58.318 CVE seguite
790 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.318 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2025-49812 | HIGH 7.4 | apache http_server In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows a man-in-the-middle attacker to hijack an HTTP session via a TLS upgrade. Only configurations using "SSLEngine optional" to enable TLS upg | 0,6% | — |
| CVE-2024-6222 | HIGH 7.0 | docker desktop In Docker Desktop before v4.29.0, an attacker who has gained access to the Docker Desktop VM through a container breakout can further escape to the host by passing extensions and dashboard related IPC messages. Docker Desktop v4.29.0 https://docs.docker.com/ | 0,6% | — |
| CVE-2023-52885 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Fix UAF in svc_tcp_listen_data_ready() After the listener svc_sock is freed, and before invoking svc_tcp_accept() for the established child sock, there is a window that the newsock r | 0,6% | — |
| CVE-2023-3864 | HIGH 7.2 | snowsoftware snow_license_manager Blind SQL injection in a service running in Snow Software license manager from version 8.0.0 up to and including 9.30.1 on Windows allows a logged in user with high privileges to inject SQL commands via the web portal. | 0,6% | — |
| CVE-2023-29333 | LOW 3.3 | microsoft 365_apps Microsoft Access Denial of Service Vulnerability | 0,6% | — |
| CVE-2023-26078 | HIGH 7.8 | atera atera Privilege escalation vulnerability was discovered in Atera Agent 1.8.4.4 and prior on Windows due to mishandling of privileged APIs. | 0,6% | — |
| CVE-2023-24594 | MED 5.3 | f5 big-ip_access_policy_manager When an SSL profile is configured on a Virtual Server, undisclosed traffic can cause an increase in CPU or SSL accelerator resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0,6% | — |
| CVE-2022-38436 | HIGH 7.8 | adobe illustrator Adobe Illustrator versions 26.4 (and earlier) and 25.4.7 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this | 0,6% | — |
| CVE-2022-36077 | HIGH 7.2 | electronjs electron The Electron framework enables writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions prior to 21.0.0-beta.1, 20.0.1, 19.0.11, and 18.3.7, Electron is vulnerable to Exposure of Sensitive Information. When following a redirect, | 0,6% | — |
| CVE-2022-35820 | HIGH 7.8 | microsoft windows_10 Windows Bluetooth Driver Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2021-43240 | HIGH 7.8 | microsoft windows_10 NTFS Set Short Name Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2021-43230 | HIGH 7.8 | microsoft windows_10 Windows NTFS Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2021-34456 | HIGH 7.8 | microsoft windows_10 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2021-20446 | MED 5.4 | ibm maximo_for_civil_infrastructure IBM Maximo for Civil Infrastructure 7.6.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a tr | 0,6% | — |
| CVE-2020-5904 | HIGH 8.8 | f5 big-ip_access_policy_manager In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, a cross-site request forgery (CSRF) vulnerability in the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, exists in an undisclosed pa | 0,6% | — |
| CVE-2020-4933 | MED 5.4 | ibm jazz_reporting_service IBM Jazz Reporting Service 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclo | 0,6% | — |
| CVE-2020-3266 | HIGH 7.8 | cisco sd-wan_firmware A vulnerability in the CLI of Cisco SD-WAN Solution software could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due to insufficient input validation. An attacker could exploit | 0,6% | — |
| CVE-2016-2847 | MED 6.2 | linux linux_kernel fs/pipe.c in the Linux kernel before 4.5 does not limit the amount of unread data in pipes, which allows local users to cause a denial of service (memory consumption) by creating many pipes with non-default sizes. | 0,6% | — |
| CVE-2016-2143 | HIGH 7.8 | debian debian_linux The fork implementation in the Linux kernel before 4.5 on s390 platforms mishandles the case of four page-table levels, which allows local users to cause a denial of service (system crash) or possibly have unspecified other impact via a crafted application, re | 0,6% | — |
| CVE-2014-9585 | LOW 2.1 | canonical ubuntu_linux The vdso_addr function in arch/x86/vdso/vma.c in the Linux kernel through 3.18.2 does not properly choose memory locations for the vDSO area, which makes it easier for local users to bypass the ASLR protection mechanism by guessing a location at the end of a P | 0,6% | — |
| CVE-2004-0109 | MED 4.6 | linux linux_kernel Buffer overflow in the ISO9660 file system component for Linux kernel 2.4.x, 2.5.x and 2.6.x, allows local users with physical access to overflow kernel memory and execute arbitrary code via a malformed CD containing a long symbolic link entry. | 0,6% | — |
| CVE-2026-13474 | HIGH 7.5 | citrix netscaler_application_delivery_controller Denial of service via malformed HTTP/2 requests in NetScaler ADC and NetScaler Gateway if HTTP/2 is enabled in HTTP Profile and associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler | 0,6% | — |
| CVE-2025-38035 | HIGH 7.5 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: don't restore null sk_state_change queue->state_change is set as part of nvmet_tcp_set_queue_sock(), but if the TCP connection isn't established when nvmet_tcp_set_queue_sock() is | 0,6% | — |
| CVE-2025-30330 | HIGH 7.8 | adobe illustrator Illustrator versions 29.3, 28.7.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim mus | 0,6% | — |
| CVE-2025-29955 | MED 6.2 | microsoft windows_11_24h2 Improper input validation in Windows Hyper-V allows an unauthorized attacker to deny service locally. | 0,6% | — |