58.306 CVE seguite
790 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.306 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2022-37979 | HIGH 7.8 | microsoft windows_10 Windows Hyper-V Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2014-4700 | MED 4.9 | citrix xendesktop Citrix XenDesktop 7.x, 5.x, and 4.x, when pooled random desktop groups is enabled and ShutdownDesktopsAfterUse is disabled, allows local guest users to gain access to another user's desktop via unspecified vectors. | 0,6% | — |
| CVE-2012-5459 | HIGH 7.9 | vmware player Untrusted search path vulnerability in VMware Workstation 8.x before 8.0.5 and VMware Player 4.x before 4.0.5 on Windows allows host OS users to gain host OS privileges via a Trojan horse DLL in a "system folder." | 0,6% | — |
| CVE-2026-40361 | HIGH 8.4 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 0,6% | — |
| CVE-2025-21281 | HIGH 7.8 | microsoft windows_10_1507 Microsoft COM for Windows Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2024-33863 | CRIT 9.8 | linqi linqi An issue was discovered in linqi before 1.4.0.1 on Windows. There is /api/Cdn/GetFile local file inclusion. | 0,6% | — |
| CVE-2024-26936 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate request buffer size in smb2_allocate_rsp_buf() The response buffer should be allocated in smb2_allocate_rsp_buf before validating request. But the fields in payload as well a | 0,6% | — |
| CVE-2023-23395 | LOW 3.1 | microsoft sharepoint_foundation Microsoft SharePoint Server Spoofing Vulnerability | 0,6% | — |
| CVE-2021-27072 | HIGH 7.0 | microsoft windows_10 Win32k Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2019-1846 | HIGH 7.4 | cisco ios_xr A vulnerability in the Multiprotocol Label Switching (MPLS) Operations, Administration, and Maintenance (OAM) implementation of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, adjacent attacker to tr | 0,6% | — |
| CVE-2019-1749 | HIGH 7.4 | cisco ios_xe A vulnerability in the ingress traffic validation of Cisco IOS XE Software for Cisco Aggregation Services Router (ASR) 900 Route Switch Processor 3 (RSP3) could allow an unauthenticated, adjacent attacker to trigger a reload of an affected device, resulting in | 0,6% | — |
| CVE-2018-11760 | MED 5.5 | apache spark When using PySpark , it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark application. This affects versions 1.x, 2.0.x, 2.1.x, 2.2.0 to 2.2.2, and 2.3.0 to 2.3.1. | 0,6% | — |
| CVE-2017-2583 | HIGH 8.4 | linux linux_kernel The load_segment_descriptor implementation in arch/x86/kvm/emulate.c in the Linux kernel before 4.9.5 improperly emulates a "MOV SS, NULL selector" instruction, which allows guest OS users to cause a denial of service (guest OS crash) or gain guest OS privileg | 0,6% | — |
| CVE-2026-68823 | CRIT 9.1 | microsoft azure_confidential_ledger Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network. | 0,6% | — |
| CVE-2026-50525 | HIGH 7.5 | microsoft .net Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. | 0,6% | — |
| CVE-2025-59234 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 0,6% | — |
| CVE-2025-39688 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nfsd: allow SC_STATUS_FREEABLE when searching via nfs4_lookup_stateid() The pynfs DELEG8 test fails when run against nfsd. It acquires a delegation and then lets the lease time out. It then | 0,6% | — |
| CVE-2025-21403 | MED 6.4 | microsoft on-prem_data_gateway On-Premises Data Gateway Information Disclosure Vulnerability | 0,6% | — |
| CVE-2025-21304 | HIGH 7.8 | microsoft windows_10_1607 Microsoft DWM Core Library Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2024-43527 | HIGH 7.8 | microsoft windows_11_24h2 Windows Kernel Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2024-43514 | HIGH 7.8 | microsoft windows_10_1507 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2024-38253 | HIGH 7.8 | microsoft windows_11_21h2 Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2024-38252 | HIGH 7.8 | microsoft windows_10_1607 Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2023-20116 | MED 6.8 | cisco unified_communications_manager A vulnerability in the Administrative XML Web Service (AXL) API of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to cause a d | 0,6% | — |
| CVE-2022-26921 | HIGH 7.3 | microsoft visual_studio_code Visual Studio Code Elevation of Privilege Vulnerability | 0,6% | — |