EN
58.444 CVE seguite
792 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.444 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più alto In KEV dal, ordina dal più alto
CVE-2012-2390 MED 4.9 linux linux_kernel Memory leak in mm/hugetlb.c in the Linux kernel before 3.4.2 allows local users to cause a denial of service (memory consumption or system crash) via invalid MAP_HUGETLB mmap operations. 0,5% —
CVE-2005-0532 LOW 2.1 linux linux_kernel The reiserfs_copy_from_user_to_file_region function in reiserfs/file.c for Linux kernel 2.6.10 and 2.6.11 before 2.6.11-rc4, when running on 64-bit architectures, may allow local users to trigger a buffer overflow as a result of casting discrepancies between s 0,5% —
CVE-2026-78449 HIGH 8.1 microsoft windows_10_1607 Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network. 0,5% —
CVE-2026-72981 HIGH 8.1 microsoft windows_10_1607 Use after free in IP Helper allows an unauthorized attacker to execute code over a network. 0,5% —
CVE-2026-45426 LOW 3.1 apache airflow Exploitation requires the attacker to already be an authenticated Airflow worker holding a valid Log-server JWT issued for at least one Dag. Apache Airflow's Log server authorized JWT tokens against Dag IDs by applying Python's `str.lstrip()` to the requested 0,5% —
CVE-2026-40963 LOW 3.1 apache airflow The structure_data endpoint in the Airflow UI returned external dependency graph nodes for linked Dags without checking whether the caller had read permission on those linked Dags. An authenticated UI/API user authorized for one Dag could enumerate linked Dag 0,5% —
CVE-2025-22042 HIGH 8.1 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: ksmbd: add bounds check for create lease context Add missing bounds check for create lease context. 0,5% —
CVE-2025-20162 HIGH 8.6 cisco ios_xe A vulnerability in the DHCP snooping security feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a full interface queue wedge, which could result in a denial of service (DoS) condition. This vulnerability is due to imp 0,5% —
CVE-2024-20426 HIGH 8.6 cisco adaptive_security_appliance_software A vulnerability in the Internet Key Exchange version 2 (IKEv2) protocol for VPN termination of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial 0,5% —
CVE-2023-42019 MED 5.9 ibm infosphere_information_server IBM InfoSphere Information Server 11.7 could allow a remote attacker to cause a denial of service due to improper input validation. IBM X-Force ID: 265161. 0,5% —
CVE-2023-36759 MED 6.7 microsoft visual_studio_2019 Visual Studio Elevation of Privilege Vulnerability 0,5% —
CVE-2023-24965 MED 5.8 ibm aspera_faspex IBM Aspera Faspex 5.0.5 does not restrict or incorrectly restricts access to a resource from an unauthorized actor. IBM X-Force ID: 246713. 0,5% —
CVE-2022-40277 HIGH 7.8 joplinapp joplin Joplin version 2.8.8 allows an external attacker to execute arbitrary commands remotely on any client that opens a link in a malicious markdown file, via Joplin. This is possible because the application does not properly validate the schema/protocol of existin 0,5% —
CVE-2022-22442 MED 6.5 ibm infosphere_information_server "IBM InfoSphere Information Server 11.7 could allow an authenticated user to access information restricted to users with elevated privileges due to improper access controls. IBM X-Force ID: 224427." 0,5% —
CVE-2021-43076 MED 6.3 fortinet fortiadc An improper privilege management vulnerability [CWE-269] in FortiADC versions 6.2.1 and below, 6.1.5 and below, 6.0.4 and below, 5.4.5 and below and 5.3.7 and below may allow a remote authenticated attacker with restricted user profile to modify the system fil 0,5% —
CVE-2020-5032 MED 4.3 ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.3 and 7.4 in some configurations may be vulnerable to a temporary denial of service attack when sent particular payloads. IBM X-Force ID: 194178. 0,5% —
CVE-2020-29373 MED 6.5 linux linux_kernel An issue was discovered in fs/io_uring.c in the Linux kernel before 5.6. It unsafely handles the root directory during path lookups, and thus a process inside a mount namespace can escape to unintended filesystem locations, aka CID-ff002b30181d. 0,5% —
CVE-2019-6724 HIGH 7.8 barracuda vpn_client The barracudavpn component of the Barracuda VPN Client prior to version 5.0.2.7 for Linux, macOS, and OpenBSD runs as a privileged process and can allow an unprivileged local attacker to load a malicious library, resulting in arbitrary code executing as root. 0,5% —
CVE-2019-18895 HIGH 7.8 scanguard scanguard_antivirus Scanguard through 2019-11-12 on Windows has Insecure Permissions for the installation directory, leading to privilege escalation via a Trojan horse executable file. 0,5% —
CVE-2019-15996 MED 6.7 cisco dna_spaces\ A vulnerability in Cisco DNA Spaces: Connector could allow an authenticated, local attacker to elevate privileges and execute arbitrary commands on the underlying operating system as root. The vulnerability is due to insufficient restrictions during the execut 0,5% —
CVE-2019-15628 HIGH 7.8 trendmicro antivirus_\+_security_2020 Trend Micro Security (Consumer) 2020 (v16.0.1221 and below) is affected by a DLL hijacking vulnerability that could allow an attacker to use a specific service as an execution and/or persistence mechanism which could execute a malicious program each time the s 0,5% —
CVE-2017-4902 HIGH 8.8 vmware esxi VMware ESXi 6.5 without patch ESXi650-201703410-SG and 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior to 12.5.5; and Fusion Pro / Fusion 8.x prior to 8.5.6 have a Heap Buffer Overflow in SVGA. This issue may allow a guest to execut 0,5% —
CVE-2015-8575 MED 4.0 linux linux_kernel The sco_sock_bind function in net/bluetooth/sco.c in the Linux kernel before 4.3.4 does not verify an address length, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR protection mechanism via a crafted applicatio 0,5% —
CVE-2015-2111 LOW 2.1 hp intelligent_provisioning Unspecified vulnerability in HP Intelligent Provisioning 1.40 through 1.60 on Windows Server 2008 R2 and 2012 allows local users to obtain sensitive information via unknown vectors. 0,5% —
CVE-2011-0463 LOW 2.1 canonical ubuntu_linux The ocfs2_prepare_page_for_write function in fs/ocfs2/aops.c in the Oracle Cluster File System 2 (OCFS2) subsystem in the Linux kernel before 2.6.39-rc1 does not properly handle holes that cross page boundaries, which allows local users to obtain potentially s 0,5% —