58.306 CVE seguite
790 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.306 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2015-5652 | HIGH 7.2 | python python Untrusted search path vulnerability in python.exe in Python through 3.5.0 on Windows allows local users to gain privileges via a Trojan horse readline.pyd file in the current working directory. NOTE: the vendor says "It was determined that this is a longtime | 0,6% | — |
| CVE-2026-65942 | HIGH 7.5 | apache ranger TLS hostname verification issue in Apache Ranger Client Code in versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue. | 0,6% | — |
| CVE-2026-42987 | HIGH 8.1 | microsoft windows_server_2012 Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network. | 0,6% | — |
| CVE-2025-54656 | MED 6.5 | apache struts_extras ** UNSUPPORTED WHEN ASSIGNED ** Improper Output Neutralization for Logs vulnerability in Apache Struts. This issue affects Apache Struts Extras: before 2. When using LookupDispatchAction, in some cases, Struts may print untrusted input to the logs without an | 0,6% | — |
| CVE-2023-4335 | HIGH 7.5 | broadcom raid_controller_web_interface Broadcom RAID Controller Web server (nginx) is serving private server-side files without any authentication on Linux | 0,6% | — |
| CVE-2023-36729 | HIGH 7.8 | microsoft windows_10_1507 Named Pipe File System Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2023-20034 | HIGH 7.5 | cisco sd-wan Vulnerability in the Elasticsearch database used in the of Cisco SD-WAN vManage software could allow an unauthenticated, remote attacker to access the Elasticsearch configuration database of an affected device with the privileges of the elasticsearch user. | 0,6% | — |
| CVE-2022-38043 | MED 5.5 | microsoft windows_10 Windows Security Support Provider Interface Information Disclosure Vulnerability | 0,6% | — |
| CVE-2022-38026 | MED 5.5 | microsoft windows_10 Windows DHCP Client Information Disclosure Vulnerability | 0,6% | — |
| CVE-2022-38025 | MED 5.5 | microsoft windows_11 Windows Distributed File System (DFS) Information Disclosure Vulnerability | 0,6% | — |
| CVE-2022-37996 | MED 5.5 | microsoft windows_10 Windows Kernel Memory Information Disclosure Vulnerability | 0,6% | — |
| CVE-2021-33762 | HIGH 7.0 | microsoft azure_cyclecloud Azure CycleCloud Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2020-25670 | HIGH 7.8 | debian debian_linux A vulnerability was found in Linux Kernel where refcount leak in llcp_sock_bind() causing use-after-free which might lead to privilege escalations. | 0,6% | — |
| CVE-2020-17163 | HIGH 7.8 | microsoft python Visual Studio Code Python Extension Remote Code Execution Vulnerability | 0,6% | — |
| CVE-2019-15239 | HIGH 7.8 | debian debian_linux In the Linux kernel, a certain net/ipv4/tcp_output.c change, which was properly incorporated into 4.16.12, was incorrectly backported to the earlier longterm kernels, introducing a new vulnerability that was potentially more severe than the issue that was inte | 0,6% | — |
| CVE-2019-13648 | MED 5.5 | linux linux_kernel In the Linux kernel through 5.2.1 on the powerpc platform, when hardware transactional memory is disabled, a local user can cause a denial of service (TM Bad Thing exception and system crash) via a sigreturn() system call that sends a crafted signal frame. Thi | 0,6% | — |
| CVE-2015-4036 | HIGH 7.2 | linux linux_kernel Array index error in the tcm_vhost_make_tpg function in drivers/vhost/scsi.c in the Linux kernel before 4.0 might allow guest OS users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted VHOST_SCSI_SET_ENDPO | 0,6% | — |
| CVE-2014-8371 | MED 4.3 | vmware vcenter_server_appliance VMware vCenter Server Appliance (vCSA) 5.5 before Update 2, 5.1 before Update 3, and 5.0 before Update 3c does not properly validate certificates when connecting to a CIM Server on an ESXi host, which allows man-in-the-middle attackers to spoof CIM servers via | 0,6% | — |
| CVE-2014-7826 | HIGH 7.8 | linux linux_kernel kernel/trace/trace_syscalls.c in the Linux kernel through 3.17.2 does not properly handle private syscall numbers during use of the ftrace subsystem, which allows local users to gain privileges or cause a denial of service (invalid pointer dereference) via a c | 0,6% | — |
| CVE-2013-4470 | MED 6.9 | linux linux_kernel The Linux kernel before 3.12, when UDP Fragmentation Offload (UFO) is enabled, does not properly initialize certain data structures, which allows local users to cause a denial of service (memory corruption and system crash) or possibly gain privileges via a cr | 0,6% | — |
| CVE-2009-1961 | MED 4.7 | canonical ubuntu_linux The inode double locking code in fs/ocfs2/file.c in the Linux kernel 2.6.30 before 2.6.30-rc3, 2.6.27 before 2.6.27.24, 2.6.29 before 2.6.29.4, and possibly other versions down to 2.6.19 allows local users to cause a denial of service (prevention of file creat | 0,6% | — |
| CVE-2026-8646 | HIGH 7.4 | ibm websphere_application_server IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to HTTP request smuggling. A remote attacker could smuggle a specially crafted request to the application server thereby allowi | 0,6% | — |
| CVE-2026-70326 | HIGH 8.8 | microsoft sharepoint_server Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | 0,6% | — |
| CVE-2026-31379 | MED 6.1 | apache ofbiz Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This | 0,6% | — |
| CVE-2025-21345 | HIGH 7.8 | microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability | 0,6% | — |