EN
56.569 CVE seguite
773 Sfruttate ora
181 Usate dai ransomware
Ultima sincronia

CVE Tracker

56.569 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordinato dal più basso
CVE-2024-50302 MED 5.5 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since the report buffer is used by all kinds of drivers in various ways, let's zero-initialize it during allocation to make sure that it can't be 0,8%
CVE-2025-26633 HIGH 7.0 ransomware microsoft windows_10_1507 Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally. 30,4%
CVE-2025-24993 HIGH 7.8 microsoft windows_10_1507 Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. 2,2%
CVE-2025-24991 MED 5.5 microsoft windows_10_1507 Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. 2,0%
CVE-2025-24985 HIGH 7.8 microsoft windows_10_1507 Integer overflow or wraparound in Windows Fast FAT Driver allows an unauthorized attacker to execute code locally. 3,8%
CVE-2025-24984 MED 4.6 microsoft windows_10_1507 Insertion of sensitive information into log file in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack. 2,0%
CVE-2025-24983 HIGH 7.0 microsoft windows_10_1507 Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally. 1,3%
CVE-2025-21590 MED 4.4 juniper junos An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to compromise the integrity of the device. A local attacker with access to the shell is able to inject arbitrar 1,7%
CVE-2025-24472 HIGH 8.1 ransomware fortinet fortios An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior knowledge of upstream an 3,6%
CVE-2025-2783 HIGH 8.3 google chrome Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker to perform a sandbox escape via a malicious file. (Chromium security severity: High) 8,4%
CVE-2024-20439 CRIT 9.8 cisco smart_license_utility A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by using a static administrative credential. This vulnerability is due to an undocumented static user credential for an ad 92,1%
CVE-2025-24813 CRIT 9.8 apache tomcat Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 t 99,9%
CVE-2025-29824 HIGH 7.8 ransomware microsoft windows_10_1507 Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. 13,8%
CVE-2024-53197 HIGH 7.8 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices A bogus device can provide a bNumConfigurations value that exceeds the initial value used in usb_get_configur 3,6%
CVE-2024-53150 HIGH 7.1 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix out of bounds reads when finding clock sources The current USB-audio driver code doesn't check bLength of each descriptor at traversing for clock descriptors. That is, 1,4%
CVE-2025-24054 MED 6.5 microsoft windows_10_1507 External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. 58,9%
CVE-2025-3928 HIGH 8.8 commvault commvault Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory: "Webservers can be compromised through bad actors creating and executing webshells." Fixed in version 11.36.46 2,1%
CVE-2024-38475 CRIT 9.1 apache http_server Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code 100,0%
CVE-2025-34028 CRIT 10.0 commvault commvault The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expanded by the target server, are vulnerable to path traversal vulnerability that can result in Remote Code Executio 97,7%
CVE-2025-32709 HIGH 7.8 microsoft windows_10_1507 Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 1,8%
CVE-2025-32706 HIGH 7.8 microsoft windows_10_1507 Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. 2,2%
CVE-2025-32701 HIGH 7.8 microsoft windows_10_1507 Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. 1,4%
CVE-2025-30400 HIGH 7.8 microsoft windows_10_1809 Use after free in Windows DWM allows an authorized attacker to elevate privileges locally. 1,9%
CVE-2025-30397 HIGH 7.5 microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network. 26,8%
CVE-2025-32756 CRIT 9.8 fortinet forticamera_firmware A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7 29,8%