58.306 CVE seguite
790 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.306 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2018-20169 | MED 6.8 | canonical ubuntu_linux An issue was discovered in the Linux kernel before 4.19.9. The USB subsystem mishandles size checks during the reading of an extra descriptor, related to __usb_get_extra_descriptor in drivers/usb/core/usb.c. | 0,6% | — |
| CVE-2016-3951 | MED 4.6 | canonical ubuntu_linux Double free vulnerability in drivers/net/usb/cdc_ncm.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (system crash) or possibly have unspecified other impact by inserting a USB device with an invalid USB desc | 0,6% | — |
| CVE-2016-3689 | MED 4.6 | canonical ubuntu_linux The ims_pcu_parse_cdc_data function in drivers/input/misc/ims-pcu.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (system crash) via a USB device without both a master and a slave interface. | 0,6% | — |
| CVE-2016-2187 | MED 4.6 | canonical ubuntu_linux The gtco_probe function in drivers/input/tablet/gtco.c in the Linux kernel through 4.5.2 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor. | 0,6% | — |
| CVE-2025-53843 | HIGH 7.5 | fortinet fortios A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions allows attacker to execute unauthorized code or commands via speciall | 0,6% | — |
| CVE-2025-30376 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0,6% | — |
| CVE-2025-30375 | HIGH 7.8 | microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0,6% | — |
| CVE-2025-29957 | MED 6.2 | microsoft windows_10_1507 Uncontrolled resource consumption in Windows Deployment Services allows an unauthorized attacker to deny service locally. | 0,6% | — |
| CVE-2024-21423 | MED 4.8 | microsoft edge_chromium Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | 0,6% | — |
| CVE-2022-35717 | HIGH 7.8 | ibm infosphere_information_server "IBM InfoSphere Information Server 11.7 could allow a locally authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-"Force ID: 231361. | 0,6% | — |
| CVE-2022-28883 | LOW 3.5 | f-secure atlant A Denial-of-Service (DoS) vulnerability was discovered in F-Secure & WithSecure products whereby the aerdl unpack function crashes. This can lead to a possible scanning engine crash. The exploit can be triggered remotely by an attacker. | 0,6% | — |
| CVE-2021-39011 | MED 4.2 | ibm cloud_pak_for_security IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.6.0 stores potentially sensitive information in log files that could be read by a privileged user. IBM X-Force ID: 213645. | 0,6% | — |
| CVE-2019-19051 | MED 5.5 | canonical ubuntu_linux A memory leak in the i2400m_op_rfkill_sw_toggle() function in drivers/net/wimax/i2400m/op-rfkill.c in the Linux kernel before 5.3.11 allows attackers to cause a denial of service (memory consumption), aka CID-6f3ef5c25cc7. | 0,6% | — |
| CVE-2026-63039 | CRIT 9.8 | apache inlong Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This allows an attacker to inject the string value into the SQL statement, enabling SQL injection. This issue affects Apache InLong: from 2.0 | 0,6% | — |
| CVE-2026-59242 | MED 5.4 | apache airflow Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal payload through `BaseXCom.deserialize_value` without the `_check_forbidden_xcom_keys` guard, allowing an authenticated API user with XCom write-and-re | 0,6% | — |
| CVE-2026-56160 | CRIT 9.1 | microsoft azure_red_hat_openshift Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network. | 0,6% | — |
| CVE-2026-41608 | HIGH 7.5 | apache thrift Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. | 0,6% | — |
| CVE-2026-32210 | CRIT 9.3 | microsoft dynamics_365 Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network. | 0,6% | — |
| CVE-2026-24015 | CRIT 9.8 | apache iotdb A vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.7, from 2.0.0 before 2.0.7. Users are recommended to upgrade to version 1.3.7 or 2.0.7, which fixes the issue. | 0,6% | — |
| CVE-2025-47173 | HIGH 7.8 | microsoft 365_apps Improper input validation in Microsoft Office allows an unauthorized attacker to execute code locally. | 0,6% | — |
| CVE-2025-26675 | HIGH 7.8 | microsoft windows_10_21h2 Out-of-bounds read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally. | 0,6% | — |
| CVE-2025-24044 | HIGH 7.8 | microsoft windows_10_1507 Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally. | 0,6% | — |
| CVE-2025-23331 | HIGH 7.5 | nvidia triton_inference_server NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where a user could cause a memory allocation with excessive size value, leading to a segmentation fault, by providing an invalid request. A successful exploit of this vulnerability m | 0,6% | — |
| CVE-2025-20256 | MED 6.5 | cisco secure_network_analytics A vulnerability in the web-based management interface of Cisco Secure Network Analytics Manager and Cisco Secure Network Analytics Virtual Manager could allow an authenticated, remote attacker with valid administrative credentials to execute arbitrary commands | 0,6% | — |
| CVE-2024-30347 | LOW 3.3 | foxit pdf_editor Foxit PDF Reader U3D File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this | 0,6% | — |