58.507 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.507 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2018-16276 | HIGH 7.8 | canonical ubuntu_linux An issue was discovered in yurex_read in drivers/usb/misc/yurex.c in the Linux kernel before 4.17.7. Local attackers could use user access read/writes with incorrect bounds checking in the yurex USB driver to crash the kernel or potentially escalate privileges | 0,4% | — |
| CVE-2018-1487 | HIGH 8.4 | ibm db2 IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5 and 11.1 binaries load shared libraries from an untrusted path potentially giving low privilege users full access to the DB2 instance account by loading a malicious shared librar | 0,4% | — |
| CVE-2014-4171 | MED 4.7 | canonical ubuntu_linux mm/shmem.c in the Linux kernel through 3.15.1 does not properly implement the interaction between range notification and hole punching, which allows local users to cause a denial of service (i_mutex hold) by using the mmap system call to access a hole, as demo | 0,4% | — |
| CVE-2013-1819 | MED 4.6 | linux linux_kernel The _xfs_buf_find function in fs/xfs/xfs_buf.c in the Linux kernel before 3.7.6 does not validate block numbers, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leve | 0,4% | — |
| CVE-2011-1169 | HIGH 7.2 | linux linux_kernel Array index error in the asihpi_hpi_ioctl function in sound/pci/asihpi/hpioctl.c in the AudioScience HPI driver in the Linux kernel before 2.6.38.1 might allow local users to cause a denial of service (memory corruption) or possibly gain privileges via a craft | 0,4% | — |
| CVE-2001-1397 | LOW 2.1 | linux linux_kernel The System V (SYS5) shared memory implementation for Linux kernel before 2.2.19 could allow attackers to modify recently freed memory. | 0,4% | — |
| CVE-2001-1396 | LOW 3.6 | linux linux_kernel Unknown vulnerabilities in strnlen_user for Linux kernel before 2.2.19, with unknown impact. | 0,4% | — |
| CVE-2001-1395 | LOW 3.6 | linux linux_kernel Unknown vulnerability in sockfilter for Linux kernel before 2.2.19 related to "boundary cases," with unknown impact. | 0,4% | — |
| CVE-2026-40978 | HIGH 8.8 | vmware spring_ai SQL injection vulnerability in Spring AI's `CosmosDBVectorStore` allows attackers to execute arbitrary SQL queries via crafted document IDs. Affected versions: Spring AI: 1.0.0 - 1.0.5 (fixed in 1.0.6), 1.1.0 - 1.1.4 (fixed in 1.1.5) | 0,4% | — |
| CVE-2025-66236 | HIGH 7.5 | apache airflow Before Airflow 3.2.0, it was unclear that secure Airflow deployments require the Deployment Manager to take appropriate actions and pay attention to security details and security model of Airflow. Some assumptions the Deployment Manager could make were not cle | 0,4% | — |
| CVE-2025-21676 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: fec: handle page_pool_dev_alloc_pages error The fec_enet_update_cbd function calls page_pool_dev_alloc_pages but did not handle the case when it returned NULL. There was a WARN_ON(!new_ | 0,4% | — |
| CVE-2025-20183 | MED 5.8 | cisco asyncos A vulnerability in a policy-based Cisco Application Visibility and Control (AVC) implementation of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to evade the antivirus scanner and download a malicious fil | 0,4% | — |
| CVE-2025-13630 | HIGH 8.8 | google chrome Type Confusion in V8 in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 0,4% | — |
| CVE-2024-44973 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mm, slub: do not call do_slab_free for kfence object In 782f8906f805 the freeing of kfence objects was moved from deep inside do_slab_free to the wrapper functions outside. This is a nice ch | 0,4% | — |
| CVE-2024-20737 | MED 5.5 | adobe after_effects After Effects versions 24.1, 23.6.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue | 0,4% | — |
| CVE-2023-28262 | HIGH 7.8 | microsoft visual_studio_2019 Visual Studio Elevation of Privilege Vulnerability | 0,4% | — |
| CVE-2023-20230 | MED 5.4 | cisco application_policy_infrastructure_controller A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to read, modify, or delete non-tenant policies (for example, access policies) created by | 0,4% | — |
| CVE-2020-7810 | HIGH 8.8 | handysoft hslogin2.dll hslogin2.dll ActiveX Control in Groupware contains a vulnerability that could allow remote files to be downloaded and executed by setting the arguments to the activex method. This is due to a lack of integrity verification of the policy files referenced in the | 0,4% | — |
| CVE-2020-36767 | HIGH 7.5 | vareille tinyfiledialogs tinyfiledialogs (aka tiny file dialogs) before 3.8.0 allows shell metacharacters in titles, messages, and other input data. | 0,4% | — |
| CVE-2020-3173 | HIGH 7.8 | cisco ucs_manager A vulnerability in the local management (local-mgmt) CLI of Cisco UCS Manager Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS) on an affected device. The vulnerability is due to insuffi | 0,4% | — |
| CVE-2020-25656 | MED 4.1 | debian debian_linux A flaw was found in the Linux kernel. A use-after-free was found in the way the console subsystem was using ioctls KDGKBSENT and KDSKBSENT. A local user could use this flaw to get read memory access out of bounds. The highest threat from this vulnerability is | 0,4% | — |
| CVE-2019-20811 | MED 5.5 | canonical ubuntu_linux An issue was discovered in the Linux kernel before 5.0.6. In rx_queue_add_kobject() and netdev_queue_add_kobject() in net/core/net-sysfs.c, a reference count is mishandled, aka CID-a3e23f719f5c. | 0,4% | — |
| CVE-2015-4279 | HIGH 7.2 | cisco unified_computing_system The Manager component in Cisco Unified Computing System (UCS) 2.2(3b) on B Blade Server devices allows local users to gain privileges for executing arbitrary CLI commands by leveraging access to the subordinate fabric interconnect, aka Bug ID CSCut32778. | 0,4% | — |
| CVE-2015-0274 | HIGH 7.2 | linux linux_kernel The XFS implementation in the Linux kernel before 3.15 improperly uses an old size value during remote attribute replacement, which allows local users to cause a denial of service (transaction overrun and data corruption) or possibly gain privileges by leverag | 0,4% | — |
| CVE-2013-2897 | MED 4.7 | linux linux_kernel Multiple array index errors in drivers/hid/hid-multitouch.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_MULTITOUCH is enabled, allow physically proximate attackers to cause a denial of service (heap memory co | 0,4% | — |