57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.971 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2016-8408 | MED 4.7 | linux linux_kernel An information disclosure vulnerability in the NVIDIA video driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: | 0,9% | — |
| CVE-2014-5207 | MED 6.2 | canonical ubuntu_linux fs/namespace.c in the Linux kernel through 3.16.1 does not properly restrict clearing MNT_NODEV, MNT_NOSUID, and MNT_NOEXEC and changing MNT_ATIME_MASK during a remount of a bind mount, which allows local users to gain privileges, interfere with backups and au | 0,9% | — |
| CVE-2007-2878 | MED 4.9 | linux linux_kernel The VFAT compat ioctls in the Linux kernel before 2.6.21.2, when run on a 64-bit system, allow local users to corrupt a kernel_dirent struct and cause a denial of service (system crash) via unknown vectors. | 0,9% | — |
| CVE-2026-76432 | MED 4.9 | A vulnerability in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker with administrative-level privileges to write arbitrary files on an affected device. This vulnerability exists because the aff | 0,9% | — |
| CVE-2025-21202 | MED 6.1 | microsoft windows_10_1507 Windows Recovery Environment Agent Elevation of Privilege Vulnerability | 0,9% | — |
| CVE-2024-43479 | HIGH 8.5 | microsoft power_automate Microsoft Power Automate Desktop Remote Code Execution Vulnerability | 0,9% | — |
| CVE-2021-0266 | HIGH 8.1 | juniper junos The use of multiple hard-coded cryptographic keys in cSRX Series software in Juniper Networks Junos OS allows an attacker to take control of any instance of a cSRX deployment through device management services. This issue affects: Juniper Networks Junos OS on | 0,9% | — |
| CVE-2020-16942 | MED 4.1 | microsoft sharepoint_enterprise_server <p>An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web pages. An attacker who took advantage of this information disclosure could view the folder path of scripts | 0,9% | — |
| CVE-2016-10293 | MED 4.7 | linux linux_kernel An information disclosure vulnerability in the Qualcomm video driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Produc | 0,9% | — |
| CVE-2013-0887 | HIGH 7.5 | google chrome The developer-tools process in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly restrict privileges during interaction with a connected server, which has unspecified impact and attack vectors. | 0,9% | — |
| CVE-2024-38152 | HIGH 7.8 | microsoft windows_10_1507 Windows OLE Remote Code Execution Vulnerability | 0,9% | — |
| CVE-2023-37935 | MED 6.5 | fortinet fortios A use of GET request method with sensitive query strings vulnerability in Fortinet FortiOS 7.0.0 - 7.0.12, 7.2.0 - 7.2.5 and 7.4.0 allows an attacker to view plaintext passwords of remote services such as RDP or VNC, if the attacker is able to read the GET req | 0,9% | — |
| CVE-2023-3312 | HIGH 7.5 | linux linux_kernel A vulnerability was found in drivers/cpufreq/qcom-cpufreq-hw.c in cpufreq subsystem in the Linux Kernel. This flaw, during device unbind will lead to double release problem leading to denial of service. | 0,9% | — |
| CVE-2022-31689 | CRIT 9.8 | vmware workspace_one_assist VMware Workspace ONE Assist prior to 22.10 contains a Session fixation vulnerability. A malicious actor who obtains a valid session token may be able to authenticate to the application using that token. | 0,9% | — |
| CVE-2022-31687 | CRIT 9.8 | vmware workspace_one_assist VMware Workspace ONE Assist prior to 22.10 contains a Broken Access Control vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application. | 0,9% | — |
| CVE-2022-24527 | HIGH 7.8 | microsoft endpoint_configuration_manager Microsoft Endpoint Configuration Manager Elevation of Privilege Vulnerability | 0,9% | — |
| CVE-2022-20925 | MED 6.3 | cisco secure_firewall_management_center A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. The vulnerability is due to insufficient | 0,9% | — |
| CVE-2021-39017 | MED 6.5 | ibm engineering_lifecycle_optimization_-_publishing IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to upload arbitrary files, caused by improper access controls. IBM X-Force ID: 213725. | 0,9% | — |
| CVE-2020-17088 | HIGH 7.8 | microsoft windows_10 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 0,9% | — |
| CVE-2020-11582 | HIGH 8.8 | pulsesecure pulse_connect_secure An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris clients when a Host Checker policy is enforced, launches a TCP server that accepts local connections on a rando | 0,9% | — |
| CVE-2015-1305 | MED 6.9 | mcafee data_loss_prevention_endpoint McAfee Data Loss Prevention Endpoint (DLPe) before 9.3.400 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a crafted (1) 0x00224014 or (2) 0x0022c018 IOCTL call. | 0,9% | — |
| CVE-2026-24252 | HIGH 7.8 | nvidia nemo NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection. A successful exploit of this vulnerability may lead to code execution, data tampering, escalation of privileges and information disclosure. | 0,9% | — |
| CVE-2026-21257 | HIGH 8.0 | microsoft visual_studio_2022 Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an authorized attacker to elevate privileges over a network. | 0,9% | — |
| CVE-2025-27018 | MED 6.3 | apache apache-airflow-providers-mysql Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow MySQL Provider. When user triggered a DAG with dump_sql or load_sql functions they could pass a table parameter from a UI, that could cause SQ | 0,9% | — |
| CVE-2024-37978 | HIGH 8.0 | microsoft windows_11_22h2 Secure Boot Security Feature Bypass Vulnerability | 0,9% | — |