58.543 CVE seguite
797 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.543 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più basso | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2015-10010 | LOW 3.1 | cisco openresolve A vulnerability was found in OpenDNS OpenResolve. It has been rated as problematic. Affected by this issue is the function get of the file resolverapi/endpoints.py of the component API. The manipulation leads to cross site scripting. The attack may be launched | 0,6% | — |
| CVE-2026-59292 | LOW 3.2 | vmware spring_integration PropertiesPersistingMetadataStore, the default file-based ConcurrentMetadataStore, persists its state to ${java.io.tmpdir}/spring-integration/metadata-store.properties with world-readable permissions. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 S | 0,1% | — |
| CVE-2026-0238 | LOW 3.2 | paloaltonetworks broker_vm A vulnerability in Palo Alto Networks Broker VM allows an authenticated administrator to inject arbitrary content into certain Broker VM fields. | 0,1% | — |
| CVE-2023-39194 | LOW 3.2 | fedoraproject fedora A flaw was found in the XFRM subsystem in the Linux kernel. The specific flaw exists within the processing of state filters, which can result in a read past the end of an allocated buffer. This flaw allows a local privileged (CAP_NET_ADMIN) attacker to trigger | 0,4% | — |
| CVE-2023-29184 | LOW 3.2 | fortinet fortios An incomplete cleanup vulnerability [CWE-459] in FortiOS 7.2 all versions and before & FortiProxy version 7.2.0 through 7.2.2 and before 7.0.8 allows a VDOM privileged attacker to add SSH key files on the system silently via crafted CLI requests. | 0,2% | — |
| CVE-2021-42754 | LOW 3.2 | fortinet forticlient An improper control of generation of code vulnerability [CWE-94] in FortiClientMacOS versions 7.0.0 and below and 6.4.5 and below may allow an authenticated attacker to hijack the MacOS camera without the user permission via the malicious dylib file. | 0,4% | — |
| CVE-2021-36170 | LOW 3.2 | fortinet fortianalyzer An information disclosure vulnerability [CWE-200] in FortiAnalyzerVM and FortiManagerVM versions 7.0.0 and 6.4.6 and below may allow an authenticated attacker to read the FortiCloud credentials which were used to activate the trial license in cleartext. | 0,2% | — |
| CVE-2013-2192 | LOW 3.2 | apache hadoop The RPC protocol implementation in Apache Hadoop 2.x before 2.0.6-alpha, 0.23.x before 0.23.9, and 1.x before 1.2.1, when the Kerberos security features are enabled, allows man-in-the-middle attackers to disable bidirectional authentication and obtain sensitiv | 1,1% | — |
| CVE-2013-0343 | LOW 3.2 | linux linux_kernel The ipv6_create_tempaddr function in net/ipv6/addrconf.c in the Linux kernel through 3.8 does not properly handle problems with the generation of IPv6 temporary addresses, which allows remote attackers to cause a denial of service (excessive retries and addres | 1,7% | — |
| CVE-2012-5512 | LOW 3.2 | citrix xenserver Array index error in the HVMOP_set_mem_access handler in Xen 4.1 allows local HVM guest OS administrators to cause a denial of service (crash) or obtain sensitive information via unspecified vectors. | 0,4% | — |
| CVE-2011-4160 | LOW 3.2 | hp operations_agent Unspecified vulnerability in HP Operations Agent 11.00 and Performance Agent 4.73 and 5.0 on AIX, HP-UX, Linux, and Solaris allows local users to bypass intended directory-access restrictions via unknown vectors. | 0,3% | — |
| CVE-2026-8662 | LOW 3.3 | rapid7 insightconnect_compression Path Traversal vulnerability in the create_archive function of Rapid7 InsightConnect Compression Plugin on Linux allows authenticated attackers to write to unintended file paths via crafted filename input. The impact is limited to file corruption as content ca | 0,3% | — |
| CVE-2026-50419 | LOW 3.3 | microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally. | 0,5% | — |
| CVE-2026-50416 | LOW 3.3 | microsoft windows_11_24h2 Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally. | 0,5% | — |
| CVE-2026-46057 | LOW 3.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: landlock: Fix LOG_SUBDOMAINS_OFF inheritance across fork() hook_cred_transfer() only copies the Landlock security blob when the source credential has a domain. This is inconsistent with lan | 0,2% | — |
| CVE-2026-45485 | LOW 3.3 | microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | 0,6% | — |
| CVE-2026-45466 | LOW 3.3 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | 0,5% | — |
| CVE-2026-45459 | LOW 3.3 | microsoft 365_apps Protection mechanism failure in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature locally. | 0,5% | — |
| CVE-2026-45455 | LOW 3.3 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | 0,8% | — |
| CVE-2026-22978 | LOW 3.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: avoid kernel-infoleak from struct iw_point struct iw_point has a 32bit hole on 64bit arches. struct iw_point { void __user *pointer; /* Pointer to the data (in user space) | 0,1% | — |
| CVE-2026-21249 | LOW 3.3 | microsoft windows_10_1607 External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing locally. | 11,4% | — |
| CVE-2026-20730 | LOW 3.3 | f5 big-ip_access_policy_manager A vulnerability exists in BIG-IP Edge Client and browser VPN clients on Windows that may allow attackers to gain access to sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | 0,1% | — |
| CVE-2025-71148 | LOW 3.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/handshake: restore destructor on submit failure handshake_req_submit() replaces sk->sk_destruct but never restores it when submission fails before the request is hashed. handshake_sk_des | 0,1% | — |
| CVE-2025-64787 | LOW 3.3 | adobe acrobat Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Improper Verification of Cryptographic Signature vulnerability that could result in a Security feature bypass. An attacker could leverag | 0,4% | — |
| CVE-2025-64786 | LOW 3.3 | adobe acrobat Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Improper Verification of Cryptographic Signature vulnerability that could result in a Security feature bypass. An attacker could leverag | 0,4% | — |