58.507 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.507 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2015-6252 | LOW 2.1 | linux linux_kernel The vhost_dev_ioctl function in drivers/vhost/vhost.c in the Linux kernel before 4.1.5 allows local users to cause a denial of service (memory consumption) via a VHOST_SET_LOG_FD ioctl call that triggers permanent file-descriptor allocation. | 0,4% | — |
| CVE-2004-0178 | LOW 2.1 | linux linux_kernel The OSS code for the Sound Blaster (sb16) driver in Linux 2.4.x before 2.4.26, when operating in 16 bit mode, does not properly handle certain sample sizes, which allows local users to cause a denial of service (crash) via a sample with an odd number of bytes. | 0,4% | — |
| CVE-2026-87618 | HIGH 8.3 | google chrome Incorrect reference resolution in Storage in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium secu | 0,4% | — |
| CVE-2026-87616 | HIGH 8.3 | google chrome Improper initialization in Views in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted H | 0,4% | — |
| CVE-2026-79175 | HIGH 8.3 | google chrome Type confusion in Accessibility in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | 0,4% | — |
| CVE-2026-53235 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: add pskb_may_pull() to skb_gro_receive_list() skb_gro_receive_list() calls skb_pull(skb, skb_gro_offset(skb)) without first ensuring the data is in the linear area via pskb_may_pull(). | 0,4% | — |
| CVE-2026-53229 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: xsk: Fix DMA and xdp_frame leak on XDP_TX xmit failure In the XSK branch of mlx5e_xmit_xdp_buff(), when sq->xmit_xdp_frame() returns false (e.g. XDPSQ is full), the function retur | 0,4% | — |
| CVE-2026-23451 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: bonding: prevent potential infinite loop in bond_header_parse() bond_header_parse() can loop if a stack of two bonding devices is setup, because skb->dev always points to the hierarchy top. | 0,4% | — |
| CVE-2025-53734 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2025-52981 | HIGH 7.5 | juniper junos An Improper Check for Unusual or Exceptional Conditions vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX1600, SRX2300, SRX 4000 Series, and SRX5000 Series with SPC3 allows an unauthenticated, network-based att | 0,4% | — |
| CVE-2025-52946 | HIGH 7.5 | juniper junos A Use After Free vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Juniper Networks Junos OS Evolved allows an attacker sending a BGP update with a specifically malformed AS PATH to cause rpd to crash, resulting in a Denial of | 0,4% | — |
| CVE-2025-52452 | HIGH 8.5 | tableau tableau_server Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salesforce Tableau Server on Windows, Linux (tabdoc api - duplicate-data-source modules) allows Absolute Path Traversal. This issue affects Tableau Server: before 2 | 0,4% | — |
| CVE-2025-21325 | HIGH 7.8 | microsoft windows_10_21h2 Windows Secure Kernel Mode Elevation of Privilege Vulnerability | 0,4% | — |
| CVE-2024-25710 | HIGH 8.1 | apache commons_compress Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.3 through 1.25.0. Users are recommended to upgrade to version 1.26.0 which fixes the issue. | 0,4% | — |
| CVE-2024-20457 | MED 6.5 | cisco unified_communications_manager_im_and_presence_service A vulnerability in the logging component of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerabil | 0,4% | — |
| CVE-2024-20445 | MED 5.3 | cisco desk_phone_9841_firmware A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 could allow an unauthenticated, remote attacker to access sensitive information on an affected device. This vulnerability is due t | 0,4% | — |
| CVE-2023-47707 | MED 5.4 | ibm security_guardium_key_lifecycle_manager IBM Security Guardium Key Lifecycle Manager 4.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure withi | 0,4% | — |
| CVE-2022-24525 | HIGH 7.0 | microsoft windows_10 Windows Update Stack Elevation of Privilege Vulnerability | 0,4% | — |
| CVE-2022-22218 | HIGH 7.5 | juniper junos On SRX Series devices, an Improper Check for Unusual or Exceptional Conditions when using Certificate Management Protocol Version 2 (CMPv2) auto re-enrollment, allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS) by crashing the | 0,4% | — |
| CVE-2021-1284 | HIGH 8.8 | cisco catalyst_sd-wan_manager A vulnerability in the web-based messaging service interface of Cisco SD-WAN vManage Software could allow an unauthenticated, adjacent attacker to bypass authentication and authorization and modify the configuration of an affected system. To exploit this vulne | 0,4% | — |
| CVE-2021-0209 | MED 6.5 | juniper junos_os_evolved In Juniper Networks Junos OS Evolved an attacker sending certain valid BGP update packets may cause Junos OS Evolved to access an uninitialized pointer causing RPD to core leading to a Denial of Service (DoS). Continued receipt of these types of valid BGP upda | 0,4% | — |
| CVE-2019-0127 | LOW 3.9 | intel openvino Logic error in the installer for Intel(R) OpenVINO(TM) 2018 R3 and before for Linux may allow a privileged user to potentially enable information disclosure via local access. | 0,4% | — |
| CVE-2017-12188 | HIGH 7.8 | linux linux_kernel arch/x86/kvm/mmu.c in the Linux kernel through 4.13.5, when nested virtualisation is used, does not properly traverse guest pagetable entries to resolve a guest virtual address, which allows L1 guest OS users to execute arbitrary code on the host OS or cause a | 0,4% | — |
| CVE-2016-9379 | HIGH 7.9 | citrix xenserver The pygrub boot loader emulator in Xen, when S-expression output format is requested, allows local pygrub-using guest OS administrators to read or delete arbitrary files on the host via string quotes and S-expressions in the bootloader configuration file. | 0,4% | — |
| CVE-2011-4621 | MED 5.5 | linux linux_kernel The Linux kernel before 2.6.37 does not properly implement a certain clock-update optimization, which allows local users to cause a denial of service (system hang) via an application that executes code in a loop. | 0,4% | — |