EN
58.306 CVE seguite
790 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.306 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più alto In KEV dal, ordina dal più alto
CVE-2006-2935 MED 4.6 canonical ubuntu_linux The dvd_read_bca function in the DVD handling code in drivers/cdrom/cdrom.c in Linux kernel 2.2.16, and later versions, assigns the wrong value to a length variable, which allows local users to execute arbitrary code via a crafted USB Storage device that trigg 0,6% —
CVE-2026-72980 MED 4.4 microsoft windows_10_1607 Uncontrolled search path element in Windows Hello allows an authorized attacker to bypass a security feature locally. 0,6% —
CVE-2026-66422 HIGH 8.1 apache tomcat Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being incorrectly used as role aliases within the Realm in additional to the correct usage with Request.isUserInRole(). This issue affects Apache Tomcat: from 11.0. 0,6% —
CVE-2026-62750 MED 6.5 microsoft windows_10_1607 Partial string comparison in Windows HTTP Protocol Stack allows an unauthorized attacker to perform tampering over an adjacent network. 0,6% —
CVE-2026-56139 MED 5.3 apache camel Generation of Error Message Containing Sensitive Information vulnerability in Apache Camel Undertow Component. The camel-undertow HTTP server consumer exposes a muteException option that controls what is returned to the client when a route processing error oc 0,6% —
CVE-2026-55035 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. 0,6% —
CVE-2026-49365 MED 5.3 apache camel Generation of Error Message Containing Sensitive Information vulnerability in Apache Camel Netty HTTP component. The camel-netty-http HTTP server consumer exposes a muteException option that controls what is returned to the client when a route processing erro 0,6% —
CVE-2026-48207 CRIT 9.8 apache fory Deserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass documented DeserializationPolicy validation hooks during reduce-state restoration and global-name resolution. An application is vulnerable if it deserializes attack 0,6% —
CVE-2026-46133 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Reject unknown opcodes before ICRC processing Even after applying commit 7244491dab34 ("RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv"), a single unauthenticated 0,6% —
CVE-2026-31378 MED 6.5 apache ofbiz Improper Input Validation vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue. 0,6% —
CVE-2025-55673 MED 4.3 apache superset When a guest user accesses a chart in Apache Superset, the API response from the /chart/data endpoint includes a query field in its payload. This field contains the underlying query, which improperly discloses database schema information, such as table names, 0,6% —
CVE-2025-26679 HIGH 7.8 microsoft windows_10_1507 Use after free in RPC Endpoint Mapper Service allows an authorized attacker to elevate privileges locally. 0,6% —
CVE-2025-10200 HIGH 8.8 google chrome Use after free in Serviceworker in Google Chrome on Desktop prior to 140.0.7339.127 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) 0,6% —
CVE-2024-35854 HIGH 7.8 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_acl_tcam: Fix possible use-after-free during rehash The rehash delayed work migrates filters from one region to another according to the number of available credits. The mig 0,6% —
CVE-2023-44152 CRIT 9.1 acronis cyber_protect Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 35979. 0,6% —
CVE-2023-28249 MED 6.2 microsoft windows_10_1507 Windows Boot Manager Security Feature Bypass Vulnerability 0,6% —
CVE-2022-3619 LOW 3.5 linux linux_kernel A vulnerability has been found in Linux Kernel and classified as problematic. This vulnerability affects the function l2cap_recv_acldata of the file net/bluetooth/l2cap_core.c of the component Bluetooth. The manipulation leads to memory leak. It is recommended 0,6% —
CVE-2021-22041 MED 6.7 vmware cloud_foundation VMware ESXi, Workstation, and Fusion contain a double-fetch vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process runnin 0,6% —
CVE-2020-13884 HIGH 7.8 citrix workspace_app Citrix Workspace App before 1912 on Windows has Insecure Permissions and an Unquoted Path vulnerability which allows local users to gain privileges during the uninstallation of the application. 0,6% —
CVE-2017-0451 MED 4.7 google android An information disclosure vulnerability in the Qualcomm sound driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Produc 0,6% —
CVE-2016-1424 MED 6.5 cisco ios Cisco IOS 15.2(1)T1.11 and 15.2(2)TST allows remote attackers to cause a denial of service (device crash) via a crafted LLDP packet, aka Bug ID CSCun63132. 0,6% —
CVE-2026-76986 MED 6.1 apache wicket Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicket.markup.html.form.AbstractSingleSelectChoice, the base class of DropDownChoice, writes the body of the default option — the entry shown when no choice is selected — 0,6% —
CVE-2026-59762 HIGH 7.5 f5 big-ip_next_cloud-native_network_functions When an HTTP/2 profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization.   Impact: System performance can degrade until the TMM process is either forced to restart or is manually restarted. T 0,6% —
CVE-2026-24178 CRIT 9.8 nvidia nvflare NVIDIA NVFlare Dashboard contains a vulnerability in the user management and authentication system where an unauthenticated attacker may cause authorization bypass through user-controlled key. A successful exploit of this vulnerability may lead to privilege es 0,6% —
CVE-2026-20301 HIGH 8.6 cisco ios A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition o 0,6% —