58.061 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.061 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2019-15217 | MED 4.6 | canonical ubuntu_linux An issue was discovered in the Linux kernel before 5.2.3. There is a NULL pointer dereference caused by a malicious USB device in the drivers/media/usb/zr364xx/zr364xx.c driver. | 0,7% | — |
| CVE-2017-12341 | MED 6.7 | cisco nx-os A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. An attacker would need valid administrator credentials to perform this exploit. The vulnerability is due to insufficie | 0,7% | — |
| CVE-2013-0248 | LOW 3.3 | apache commons_fileupload The default configuration of javax.servlet.context.tempdir in Apache Commons FileUpload 1.0 through 1.2.2 uses the /tmp directory for uploaded files, which allows local users to overwrite arbitrary files via an unspecified symlink attack. | 0,7% | — |
| CVE-2012-4001 | MED 5.0 | google mod_pagespeed The mod_pagespeed module before 0.10.22.6 for the Apache HTTP Server does not properly verify its host name, which allows remote attackers to trigger HTTP requests to arbitrary hosts via unspecified vectors, as demonstrated by requests to intranet servers. | 0,7% | — |
| CVE-2026-85893 | HIGH 8.8 | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network. | 0,7% | — |
| CVE-2026-52760 | MED 6.1 | apache activemq Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web Console. The browse page in the web console renders a message Id directly without sanitization. This allows an authentic | 0,7% | — |
| CVE-2025-21399 | HIGH 7.4 | microsoft edge_update Microsoft Edge (Chromium-based) Update Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2024-47739 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: padata: use integer wrap around to prevent deadlock on seq_nr overflow When submitting more than 2^32 padata objects to padata_do_serial, the current sorting implementation incorrectly sorts | 0,7% | — |
| CVE-2024-26665 | CRIT 9.1 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: tunnels: fix out of bounds access when building IPv6 PMTU error If the ICMPv6 error is built from a non-linear skb we get the following splat, BUG: KASAN: slab-out-of-bounds in do_csum+0x | 0,7% | — |
| CVE-2023-52441 | CRIT 9.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out of bounds in init_smb2_rsp_hdr() If client send smb2 negotiate request and then send smb1 negotiate request, init_smb2_rsp_hdr is called for smb1 negotiate request since need_ | 0,7% | — |
| CVE-2023-36760 | HIGH 7.8 | microsoft 3d_viewer 3D Viewer Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2023-36740 | HIGH 7.8 | microsoft 3d_viewer 3D Viewer Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2023-36739 | HIGH 7.8 | microsoft 3d_viewer 3D Viewer Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2022-47984 | MED 6.3 | ibm infosphere_information_server IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 243163. | 0,7% | — |
| CVE-2022-2622 | MED 6.5 | fedoraproject fedora Insufficient validation of untrusted input in Safe Browsing in Google Chrome on Windows prior to 104.0.5112.79 allowed a remote attacker to bypass download restrictions via a crafted file. | 0,7% | — |
| CVE-2022-30535 | MED 6.5 | f5 nginx_ingress_controller In versions 2.x before 2.3.0 and all versions of 1.x, An attacker authorized to create or update ingress objects can obtain the secrets available to the NGINX Ingress Controller. Note: Software versions which have reached End of Technical Support (EoTS) are no | 0,7% | — |
| CVE-2019-19332 | MED 6.1 | linux linux_kernel An out-of-bounds memory write issue was found in the Linux Kernel, version 3.13 through 5.4, in the way the Linux kernel's KVM hypervisor handled the 'KVM_GET_EMULATED_CPUID' ioctl(2) request to get CPUID features emulated by the KVM hypervisor. A user or proc | 0,7% | — |
| CVE-2016-2067 | HIGH 7.8 | google android drivers/gpu/msm/kgsl.c in the MSM graphics driver (aka GPU driver) for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, mishandles the KGSL_MEMFLAGS_GPUREADONLY flag, which allows atta | 0,7% | — |
| CVE-2014-1210 | MED 5.8 | vmware vsphere_client VMware vSphere Client 5.0 before Update 3 and 5.1 before Update 2 does not properly validate X.509 certificates, which allows man-in-the-middle attackers to spoof SSL servers via a crafted certificate. | 0,7% | — |
| CVE-2026-62910 | HIGH 7.2 | microsoft exchange_server Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | 0,7% | — |
| CVE-2026-53421 | CRIT 9.8 | apache syncope Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve remote code execution through the connector subsystem by relying on scripted connectors' (REST and SQL) capability to run Gro | 0,7% | — |
| CVE-2024-24778 | MED 6.5 | apache streampipes Improper privilege management in a REST interface allowed registered users to access unauthorized resources if the resource ID was know. This issue affects Apache StreamPipes: through 0.95.1. Users are recommended to upgrade to version 0.97.0 which fixe | 0,7% | — |
| CVE-2023-28222 | HIGH 7.1 | microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2023-20081 | MED 6.8 | cisco adaptive_security_appliance_software A vulnerability in the IPv6 DHCP (DHCPv6) client module of Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense (FTD) Software, Cisco IOS Software, and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a | 0,7% | — |
| CVE-2022-20952 | MED 5.3 | cisco asyncos A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA), could allow an unauthenticated, remote attacker to bypass a configured rule, thereby allowing traffic onto a | 0,7% | — |