58.493 CVE seguite
793 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.493 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-20949 | HIGH 7.8 | microsoft 365_apps Improper access control in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature locally. | 0,5% | — |
| CVE-2025-38057 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: espintcp: fix skb leaks A few error paths are missing a kfree_skb. | 0,5% | — |
| CVE-2024-47658 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: crypto: stm32/cryp - call finalize with bh disabled The finalize operation in interrupt mode produce a produces a spinlock recursion warning. The reason is the fact that BH must be disabled | 0,5% | — |
| CVE-2024-25690 | MED 4.7 | esri portal_for_arcgis There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.1 and below that may allow a remote, unauthenticated attacker to create a crafted link which when clicked could render arbitrary HTML in the victim’s browser. | 0,5% | — |
| CVE-2022-27490 | MED 5.4 | fortinet fortianalyzer A exposure of sensitive information to an unauthorized actor in Fortinet FortiManager version 6.0.0 through 6.0.4, FortiAnalyzer version 6.0.0 through 6.0.4, FortiPortal version 6.0.0 through 6.0.9, 5.3.0 through 5.3.8, 5.2.x, 5.1.0, 5.0.x, 4.2.x, 4.1.x, Forti | 0,5% | — |
| CVE-2022-26529 | MED 6.5 | realtek bluetooth_mesh_software_development_kit Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for segmented packets’ link parameter. An unauthenticated attacker in the adjacent network can exploit this vulnerability to cause buffer overflow and d | 0,5% | — |
| CVE-2022-26528 | MED 6.5 | realtek bluetooth_mesh_software_development_kit Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for the length of segmented packets’ shift parameter. An unauthenticated attacker in the adjacent network can exploit this vulnerability to cause buffer | 0,5% | — |
| CVE-2022-26527 | MED 6.5 | realtek bluetooth_mesh_software_development_kit Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for the size of segmented packets’ reference parameter. An unauthenticated attacker in the adjacent network can exploit this vulnerability to cause buff | 0,5% | — |
| CVE-2020-4739 | HIGH 7.8 | ibm db2 IBM DB2 Accessories Suite for Linux, UNIX, and Windows, DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local authenticated attacker to execute arbitrary code on the system, caused by DLL search order | 0,5% | — |
| CVE-2019-12380 | MED 5.5 | linux linux_kernel **DISPUTED** An issue was discovered in the efi subsystem in the Linux kernel through 5.1.5. phys_efi_set_virtual_address_map in arch/x86/platform/efi/efi.c and efi_call_phys_prolog in arch/x86/platform/efi/efi_64.c mishandle memory allocation failures. NOTE: | 0,5% | — |
| CVE-2017-18216 | MED 5.5 | linux linux_kernel In fs/ocfs2/cluster/nodemanager.c in the Linux kernel before 4.15, local users can cause a denial of service (NULL pointer dereference and BUG) because a required mutex is not used. | 0,5% | — |
| CVE-2017-14140 | MED 5.5 | linux linux_kernel The move_pages system call in mm/migrate.c in the Linux kernel before 4.12.9 doesn't check the effective uid of the target process, enabling a local attacker to learn the memory layout of a setuid executable despite ASLR. | 0,5% | — |
| CVE-2010-2071 | MED 4.6 | linux linux_kernel The btrfs_xattr_set_acl function in fs/btrfs/acl.c in btrfs in the Linux kernel 2.6.34 and earlier does not check file ownership before setting an ACL, which allows local users to bypass file permissions by setting arbitrary ACLs, as demonstrated using setfacl | 0,5% | — |
| CVE-2010-1558 | MED 4.7 | hp multifunction_peripheral_digital_sending_software Unspecified vulnerability in HP Multifunction Peripheral (MFP) Digital Sending Software before 4.18.3 allows local users to bypass intended restrictions on the MFP "Send to e-mail" feature, and obtain sensitive information, via unknown vectors. | 0,5% | — |
| CVE-2006-5751 | HIGH 7.2 | linux linux_kernel Integer overflow in the get_fdb_entries function in net/bridge/br_ioctl.c in the Linux kernel before 2.6.18.4 allows local users to execute arbitrary code via a large maxnum value in an ioctl request. | 0,5% | — |
| CVE-2005-4639 | MED 4.6 | linux linux_kernel Buffer overflow in the CA-driver (dst_ca.c) for TwinHan DST Frontend/Card in Linux kernel 2.6.12 and other versions before 2.6.15 allows local users to cause a denial of service (crash) and possibly execute arbitrary code by "reading more than 8 bytes into an | 0,5% | — |
| CVE-2026-78508 | MED 4.6 | microsoft windows_10_1607 Out-of-bounds read in Windows CD-ROM Driver allows an unauthorized attacker to disclose information with a physical attack. | 0,5% | — |
| CVE-2026-78452 | MED 4.6 | microsoft windows_10_1809 Out-of-bounds read in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information with a physical attack. | 0,5% | — |
| CVE-2026-69548 | MED 4.6 | microsoft windows_10_1607 Heap-based buffer overflow in Windows RNDIS allows an unauthorized attacker to disclose information with a physical attack. | 0,5% | — |
| CVE-2026-69381 | MED 4.6 | microsoft windows_10_1607 Out-of-bounds read in Windows Storage Port Driver allows an unauthorized attacker to disclose information with a physical attack. | 0,5% | — |
| CVE-2026-66842 | HIGH 8.8 | BIG-IP has a vulnerability where an authenticated user of any role may be able to create administrative user accounts through an undisclosed request to Traffic Management User Interface (TMUI). Impact: This vulnerability may allow an authenticated attacke | 0,5% | — |
| CVE-2026-61350 | MED 4.6 | microsoft windows_10_1607 Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack. | 0,5% | — |
| CVE-2026-49794 | MED 4.6 | microsoft windows_10_1607 Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack. | 0,5% | — |
| CVE-2026-47898 | CRIT 9.8 | apache lucene.net Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common library). This issue affects Apache Lucene.Net.Analysis.Common: from 4.8.0-beta00005 before 4.8.0-beta00018. Users are recommended to upgrade | 0,5% | — |
| CVE-2026-45655 | MED 5.3 | microsoft windows_10_1607 Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. | 0,5% | — |