_10_1507 Windows MSHTML Platform Spoofing Vulnerability | 54,5% | |
| CVE-2020-1054 | HIGH 7.0 | microsoft windows_10_1507 An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then | 54,2% | |
| CVE-2023-20118 | MED 6.5 | cisco rv016_firmware A vulnerability in the web-based management interface of Cisco Small Business Routers RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. This vulnerability | 54,1% | |
| CVE-2021-31196 | HIGH 7.2 | microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 54,1% | |
| CVE-2022-21971 | HIGH 7.8 | microsoft windows_10_1809 Windows Runtime Remote Code Execution Vulnerability | 53,9% | |
| CVE-2021-22941 | CRIT 9.8 | ransomware citrix sharefile_storagezones_controller Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compromise the storage zones controller. | 53,6% | |
| CVE-2019-0541 | HIGH 8.8 | microsoft excel_viewer A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Office Word Viewer, Internet Explorer 9, Internet Explo | 53,2% | |
| CVE-2015-2419 | HIGH 8.8 | microsoft internet_explorer JScript 9 in Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "JScript9 Memory Corruption Vulnerability." | 53,1% | |
| CVE-2015-1642 | HIGH 7.8 | microsoft office Microsoft Office 2007 SP3, 2010 SP2, and 2013 SP1 allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability." | 53,1% |