58.535 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.535 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-69308 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-69303 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-68895 | MED 5.5 | microsoft windows_10_1607 Numeric truncation error in Internet Storage Name Service allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-68881 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-68843 | MED 5.5 | microsoft windows_10_1607 Use after free in Microsoft Office Word allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-3542 | HIGH 8.8 | google chrome Inappropriate implementation in WebAssembly in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) | 0,4% | — |
| CVE-2026-32077 | HIGH 7.8 | microsoft windows_10_1607 Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2026-23112 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec nvmet_tcp_build_pdu_iovec() could walk past cmd->req.sg when a PDU length or offset exceeds sg_cnt and then use bogus sg->length/off | 0,4% | — |
| CVE-2026-20068 | MED 5.8 | cisco cyber_vision Multiple Cisco products are affected by a vulnerability in the Snort 3 detection engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspection. This vulnerabil | 0,4% | — |
| CVE-2026-20053 | MED 5.8 | cisco cyber_vision Multiple Cisco products are affected by a vulnerability in the Snort 3 VBA feature that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash. This vulnerability is due to improper range checking when decompressing V | 0,4% | — |
| CVE-2025-62216 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2025-62205 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2025-38527 | CRIT 9.8 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: smb: client: fix use-after-free in cifs_oplock_break A race condition can occur in cifs_oplock_break() leading to a use-after-free of the cinode structure when unmounting: cifs_oplock_bre | 0,4% | — |
| CVE-2025-27163 | MED 5.5 | adobe acrobat Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR | 0,4% | — |
| CVE-2024-57843 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: virtio-net: fix overflow inside virtnet_rq_alloc When the frag just got a page, then may lead to regression on VM. Specially if the sysctl net.core.high_order_alloc_disable value is 1, then | 0,4% | — |
| CVE-2024-21107 | MED 6.7 | oracle vm_virtualbox Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.16. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Ora | 0,4% | — |
| CVE-2022-45430 | LOW 3.7 | dahuasecurity dhi-dss4004-s2_firmware Some Dahua software products have a vulnerability of unauthenticated enable or disable SSHD service. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could enable or disable the S | 0,4% | — |
| CVE-2021-35538 | HIGH 7.8 | oracle vm_virtualbox Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.28. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Orac | 0,4% | — |
| CVE-2021-26113 | MED 6.2 | fortinet fortiwan A use of a one-way hash with a predictable salt vulnerability [CWE-760] in FortiWAN before 4.5.9 may allow an attacker who has previously come in possession of the password file to potentially guess passwords therein stored. | 0,4% | — |
| CVE-2020-12423 | HIGH 7.8 | mozilla firefox When the Windows DLL "webauthn.dll" was missing from the Operating System, and a malicious one was placed in a folder in the user's %PATH%, Firefox may have loaded the DLL, leading to arbitrary code execution. *Note: This issue only affects the Windows operati | 0,4% | — |
| CVE-2017-7187 | HIGH 7.8 | linux linux_kernel The sg_ioctl function in drivers/scsi/sg.c in the Linux kernel through 4.10.4 allows local users to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact via a large command size in an SG_NEXT_CMD_LEN ioctl call, lea | 0,4% | — |
| CVE-2017-16529 | MED 6.6 | canonical ubuntu_linux The snd_usb_create_streams function in sound/usb/card.c in the Linux kernel before 4.13.6 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspecified other impact via a crafted USB device. | 0,4% | — |
| CVE-2017-14991 | MED 5.5 | linux linux_kernel The sg_ioctl function in drivers/scsi/sg.c in the Linux kernel before 4.13.4 allows local users to obtain sensitive information from uninitialized kernel heap-memory locations via an SG_GET_REQUEST_TABLE ioctl call for /dev/sg0. | 0,4% | — |
| CVE-2015-4327 | HIGH 7.2 | cisco telepresence_video_communication_server_software The CLI in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows local users to obtain root privileges by writing script arguments to an unspecified file, aka Bug ID CSCuv12542. | 0,4% | — |
| CVE-2015-4211 | HIGH 7.2 | cisco anyconnect_secure_mobility_client Cisco AnyConnect Secure Mobility Client 3.1(60) on Windows does not properly validate pathnames, which allows local users to gain privileges via a crafted INF file, aka Bug ID CSCus65862. | 0,4% | — |