57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.971 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2023-4576 | HIGH 8.6 | mozilla firefox On Windows, an integer overflow could occur in `RecordedSourceSurfaceCreation` which resulted in a heap buffer overflow potentially leaking sensitive data that could have led to a sandbox escape. *This bug only affects Firefox on Windows. Other operating syste | 0,8% | — |
| CVE-2013-2268 | HIGH 7.5 | google chrome Unspecified vulnerability in the MathML implementation in WebKit in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, has unknown impact and remote attack vectors, related to a "high severity security issue." | 0,8% | — |
| CVE-2026-70586 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Paint allows an unauthorized attacker to execute code over a network. | 0,8% | — |
| CVE-2026-69860 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network. | 0,8% | — |
| CVE-2026-61483 | HIGH 7.5 | apache lucy ** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alt | 0,8% | — |
| CVE-2025-47997 | MED 6.5 | microsoft sql_server_2016 Concurrent execution using shared resource with improper synchronization ('race condition') in SQL Server allows an authorized attacker to disclose information over a network. | 0,8% | — |
| CVE-2025-29822 | HIGH 7.8 | microsoft office Incomplete list of disallowed inputs in Microsoft Office OneNote allows an unauthorized attacker to bypass a security feature locally. | 0,8% | — |
| CVE-2022-49561 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: re-fetch conntrack after insertion In case the conntrack is clashing, insertion can free skb->_nfct and set skb->_nfct to the already-confirmed entry. This wasn't foun | 0,8% | — |
| CVE-2022-41079 | HIGH 8.0 | microsoft exchange_server Microsoft Exchange Server Spoofing Vulnerability | 0,8% | — |
| CVE-2022-41078 | HIGH 8.0 | microsoft exchange_server Microsoft Exchange Server Spoofing Vulnerability | 0,8% | — |
| CVE-2022-26914 | HIGH 7.8 | microsoft windows_10 Win32k Elevation of Privilege Vulnerability | 0,8% | — |
| CVE-2022-26116 | HIGH 7.2 | fortinet fortinac Multiple improper neutralization of special elements used in SQL commands ('SQL Injection') vulnerability [CWE-89] in FortiNAC version 8.3.7 and below, 8.5.2 and below, 8.5.4, 8.6.0, 8.6.5 and below, 8.7.6 and below, 8.8.11 and below, 9.1.5 and below, 9.2.2 an | 0,8% | — |
| CVE-2022-24546 | HIGH 7.8 | microsoft windows_10 Windows DWM Core Library Elevation of Privilege Vulnerability | 0,8% | — |
| CVE-2022-23014 | MED 6.5 | f5 big-ip_access_policy_manager On versions 16.1.x before 16.1.2 and 15.1.x before 15.1.4.1, when BIG-IP APM portal access is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End o | 0,8% | — |
| CVE-2021-1731 | MED 5.5 | microsoft windows_10 PFX Encryption Security Feature Bypass Vulnerability | 0,8% | — |
| CVE-2021-1661 | HIGH 7.8 | microsoft windows_10 Windows Installer Elevation of Privilege Vulnerability | 0,8% | — |
| CVE-2020-0733 | HIGH 7.8 | microsoft windows_malicious_software_removal_tool An elevation of privilege vulnerability exists when the Windows Malicious Software Removal Tool (MSRT) improperly handles junctions.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Malicious Softw | 0,8% | — |
| CVE-2017-6601 | HIGH 7.1 | cisco firepower_extensible_operating_system A vulnerability in the CLI of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to perform a command injection | 0,8% | — |
| CVE-2013-1860 | MED 6.9 | canonical ubuntu_linux Heap-based buffer overflow in the wdm_in_callback function in drivers/usb/class/cdc-wdm.c in the Linux kernel before 3.8.4 allows physically proximate attackers to cause a denial of service (system crash) or possibly execute arbitrary code via a crafted cdc-wd | 0,8% | — |
| CVE-2007-4573 | HIGH 7.2 | linux linux_kernel The IA32 system call emulation functionality in Linux kernel 2.4.x and 2.6.x before 2.6.22.7, when running on the x86_64 architecture, does not zero extend the eax register after the 32bit entry path to ptrace is used, which might allow local users to gain pri | 0,8% | — |
| CVE-2026-78524 | HIGH 8.8 | microsoft 365_apps Out-of-bounds write in Microsoft Office allows an unauthorized attacker to execute code over a network. | 0,8% | — |
| CVE-2026-78512 | HIGH 8.8 | microsoft 365_apps Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | 0,8% | — |
| CVE-2026-78511 | HIGH 8.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | 0,8% | — |
| CVE-2026-72973 | HIGH 8.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | 0,8% | — |
| CVE-2026-72972 | HIGH 8.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | 0,8% | — |