56.662 CVE seguite
776 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.662 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più basso | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2007-5671 | MED 4.4 | vmware ace HGFS.sys in the VMware Tools package in VMware Workstation 5.x before 5.5.6 build 80404, VMware Player before 1.0.6 build 80404, VMware ACE before 1.0.5 build 79846, VMware Server before 1.0.5 build 80187, and VMware ESX 2.5.4 through 3.0.2 does not properly v | 0,4% | — |
| CVE-2007-3740 | MED 4.4 | linux linux_kernel The CIFS filesystem in the Linux kernel before 2.6.22, when Unix extension support is enabled, does not honor the umask of a process, which allows local users to gain privileges. | 0,4% | — |
| CVE-2007-2110 | MED 4.4 | oracle database_server Unspecified vulnerability in the Core RDBMS component for Oracle Database 9.0.1.5+, 9.2.0.7, and 10.1.0.4 on Windows systems has unknown impact and attack vectors, aka DB03. NOTE: as of 20070424, Oracle has not disputed reliable claims that DB03 occurs becaus | 0,5% | — |
| CVE-2007-1743 | MED 4.4 | apache http_server suexec in Apache HTTP Server (httpd) 2.2.3 does not verify combinations of user and group IDs on the command line, which might allow local users to leverage other vulnerabilities to create arbitrary UID/GID owned files if /proc is mounted. NOTE: the researche | 0,7% | — |
| CVE-2007-1388 | MED 4.4 | linux linux_kernel The do_ipv6_setsockopt function in net/ipv6/ipv6_sockglue.c in Linux kernel before 2.6.20, and possibly other versions, allows local users to cause a denial of service (oops) by calling setsockopt with the IPV6_RTHDR option name and possibly a zero option leng | 0,6% | — |
| CVE-2006-7037 | MED 4.4 | mathsoft mathcad Mathcad 12 through 13.1 allows local users to bypass the security features by directly accessing or editing the XML representation of the worksheet with a text editor or other program, which allows attackers to (1) bypass password protection by replacing the p | 0,3% | — |
| CVE-2006-6579 | MED 4.4 | microsoft internet_information_server Microsoft Windows XP has weak permissions (FILE_WRITE_DATA and FILE_READ_DATA for Everyone) for %WINDIR%\pchealth\ERRORREP\QHEADLES, which allows local users to write and read files in this folder, as demonstrated by an ASP shell that has write access by IWAM_ | 1,3% | — |
| CVE-2004-2731 | MED 4.4 | linux linux_kernel Multiple integer overflows in Sbus PROM driver (drivers/sbus/char/openprom.c) for the Linux kernel 2.4.x up to 2.4.27, 2.6.x up to 2.6.7, and possibly later versions, allow local users to execute arbitrary code by specifying (1) a small buffer size to the copy | 0,6% | — |
| CVE-2026-50485 | MED 4.5 | microsoft windows_10_1607 Buffer over-read in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network. | 0,4% | — |
| CVE-2025-21401 | MED 4.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | 0,3% | — |
| CVE-2024-27265 | MED 4.5 | ibm integration_bus IBM Integration Bus for z/OS 10.1 through 10.1.0.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 284564. | 0,2% | — |
| CVE-2024-2432 | MED 4.5 | paloaltonetworks globalprotect A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs with elevated privileges. However, execution requires that the local user is able to successfully exploit a race c | 0,4% | — |
| CVE-2023-38188 | MED 4.5 | microsoft azure_hdinsight Azure Apache Hadoop Spoofing Vulnerability | 1,0% | — |
| CVE-2023-36881 | MED 4.5 | microsoft azure_hdinsight Azure Apache Ambari Spoofing Vulnerability | 1,0% | — |
| CVE-2023-36877 | MED 4.5 | microsoft azure_hdinsight Azure Apache Oozie Spoofing Vulnerability | 1,0% | — |
| CVE-2023-35393 | MED 4.5 | microsoft azure_hdinsight Azure Apache Hive Spoofing Vulnerability | 1,4% | — |
| CVE-2023-24816 | MED 4.5 | ipython ipython IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language. Versions prior to 8.1.0 are subject to a command injection vulnerability with very specific p | 1,3% | — |
| CVE-2023-23408 | MED 4.5 | microsoft azure_hdinsight Azure Apache Ambari Spoofing Vulnerability | 4,0% | — |
| CVE-2022-30610 | MED 4.5 | ibm spectrum_copy_data_management IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 is vulnerable to reverse tabnabbing where it could allow a page linked to from within IBM Spectrum Copy Data Management to rewrite it. An administrator could enter a link to a malicious URL that anothe | 0,6% | — |
| CVE-2021-23002 | MED 4.5 | f5 access_policy_manager_clients When using BIG-IP APM 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, or all 12.1.x and 11.6.x versions or Edge Client versions 7.2.1.x before 7.2.1.1, 7.1.9.x before 7.1.9.8, or 7.1.8.x before 7.1.8.5, the session | 0,3% | — |
| CVE-2020-35508 | MED 4.5 | linux linux_kernel A flaw possibility of race condition and incorrect initialization of the process id was found in the Linux kernel child/parent process identification handling while filtering signal handlers. A local attacker is able to abuse this flaw to bypass checks to send | 0,2% | — |
| CVE-2018-8201 | MED 4.5 | microsoft windows_10 A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server | 1,9% | — |
| CVE-2017-11818 | MED 4.5 | microsoft windows_10 The Microsoft Windows Storage component on Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a security feature bypass vulnerability when it fails to validate an integrity-level | 1,2% | — |
| CVE-2010-5160 | MED 4.5 | eset smart_security Race condition in ESET Smart Security 4.2.35.3 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user- | 0,4% | — |
| CVE-2026-64922 | MED 4.6 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 0,4% | — |