EN
58.444 CVE seguite
792 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.444 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più alto In KEV dal, ordina dal più alto
CVE-2007-6716 MED 5.5 canonical ubuntu_linux fs/direct-io.c in the dio subsystem in the Linux kernel before 2.6.23 does not properly zero out the dio struct, which allows local users to cause a denial of service (OOPS), as demonstrated by a certain fio test. 0,5% —
CVE-2005-2708 LOW 2.1 linux linux_kernel The search_binary_handler function in exec.c in Linux 2.4 kernel on 64-bit x86 architectures does not check a return code for a particular function call when virtual memory is low, which allows local users to cause a denial of service (panic), as demonstrated 0,5% —
CVE-2026-53391 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr nfs4_decode_mp_ds_addr() decodes the r_netid and r_addr opaques of a netaddr4 from a GETDEVICEINFO multipath-DS body, then imm 0,5% —
CVE-2026-50338 HIGH 8.2 microsoft azure_spring_cloud Improper authentication in Azure Spring Apps allows an authorized attacker to elevate privileges over a network. 0,5% —
CVE-2026-24734 HIGH 7.5 apache tomcat Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Native (and Tomcat's FFM port of the Tomcat Native code) did not complete verification or freshness checks on the OCSP response which could al 0,5% —
CVE-2025-59204 MED 5.5 microsoft windows_10_1809 Use of uninitialized resource in Windows Management Services allows an authorized attacker to disclose information locally. 0,5% —
CVE-2025-55682 MED 6.1 microsoft windows_11_24h2 Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. 0,5% —
CVE-2025-55337 MED 6.1 microsoft windows_11_24h2 Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. 0,5% —
CVE-2025-55325 MED 5.5 microsoft windows_10_1507 Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. 0,5% —
CVE-2025-53761 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. 0,5% —
CVE-2025-53741 HIGH 7.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0,5% —
CVE-2025-53738 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0,5% —
CVE-2025-49736 MED 4.3 microsoft edge The ui performs the wrong action in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network. 0,5% —
CVE-2025-49680 HIGH 7.3 microsoft windows_10_1507 Improper link resolution before file access ('link following') in Windows Performance Recorder allows an authorized attacker to deny service locally. 0,5% —
CVE-2024-53956 HIGH 7.8 adobe premiere_pro Premiere Pro versions 25.0, 24.6.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim mu 0,5% —
CVE-2024-50162 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: bpf: devmap: provide rxq after redirect rxq contains a pointer to the device from where the redirect happened. Currently, the BPF program that was executed after a redirect via BPF_MAP_TYPE_ 0,5% —
CVE-2024-39565 HIGH 8.8 juniper j-web An Improper Neutralization of Data within XPath Expressions ('XPath Injection') vulnerability in J-Web shipped with Juniper Networks Junos OS allows an unauthenticated, network-based attacker to execute remote commands on the target device.  While an administ 0,5% —
CVE-2023-47160 HIGH 8.2 ibm cognos_controller IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consu 0,5% —
CVE-2023-20136 MED 4.3 cisco secure_workload A vulnerability in the OpenAPI of Cisco Secure Workload could allow an authenticated, remote attacker with the privileges of a read-only user to execute operations that should require Administrator privileges. The attacker would need valid user credentials. 0,5% —
CVE-2022-49872 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: gso: fix panic on frag_list with mixed head alloc types Since commit 3dcbdb134f32 ("net: gso: Fix skb_segment splat when splitting gso_size mangled skb having linear-headed frag_list"), 0,5% —
CVE-2020-9391 MED 5.5 fedoraproject fedora An issue was discovered in the Linux kernel 5.4 and 5.5 through 5.5.6 on the AArch64 architecture. It ignores the top byte in the address passed to the brk system call, potentially moving the memory break downwards when the application expects it to move upwar 0,5% —
CVE-2020-5932 MED 4.8 f5 big-ip_application_security_manager On BIG-IP ASM 15.1.0-15.1.0.5, a cross-site scripting (XSS) vulnerability exists in the BIG-IP ASM Configuration utility response and blocking pages. An authenticated user with administrative privileges can specify a response page with any content, including J 0,5% —
CVE-2020-28974 MED 5.0 debian debian_linux A slab-out-of-bounds read in fbcon in the Linux kernel before 5.9.7 could be used by local attackers to read privileged information or potentially crash the kernel, aka CID-3c4e0dff2095. This occurs because KD_FONT_OP_COPY in drivers/tty/vt/vt.c can be used fo 0,5% —
CVE-2020-11565 MED 6.0 canonical ubuntu_linux An issue was discovered in the Linux kernel through 5.6.2. mpol_parse_str in mm/mempolicy.c has a stack-based out-of-bounds write because an empty nodelist is mishandled during mount option parsing, aka CID-aa9f7d5172fa. NOTE: Someone in the security community 0,5% —
CVE-2013-6975 MED 4.6 cisco nx-os Directory traversal vulnerability in the command-line interface in Cisco NX-OS 6.2(2a) and earlier allows local users to read arbitrary files via unspecified input, aka Bug ID CSCul05217. 0,5% —