58.047 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.047 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-33557 | CRIT 9.1 | apache kafka A possible security vulnerability has been identified in Apache Kafka. By default, the broker property `sasl.oauthbearer.jwt.validator.class` is set to `org.apache.kafka.common.security.oauthbearer.DefaultJwtValidator`. It accepts any JWT token without valida | 0,7% | — |
| CVE-2025-24084 | HIGH 8.4 | microsoft windows_11_22h2 Untrusted pointer dereference in Windows Subsystem for Linux allows an unauthorized attacker to execute code locally. | 0,7% | — |
| CVE-2024-43636 | HIGH 7.8 | microsoft windows_10_1507 Win32k Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2021-47307 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: cifs: prevent NULL deref in cifs_compose_mount_options() The optional @ref parameter might contain an NULL node_name, so prevent dereferencing it in cifs_compose_mount_options(). Addresses- | 0,7% | — |
| CVE-2021-47267 | MED 6.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: usb: fix various gadget panics on 10gbps cabling usb_assign_descriptors() is called with 5 parameters, the last 4 of which are the usb_descriptor_header for: full-speed (USB1.1 - 12Mbps [i | 0,7% | — |
| CVE-2023-52669 | HIGH 8.2 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: crypto: s390/aes - Fix buffer overread in CTR mode When processing the last block, the s390 ctr code will always read a whole block, even if there isn't a whole block of data left. Fix this | 0,7% | — |
| CVE-2024-22267 | CRIT 9.3 | vmware fusion VMware Workstation and Fusion contain a use-after-free vulnerability in the vbluetooth device. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on th | 0,7% | — |
| CVE-2021-47109 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: neighbour: allow NUD_NOARP entries to be forced GCed IFF_POINTOPOINT interfaces use NUD_NOARP entries for IPv6. It's possible to fill up the neighbour table with enough entries that it will | 0,7% | — |
| CVE-2023-21569 | MED 5.5 | microsoft azure_devops_server Azure DevOps Server Spoofing Vulnerability | 0,7% | — |
| CVE-2022-26938 | HIGH 7.0 | microsoft windows_server Storage Spaces Direct Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2021-42274 | MED 6.8 | microsoft windows_10 Windows Hyper-V Discrete Device Assignment (DDA) Denial of Service Vulnerability | 0,7% | — |
| CVE-2021-31951 | HIGH 7.8 | microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2021-1690 | HIGH 7.8 | microsoft windows_10 Windows WalletService Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2021-1689 | HIGH 7.8 | microsoft windows_10 Windows Multipoint Management Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2021-1688 | HIGH 7.8 | microsoft windows_10 Windows CSC Service Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2021-1687 | HIGH 7.8 | microsoft windows_10 Windows WalletService Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2021-1686 | HIGH 7.8 | microsoft windows_10 Windows WalletService Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2021-1681 | HIGH 7.8 | microsoft windows_10 Windows WalletService Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2021-1662 | HIGH 7.8 | microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2021-1659 | HIGH 7.8 | microsoft windows_10 Windows CSC Service Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2018-0324 | MED 6.7 | cisco network_functions_virtualization_infrastructure A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, high-privileged, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation of command paramet | 0,7% | — |
| CVE-2018-0259 | HIGH 8.8 | cisco mate_collector A vulnerability in the web-based management interface of Cisco MATE Collector could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to | 0,7% | — |
| CVE-2017-13864 | MED 5.9 | apple icloud An issue was discovered in certain Apple products. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. The issue involves the "APNs Server" component. It allows man-in-the-middle attackers to track users by leveraging mishand | 0,7% | — |
| CVE-2011-1305 | MED 6.8 | google chrome Race condition in Google Chrome before 11.0.696.57 on Linux and Mac OS X allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to linked lists and a database. | 0,7% | — |
| CVE-2025-68280 | MED 6.5 | apache spatial_information_system Improper Restriction of XML External Entity Reference vulnerability in Apache SIS. It is possible to write XML files in such a way that, when parsed by Apache SIS, an XML file reveals to the attacker the content of a local file on the server running Apache | 0,7% | — |