58.254 CVE seguite
789 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.254 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2025-59489 | HIGH 7.4 | unity editor Unity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loading of library code from an unintended location. If an application was built with a version of Unity Editor that had the vulnerable Unity Run | 0,6% | — |
| CVE-2025-29811 | HIGH 7.8 | microsoft windows_11_22h2 Improper input validation in Windows Mobile Broadband allows an authorized attacker to elevate privileges locally. | 0,6% | — |
| CVE-2025-1695 | MED 5.3 | f5 nginx_unit In NGINX Unit before version 1.34.2 with the Java Language Module in use, undisclosed requests can lead to an infinite loop and cause an increase in CPU resource utilization. This vulnerability allows a remote attacker to cause a degradation that can lead to | 0,6% | — |
| CVE-2024-49571 | CRIT 9.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/smc: check iparea_offset and ipv6_prefixes_cnt when receiving proposal msg When receiving proposal msg in server, the field iparea_offset and the field ipv6_prefixes_cnt in proposal msg | 0,6% | — |
| CVE-2024-26585 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tls: fix race between tx work scheduling and socket close Similarly to previous commit, the submitting thread (recvmsg/sendmsg) may exit as soon as the async crypto handler calls complete(). | 0,6% | — |
| CVE-2024-21611 | HIGH 7.5 | juniper junos A Missing Release of Memory after Effective Lifetime vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). In a Juniper Flow | 0,6% | — |
| CVE-2023-20186 | HIGH 8.0 | cisco ios A vulnerability in the Authentication, Authorization, and Accounting (AAA) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to bypass command authorization and copy files to or from the file system of an aff | 0,6% | — |
| CVE-2023-41180 | MED 5.9 | apache nifi_minifi_c\+\+ Incorrect certificate validation in InvokeHTTP on Apache NiFi MiNiFi C++ versions 0.13 to 0.14 allows an intermediary to present a forged certificate during TLS handshake negotation. The Disable Peer Verification property of InvokeHTTP was effectively flipped, | 0,6% | — |
| CVE-2023-28237 | HIGH 7.8 | microsoft windows_10_1507 Windows Kernel Remote Code Execution Vulnerability | 0,6% | — |
| CVE-2022-21896 | HIGH 7.0 | microsoft windows_10 Windows DWM Core Library Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2021-41348 | HIGH 8.0 | microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2020-12770 | MED 6.7 | canonical ubuntu_linux An issue was discovered in the Linux kernel through 5.6.11. sg_write lacks an sg_remove_request call in a certain failure case, aka CID-83c6f2390040. | 0,6% | — |
| CVE-2020-5876 | HIGH 8.1 | f5 big-ip_access_policy_manager On BIG-IP 15.0.0-15.0.1.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, a race condition exists where mcpd and other processes may make unencrypted connection attempts to a new configuration sync peer. The race condition can occur wh | 0,6% | — |
| CVE-2018-20169 | MED 6.8 | canonical ubuntu_linux An issue was discovered in the Linux kernel before 4.19.9. The USB subsystem mishandles size checks during the reading of an extra descriptor, related to __usb_get_extra_descriptor in drivers/usb/core/usb.c. | 0,6% | — |
| CVE-2016-3951 | MED 4.6 | canonical ubuntu_linux Double free vulnerability in drivers/net/usb/cdc_ncm.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (system crash) or possibly have unspecified other impact by inserting a USB device with an invalid USB desc | 0,6% | — |
| CVE-2016-3689 | MED 4.6 | canonical ubuntu_linux The ims_pcu_parse_cdc_data function in drivers/input/misc/ims-pcu.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (system crash) via a USB device without both a master and a slave interface. | 0,6% | — |
| CVE-2016-2187 | MED 4.6 | canonical ubuntu_linux The gtco_probe function in drivers/input/tablet/gtco.c in the Linux kernel through 4.5.2 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor. | 0,6% | — |
| CVE-2025-53843 | HIGH 7.5 | fortinet fortios A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions allows attacker to execute unauthorized code or commands via speciall | 0,6% | — |
| CVE-2025-30376 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0,6% | — |
| CVE-2025-30375 | HIGH 7.8 | microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0,6% | — |
| CVE-2025-29957 | MED 6.2 | microsoft windows_10_1507 Uncontrolled resource consumption in Windows Deployment Services allows an unauthorized attacker to deny service locally. | 0,6% | — |
| CVE-2024-21423 | MED 4.8 | microsoft edge_chromium Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | 0,6% | — |
| CVE-2021-39011 | MED 4.2 | ibm cloud_pak_for_security IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.6.0 stores potentially sensitive information in log files that could be read by a privileged user. IBM X-Force ID: 213645. | 0,6% | — |
| CVE-2022-35717 | HIGH 7.8 | ibm infosphere_information_server "IBM InfoSphere Information Server 11.7 could allow a locally authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-"Force ID: 231361. | 0,6% | — |
| CVE-2022-28883 | LOW 3.5 | f-secure atlant A Denial-of-Service (DoS) vulnerability was discovered in F-Secure & WithSecure products whereby the aerdl unpack function crashes. This can lead to a possible scanning engine crash. The exploit can be triggered remotely by an attacker. | 0,6% | — |