58.211 CVE seguite
789 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.211 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2020-3962 | HIGH 8.2 | vmware cloud_foundation VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain a use-after-free vulnerability in the SVGA device. A malicious act | 0,6% | — |
| CVE-2012-4073 | MED 5.8 | cisco unified_computing_system The KVM subsystem in the client in Cisco Unified Computing System (UCS) does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers, and read or modify KVM data, via a crafted certificate, aka Bug ID CSCte9033 | 0,6% | — |
| CVE-2026-83992 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network. | 0,6% | — |
| CVE-2026-81952 | HIGH 8.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | 0,6% | — |
| CVE-2026-26135 | CRIT 9.6 | microsoft azure_custom_locations_resource_provider Server-side request forgery (ssrf) in Azure Custom Locations Resource Provider (RP) allows an authorized attacker to elevate privileges over a network. | 0,6% | — |
| CVE-2026-20851 | MED 6.2 | microsoft windows_11_24h2 Out-of-bounds read in Capability Access Management Service (camsvc) allows an unauthorized attacker to disclose information locally. | 0,6% | — |
| CVE-2025-62552 | HIGH 7.8 | microsoft 365_apps Relative path traversal in Microsoft Office Access allows an unauthorized attacker to execute code locally. | 0,6% | — |
| CVE-2025-58718 | HIGH 8.8 | microsoft remote_desktop_client Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 0,6% | — |
| CVE-2025-49730 | HIGH 7.8 | microsoft windows_10_1507 Time-of-check time-of-use (toctou) race condition in Microsoft Windows QoS scheduler allows an authorized attacker to elevate privileges locally. | 0,6% | — |
| CVE-2024-20304 | HIGH 8.6 | cisco ios_xr A vulnerability in the multicast traceroute version 2 (Mtrace2) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to exhaust the UDP packet memory of an affected device. This vulnerability exists because the Mtrace2 code does | 0,6% | — |
| CVE-2023-4010 | MED 4.6 | linux linux_kernel A flaw was found in the USB Host Controller Driver framework in the Linux kernel. The usb_giveback_urb function has a logic loophole in its implementation. Due to the inappropriate judgment condition of the goto statement, the function cannot return under the | 0,6% | — |
| CVE-2023-23423 | HIGH 7.8 | microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2023-23422 | HIGH 7.8 | microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2022-33640 | HIGH 7.8 | microsoft open_management_infrastructure System Center Operations Manager: Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2021-41020 | HIGH 8.8 | fortinet fortiisolator An improper access control vulnerability [CWE-284] in FortiIsolator versions 2.3.2 and below may allow an authenticated, non privileged attacker to regenerate the CA certificate via the regeneration URL. | 0,6% | — |
| CVE-2021-26429 | HIGH 7.7 | microsoft azure_sphere Azure Sphere Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2019-12672 | MED 6.8 | cisco ios A vulnerability in the filesystem of Cisco IOS XE Software could allow an authenticated, local attacker with physical access to an affected device to execute arbitrary code on the underlying operating system (OS) with root privileges. The vulnerability is due | 0,6% | — |
| CVE-2019-9492 | HIGH 7.8 | trendmicro officescan A DLL side-loading vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow an authenticated attacker to gain code execution and terminate the product's process - disabling endpoint protection. The attacker must have already gained authentication an | 0,6% | — |
| CVE-2017-12618 | MED 4.7 | apache portable_runtime_utility Apache Portable Runtime Utility (APR-util) 1.6.0 and prior fail to validate the integrity of SDBM database files used by apr_sdbm*() functions, resulting in a possible out of bound read access. A local user with write access to the database can make a program | 0,6% | — |
| CVE-2014-3185 | MED 6.9 | linux linux_kernel Multiple buffer overflows in the command_port_read_callback function in drivers/usb/serial/whiteheat.c in the Whiteheat USB Serial Driver in the Linux kernel before 3.16.2 allow physically proximate attackers to execute arbitrary code or cause a denial of serv | 0,6% | — |
| CVE-2013-4511 | MED 6.9 | linux linux_kernel Multiple integer overflows in Alchemy LCD frame-buffer drivers in the Linux kernel before 3.12 allow local users to create a read-write memory mapping for the entirety of kernel memory, and consequently gain privileges, via crafted mmap operations, related to | 0,6% | — |
| CVE-2006-1055 | MED 4.9 | linux linux_kernel The fill_write_buffer function in sysfs/file.c in Linux kernel 2.6.12 up to versions before 2.6.17-rc1 does not zero terminate a buffer when a length of PAGE_SIZE or more is requested, which might allow local users to cause a denial of service (crash) by causi | 0,6% | — |
| CVE-2026-72954 | HIGH 7.5 | microsoft windows_10_1607 Use after free in Windows Deployment Services allows an authorized attacker to execute code over a network. | 0,6% | — |
| CVE-2026-56192 | MED 5.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | 0,6% | — |
| CVE-2026-55142 | MED 5.5 | microsoft 365_apps Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | 0,6% | — |