58.507 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.507 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2019-1215 | HIGH 7.8 | ransomware microsoft windows_10_1507 An elevation of privilege vulnerability exists in the way that ws2ifsl.sys (Winsock) handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1253, CVE-2019-1278, CVE-2019-1303. | 19,3% | |
| CVE-2019-1322 | HIGH 7.8 | ransomware microsoft windows_10_1803 An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka 'Microsoft Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1320, CVE-2019-1340. | 19,2% | |
| CVE-2015-5123 | CRIT 9.8 | adobe flash_player Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through | 18,8% | |
| CVE-2016-7892 | HIGH 8.8 | adobe flash_player Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the TextField class. Successful exploitation could lead to arbitrary code execution. | 18,8% | |
| CVE-2022-22047 | HIGH 7.8 | microsoft windows_10_1507 Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability | 18,8% | |
| CVE-2024-7965 | HIGH 8.8 | google chrome Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 18,5% | |
| CVE-2022-22718 | HIGH 7.8 | microsoft windows_10_1507 Windows Print Spooler Elevation of Privilege Vulnerability | 18,5% | |
| CVE-2019-5591 | MED 6.5 | ransomware fortinet fortios A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the LDAP server. | 18,4% | |
| CVE-2018-8440 | HIGH 7.8 | ransomware microsoft windows_10_1607 An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC), aka "Windows ALPC Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Serve | 18,4% | |
| CVE-2018-0147 | CRIT 9.8 | cisco secure_access_control_system A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9 could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure dese | 18,2% | |
| CVE-2017-0022 | MED 6.5 | microsoft windows_8.1 Microsoft XML Core Services (MSXML) in Windows 10 Gold, 1511, and 1607; Windows 7 SP1; Windows 8.1; Windows RT 8.1; Windows Server 2008 SP2 and R2 SP1; Windows Server 2012 Gold and R2; Windows Server 2016; and Windows Vista SP2 improperly handles objects in me | 18,1% | |
| CVE-2026-22719 | HIGH 8.1 | vmware aria_operations VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration | 17,7% | |
| CVE-2026-55040 | CRIT 9.1 | microsoft sharepoint_server Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network. | 17,5% | |
| CVE-2024-38813 | HIGH 7.5 | vmware cloud_foundation The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to root by sending a specially crafted network packet. | 17,4% | |
| CVE-2020-4006 | CRIT 9.1 | vmware cloud_foundation VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability. | 17,3% | |
| CVE-2022-26904 | HIGH 7.0 | microsoft windows_10_1507 Windows User Profile Service Elevation of Privilege Vulnerability | 16,9% | |
| CVE-2023-36036 | HIGH 7.8 | microsoft windows_10_1507 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | 16,7% | |
| CVE-2021-20022 | HIGH 7.2 | ransomware sonicwall email_security SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host. | 16,5% | |
| CVE-2023-6345 | CRIT 9.6 | debian debian_linux Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High) | 16,5% | |
| CVE-2020-0986 | HIGH 7.8 | microsoft windows_10_1507 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1237, CVE-2020-1246, CVE-2020-1262, CVE-2020-1264, | 16,3% | |
| CVE-2026-58644 | CRIT 9.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | 15,9% | |
| CVE-2024-20481 | MED 5.8 | cisco adaptive_security_appliance_software A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of the RAVPN servi | 15,8% | |
| CVE-2026-21513 | HIGH 8.8 | microsoft windows_10_1607 Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network. | 15,6% | |
| CVE-2023-35311 | HIGH 8.8 | microsoft 365_apps Microsoft Outlook Security Feature Bypass Vulnerability | 15,5% | |
| CVE-2026-34197 | HIGH 8.8 | apache activemq Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia | 15,5% |