58.426 CVE seguite
792 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.426 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2021-36966 | HIGH 7.8 | microsoft windows_10 Windows Subsystem for Linux Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2021-36964 | HIGH 7.8 | microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2021-36954 | HIGH 8.8 | microsoft windows_10 Windows Bind Filter Driver Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2020-5917 | MED 5.9 | f5 big-ip_access_policy_manager In BIG-IP versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.2 and BIG-IQ versions 5.2.0-7.0.0, the host OpenSSH servers utilize keys of less than 2048 bits which are no longer considered secure. | 0,5% | — |
| CVE-2020-5870 | HIGH 8.1 | f5 big-iq_centralized_management In BIG-IQ 5.2.0-7.0.0, high availability (HA) synchronization mechanisms do not use any form of authentication for connecting to the peer. | 0,5% | — |
| CVE-2019-4640 | CRIT 9.8 | ibm security_secret_server IBM Security Secret Server 10.7 processes patches, image backups and other updates without sufficiently verifying the origin and integrity of the code which could result in an attacker executing malicious code. IBM X-Force ID: 170046. | 0,5% | — |
| CVE-2018-10902 | HIGH 7.8 | canonical ubuntu_linux It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_input_params() and snd_rawmidi_output_status() which are part of snd_rawmidi_ioctl() handler in rawmidi.c file. | 0,5% | — |
| CVE-2017-8360 | MED 5.5 | conexant mictray64 Conexant Systems mictray64 task, as used on HP Elite, EliteBook, ProBook, and ZBook systems, leaks sensitive data (keystrokes) to any process. In mictray64.exe (mic tray icon) 1.0.0.46, a LowLevelKeyboardProc Windows hook is used to capture keystrokes. This da | 0,5% | — |
| CVE-2016-2543 | MED 6.2 | linux linux_kernel The snd_seq_ioctl_remove_events function in sound/core/seq/seq_clientmgr.c in the Linux kernel before 4.4.1 does not verify FIFO assignment before proceeding with FIFO clearing, which allows local users to cause a denial of service (NULL pointer dereference an | 0,5% | — |
| CVE-2001-0020 | LOW 2.1 | cisco arrowpoint Directory traversal vulnerability in Arrowpoint (aka Cisco Content Services, or CSS) allows local unprivileged users to read arbitrary files via a .. (dot dot) attack. | 0,5% | — |
| CVE-2026-69775 | HIGH 7.1 | microsoft windows_11_23h2 Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges over a network. | 0,5% | — |
| CVE-2026-69761 | HIGH 7.1 | microsoft windows_10_1607 Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges over a network. | 0,5% | — |
| CVE-2026-69340 | HIGH 7.1 | microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network. | 0,5% | — |
| CVE-2026-68893 | HIGH 7.1 | microsoft windows_10_1607 Use after free in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges over a network. | 0,5% | — |
| CVE-2026-47891 | CRIT 9.8 | vmware spring_framework A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the maxInMemorySize limit. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - | 0,5% | — |
| CVE-2026-22730 | HIGH 8.8 | vmware spring_ai A critical SQL injection vulnerability in Spring AI's MariaDBFilterExpressionConverter allows attackers to bypass metadata-based access controls and execute arbitrary SQL commands. The vulnerability exists due to missing input sanitization. | 0,5% | — |
| CVE-2025-26796 | MED 5.4 | apache oozie ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Oozie. This issue affects Apache Oozie: all versions. As this project is retired, we do not plan to release a version | 0,5% | — |
| CVE-2025-20150 | MED 5.3 | cisco nexus_dashboard A vulnerability in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to enumerate LDAP user accounts. This vulnerability is due to the improper handling of LDAP authentication requests. An attacker could exploit this vulnerability by sen | 0,5% | — |
| CVE-2024-50047 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: client: fix UAF in async decryption Doing an async decryption (large read) crashes with a slab-use-after-free way down in the crypto API. Reproducer: # mount.cifs -o ...,seal,esize | 0,5% | — |
| CVE-2024-30402 | MED 5.9 | juniper junos An Improper Check for Unusual or Exceptional Conditions vulnerability in the Layer 2 Address Learning Daemon (l2ald) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS). When teleme | 0,5% | — |
| CVE-2023-52732 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ceph: blocklist the kclient when receiving corrupted snap trace When received corrupted snap trace we don't know what exactly has happened in MDS side. And we shouldn't continue IOs and meta | 0,5% | — |
| CVE-2023-45582 | MED 5.6 | fortinet fortimail An improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiMail webmail version 7.2.0 through 7.2.4, 7.0.0 through 7.0.6 and before 6.4.8 may allow an unauthenticated attacker to perform a brute force attack on the affected e | 0,5% | — |
| CVE-2023-44207 | MED 5.4 | acronis cyber_protect Stored cross-site scripting (XSS) vulnerability in protection plan name. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979. | 0,5% | — |
| CVE-2022-38444 | HIGH 7.8 | adobe dimension Adobe Dimension versions 3.4.5 is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | 0,5% | — |
| CVE-2022-38442 | HIGH 7.8 | adobe dimension Adobe Dimension versions 3.4.5 is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | 0,5% | — |