EN
58.462 CVE seguite
793 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.462 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più alto In KEV dal, ordina dal più alto
CVE-2016-3699 HIGH 7.4 linux linux_kernel The Linux kernel, as used in Red Hat Enterprise Linux 7.2 and Red Hat Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended Secure Boot restrictions and execute untrusted code by appending ACPI tables to the init 0,5% —
CVE-2014-8989 MED 4.6 linux linux_kernel The Linux kernel through 3.17.4 does not properly restrict dropping of supplemental group memberships in certain namespace scenarios, which allows local users to bypass intended file permissions by leveraging a POSIX ACL containing an entry for the group categ 0,5% —
CVE-2014-4654 MED 4.6 canonical ubuntu_linux The snd_ctl_elem_add function in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 does not check authorization for SNDRV_CTL_IOCTL_ELEM_REPLACE commands, which allows local users to remove kernel controls and cause a de 0,5% —
CVE-2014-4653 MED 4.6 canonical ubuntu_linux sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 does not ensure possession of a read/write lock, which allows local users to cause a denial of service (use-after-free) and obtain sensitive information from kernel memor 0,5% —
CVE-2009-2406 MED 6.9 linux kernel Stack-based buffer overflow in the parse_tag_11_packet function in fs/ecryptfs/keystore.c in the eCryptfs subsystem in the Linux kernel before 2.6.30.4 allows local users to cause a denial of service (system crash) or possibly gain privileges via vectors invol 0,5% —
CVE-2026-77103 HIGH 7.5 commvault commvault CommServe contained an authentication bypass issue affecting access authorization and information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe. 0,5% —
CVE-2024-52052 HIGH 7.2 wowza streaming_engine Wowza Streaming Engine below 4.9.1 permits an authenticated Streaming Engine Manager administrator to define a custom application property and poison a stream target for high-privilege remote code execution. 0,5% —
CVE-2024-43530 HIGH 7.8 microsoft windows_10_21h2 Windows Update Stack Elevation of Privilege Vulnerability 0,5% —
CVE-2024-38093 MED 4.3 microsoft edge Microsoft Edge (Chromium-based) Spoofing Vulnerability 0,5% —
CVE-2024-38083 MED 4.3 microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability 0,5% —
CVE-2024-38082 MED 4.7 microsoft edge Microsoft Edge (Chromium-based) Spoofing Vulnerability 0,5% —
CVE-2024-22389 HIGH 7.2 f5 big-ip_access_policy_manager When BIG-IP is deployed in high availability (HA) and an iControl REST API token is updated, the change does not sync to the peer device. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated 0,5% —
CVE-2024-21397 MED 5.3 microsoft azure_file_sync Microsoft Azure File Sync Elevation of Privilege Vulnerability 0,5% —
CVE-2023-47131 HIGH 7.5 n-able passportal The N-able PassPortal extension before 3.29.2 for Chrome inserts sensitive information into a log file. 0,5% —
CVE-2023-32017 HIGH 7.8 microsoft windows_10_1507 Microsoft PostScript Printer Driver Remote Code Execution Vulnerability 0,5% —
CVE-2023-24862 MED 5.5 microsoft windows_10_1507 Windows Secure Channel Denial of Service Vulnerability 0,5% —
CVE-2023-22663 MED 5.9 intel unison_software Improper authentication for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via network access. 0,5% —
CVE-2023-21697 MED 6.2 microsoft windows_10 Windows Internet Storage Name Service (iSNS) Server Information Disclosure Vulnerability 0,5% —
CVE-2022-38408 HIGH 7.8 adobe illustrator Adobe Illustrator versions 26.4 (and earlier) and 25.4.7 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interac 0,5% —
CVE-2022-35758 MED 5.5 microsoft windows_10_1507 Windows Kernel Memory Information Disclosure Vulnerability 0,5% —
CVE-2022-0617 MED 5.5 debian debian_linux A flaw null pointer dereference in the Linux kernel UDF file system functionality was found in the way user triggers udf_file_write_iter function for the malicious UDF image. A local user could use this flaw to crash the system. Actual from Linux kernel 4.2-rc 0,5% —
CVE-2021-29755 HIGH 7.5 ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.3, 7.4, and 7.5 does not preform proper certificate validation for some inter-host communications. IBM X-Force ID: 202015. 0,5% —
CVE-2021-1256 MED 6.0 cisco secure_firewall_threat_defense A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to overwrite files on the file system of an affected device by using directory traversal techniques. A successful exploit could cause syste 0,5% —
CVE-2019-15921 MED 4.7 linux linux_kernel An issue was discovered in the Linux kernel before 5.0.6. There is a memory leak issue when idr_alloc() fails in genl_register_family() in net/netlink/genetlink.c. 0,5% —
CVE-2018-6555 HIGH 7.8 canonical ubuntu_linux The irda_setsockopt function in net/irda/af_irda.c and later in drivers/staging/irda/net/af_irda.c in the Linux kernel before 4.17 allows local users to cause a denial of service (ias_object use-after-free and system crash) or possibly have unspecified other i 0,5% —