58.046 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.046 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2022-3566 | MED 4.6 | linux linux_kernel A vulnerability was identified in Linux Kernel up to 4.19.316/5.4.278/5.10.220/5.15.161. This impacts the function tcp_getsockopt/tcp_setsockopt of the component TCP Handler. Such manipulation leads to race condition. A high complexity level is associated with | 0,7% | — |
| CVE-2022-38007 | HIGH 7.8 | microsoft azure_arc Azure Guest Configuration and Azure Arc-enabled servers Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2021-29737 | HIGH 7.5 | ibm infosphere_information_server IBM InfoSphere Data Flow Designer Engine (IBM InfoSphere Information Server 11.7 ) component has improper validation of the REST API server certificate. IBM X-Force ID: 201301. | 0,7% | — |
| CVE-2026-82428 | HIGH 8.8 | Description Dependency artifacts uploaded with `storm jar --artifacts` were stored under a blob key derived only from the Maven coordinate, for example `dep---.jar`. The key was therefore identical for every user of the cluster and predictable in advance. Whe | 0,7% | — |
| CVE-2026-48330 | CRIT 10.0 | adobe campaign Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this v | 0,7% | — |
| CVE-2025-48822 | HIGH 8.6 | microsoft windows_10_1607 Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally. | 0,7% | — |
| CVE-2022-49664 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tipc: move bc link creation back to tipc_node_create Shuang Li reported a NULL pointer dereference crash: [] BUG: kernel NULL pointer dereference, address: 0000000000000068 [] RIP: 0010 | 0,7% | — |
| CVE-2022-49194 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: Use stronger register read/writes to assure ordering GCC12 appears to be much smarter about its dependency tracking and is aware that the relaxed variants are just normal load | 0,7% | — |
| CVE-2024-46666 | MED 5.3 | fortinet fortios An allocation of resources without limits or throttling [CWE-770] vulnerability in FortiOS versions 7.6.0, versions 7.4.4 through 7.4.0, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow a remote unauthenticated attacker to prevent access to the G | 0,7% | — |
| CVE-2024-38117 | HIGH 7.8 | microsoft windows_10_1507 NTFS Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2024-25699 | HIGH 8.5 | esri arcgis_enterprise There is a difficult‑to‑exploit improper authentication issue in the Home application for Esri Portal for ArcGIS versions 11.2 and below on Windows and Linux, and ArcGIS Enterprise versions 11.1 and below on Kubernetes, which under unique circumstances could a | 0,7% | — |
| CVE-2023-20083 | HIGH 8.6 | cisco secure_firewall_threat_defense A vulnerability in ICMPv6 inspection when configured with the Snort 2 detection engine for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the CPU of an affected device to spike to 100 percent, which could | 0,7% | — |
| CVE-2023-46813 | HIGH 7.0 | linux linux_kernel An issue was discovered in the Linux kernel before 6.5.9, exploitable by local users with userspace access to MMIO registers. Incorrect access checking in the #VC handler and instruction emulation of the SEV-ES emulation of MMIO accesses could lead to arbitrar | 0,7% | — |
| CVE-2023-36717 | MED 6.5 | microsoft windows_10_1507 Windows Virtual Trusted Platform Module Denial of Service Vulnerability | 0,7% | — |
| CVE-2023-38170 | HIGH 7.8 | microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2023-36869 | MED 6.3 | microsoft azure_devops_server Azure DevOps Server Spoofing Vulnerability | 0,7% | — |
| CVE-2021-38874 | MED 4.3 | ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.3, 7.4, and 7.5 allows for users to access information across tenant and domain boundaries in some situations. IBM X-Force ID: 208397. | 0,7% | — |
| CVE-2021-42304 | MED 6.6 | microsoft azure_real_time_operating_system Azure RTOS Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2021-42302 | MED 6.6 | microsoft azure_real_time_operating_system Azure RTOS Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2021-26880 | HIGH 7.8 | microsoft windows_10 Windows Storage Spaces Controller Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2021-26872 | HIGH 7.8 | microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2021-26870 | HIGH 7.8 | microsoft windows_10 Windows Projected File System Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2019-15216 | MED 4.6 | canonical ubuntu_linux An issue was discovered in the Linux kernel before 5.0.14. There is a NULL pointer dereference caused by a malicious USB device in the drivers/usb/misc/yurex.c driver. | 0,7% | — |
| CVE-2016-6325 | HIGH 7.8 | apache tomcat The Tomcat package on Red Hat Enterprise Linux (RHEL) 5 through 7, JBoss Web Server 3.0, and JBoss EWS 2 uses weak permissions for (1) /etc/sysconfig/tomcat and (2) /etc/tomcat/tomcat.conf, which allows local users to gain privileges by leveraging membership i | 0,7% | — |
| CVE-2026-81383 | HIGH 7.4 | microsoft visual_studio_code Use of incorrectly-resolved name or reference in Visual Studio Code allows an unauthorized attacker to disclose information over a network. | 0,7% | — |