58.507 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.507 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2017-18208 | MED 5.5 | linux linux_kernel The madvise_willneed function in mm/madvise.c in the Linux kernel before 4.14.4 allows local users to cause a denial of service (infinite loop) by triggering use of MADVISE_WILLNEED for a DAX mapping. | 0,5% | — |
| CVE-2013-2899 | MED 4.7 | linux linux_kernel drivers/hid/hid-picolcd_core.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_PICOLCD is enabled, allows physically proximate attackers to cause a denial of service (NULL pointer dereference and OOPS) via a craf | 0,5% | — |
| CVE-2011-2493 | LOW 2.1 | linux linux_kernel The ext4_fill_super function in fs/ext4/super.c in the Linux kernel before 2.6.39 does not properly initialize a certain error-report data structure, which allows local users to cause a denial of service (OOPS) by attempting to mount a crafted ext4 filesystem. | 0,5% | — |
| CVE-2010-1970 | MED 4.6 | hp insight_software_installer Unspecified vulnerability in HP Insight Software Installer for Windows before 6.1 allows local users to read or modify data, and consequently gain privileges, via unknown vectors. | 0,5% | — |
| CVE-2005-3620 | LOW 2.1 | vmware esx The management interface for VMware ESX Server 2.0.x before 2.0.2 patch 1, 2.1.x before 2.1.3 patch 1, and 2.x before 2.5.3 patch 2 records passwords in cleartext in URLs that are stored in world-readable web server log files, which allows local users to gain | 0,5% | — |
| CVE-2026-56207 | CRIT 9.8 | apache impala Signature of Bearer token is not verified in last step of SAML2 authentication for Impala's hs2-http interface, allowing altering user name and acting as another user. This issue affects Apache Impala: >=4.0.0. Users are recommended to upgrade to version | 0,5% | — |
| CVE-2026-53394 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nfsd: avoid leaking pre-allocated openowner on unconfirmed retry race When find_or_alloc_open_stateowner() encounters an unconfirmed owner, it calls release_openowner() and sets oo = NULL. C | 0,5% | — |
| CVE-2026-0284 | CRIT 9.9 | paloaltonetworks pan-os An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to inject malicious XML content, potentially leading to information disclosure or corrupt | 0,5% | — |
| CVE-2025-54659 | MED 5.8 | fortinet fortisoar_agent_communication_bridge An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] vulnerability in Fortinet FortiSOAR Agent Communication Bridge 1.1.0, FortiSOAR Agent Communication Bridge 1.0 all versions may allow an unauthenticated at | 0,5% | — |
| CVE-2025-30416 | CRIT 10.0 | acronis cyber_protect Sensitive data disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis Cyber Protect 15 (Linux, Windows) before build 41800. | 0,5% | — |
| CVE-2025-13224 | HIGH 8.8 | google chrome Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 0,5% | — |
| CVE-2024-56718 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/smc: protect link down work from execute after lgr freed link down work may be scheduled before lgr freed but execute after lgr freed, which may result in crash. So it is need to hold a | 0,5% | — |
| CVE-2023-38116 | LOW 3.3 | foxit pdf_editor Foxit PDF Reader Doc Object Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulner | 0,5% | — |
| CVE-2023-38115 | LOW 3.3 | foxit pdf_editor Foxit PDF Reader AcroForm Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerab | 0,5% | — |
| CVE-2023-38108 | LOW 3.3 | foxit pdf_editor Foxit PDF Reader PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this | 0,5% | — |
| CVE-2023-35320 | HIGH 7.8 | microsoft windows_10_1607 Connected User Experiences and Telemetry Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2023-34037 | MED 5.3 | vmware horizon_client VMware Horizon Server contains a HTTP request smuggling vulnerability. A malicious actor with network access may be able to perform HTTP smuggle requests. | 0,5% | — |
| CVE-2023-33952 | MED 6.7 | linux linux_kernel A double-free vulnerability was found in handling vmw_buffer_object objects in the vmwgfx driver in the Linux kernel. This issue occurs due to the lack of validating the existence of an object prior to performing further free operations on the object, which ma | 0,5% | — |
| CVE-2023-23409 | MED 5.5 | microsoft windows_10_1507 Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability | 0,5% | — |
| CVE-2023-23394 | MED 5.5 | microsoft windows_10_1507 Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability | 0,5% | — |
| CVE-2023-21687 | MED 5.5 | microsoft windows_11_21h2 HTTP.sys Information Disclosure Vulnerability | 0,5% | — |
| CVE-2022-3903 | MED 4.6 | linux linux_kernel An incorrect read request flaw was found in the Infrared Transceiver USB driver in the Linux kernel. This issue occurs when a user attaches a malicious USB device. A local user could use this flaw to starve the resources, causing denial of service or potential | 0,5% | — |
| CVE-2022-35849 | HIGH 7.8 | fortinet fortiadc An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiADC 7.1.0 through 7.1.1, 7.0.0 through 7.0.3, 6.2.0 through 6.2.5 and 6.1.0 all versions may allow an authenticated attacker to exe | 0,5% | — |
| CVE-2022-22208 | MED 5.9 | juniper junos A Use After Free vulnerability in the Routing Protocol Daemon (rdp) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker to cause Denial of Service (DoS). When a BGP session flap happens, a Use After Free of a memo | 0,5% | — |
| CVE-2017-10662 | HIGH 7.8 | linux linux_kernel The sanity_check_raw_super function in fs/f2fs/super.c in the Linux kernel before 4.11.1 does not validate the segment count, which allows local users to gain privileges via unspecified vectors. | 0,5% | — |