58.290 CVE seguite
789 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.290 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-52998 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_osf: fix potential NULL dereference in ttl check The nf_osf_ttl() function accessed skb->dev to perform a local interface address lookup without verifying that the devic | 0,6% | — |
| CVE-2026-8992 | HIGH 8.8 | ivanti secure_access_client An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remote unauthenticated attacker to execute arbitrary code. | 0,6% | — |
| CVE-2025-53844 | HIGH 8.8 | fortinet fortios A out-of-bounds write vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11 allows attacker to execute unauthorized code or commands via specially crafted packets. | 0,6% | — |
| CVE-2026-20835 | MED 5.5 | microsoft windows_11_24h2 Out-of-bounds read in Capability Access Management Service (camsvc) allows an authorized attacker to disclose information locally. | 0,6% | — |
| CVE-2026-20829 | MED 5.5 | microsoft windows_10_1809 Out-of-bounds read in Windows TPM allows an authorized attacker to disclose information locally. | 0,6% | — |
| CVE-2025-26631 | HIGH 7.3 | microsoft visual_studio_code Uncontrolled search path element in Visual Studio Code allows an authorized attacker to elevate privileges locally. | 0,6% | — |
| CVE-2025-21378 | HIGH 7.8 | microsoft windows_10_1507 Windows CSC Service Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2024-53095 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: client: Fix use-after-free of network namespace. Recently, we got a customer report that CIFS triggers oops while reconnecting to a server. [0] The workload runs on Kubernetes, and so | 0,6% | — |
| CVE-2024-50185 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mptcp: handle consistently DSS corruption Bugged peer implementation can send corrupted DSS options, consistently hitting a few warning in the data path. Use DEBUG_NET assertions, to avoid t | 0,6% | — |
| CVE-2024-44970 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: SHAMPO, Fix invalid WQ linked list unlink When all the strides in a WQE have been consumed, the WQE is unlinked from the WQ linked list (mlx5_wq_ll_pop()). For SHAMPO, it is possi | 0,6% | — |
| CVE-2023-38150 | HIGH 7.8 | microsoft windows_11_21h2 Windows Kernel Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2023-4147 | HIGH 7.8 | debian debian_linux A use-after-free flaw was found in the Linux kernel’s Netfilter functionality when adding a rule with NFTA_RULE_CHAIN_ID. This flaw allows a local user to crash or escalate their privileges on the system. | 0,6% | — |
| CVE-2023-21739 | HIGH 7.0 | microsoft windows_10_1507 Windows Bluetooth Driver Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2022-38457 | MED 6.3 | linux linux_kernel A use-after-free(UAF) vulnerability was found in function 'vmw_cmd_res_check' in drivers/gpu/vmxgfx/vmxgfx_execbuf.c in Linux kernel's vmwgfx driver with device file '/dev/dri/renderD128 (or Dxxx)'. This flaw allows a local attacker with a user account on the | 0,6% | — |
| CVE-2021-39016 | MED 4.3 | ibm engineering_lifecycle_optimization_-_publishing IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 does not sufficiently monitor or control transmitted network traffic volume, so that an actor can cause the software to transmit more traffic than should be allowed for t | 0,6% | — |
| CVE-2022-20765 | MED 4.8 | cisco ucs_director A vulnerability in the web applications of Cisco UCS Director could allow an authenticated, remote attacker to conduct a cross-site scripting attack on an affected system. This vulnerability is due to unsanitized user input. An attacker could exploit this vuln | 0,6% | — |
| CVE-2021-34460 | HIGH 7.8 | microsoft windows_10 Windows Storage Spaces Controller Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2021-34511 | HIGH 7.8 | microsoft windows_10 Windows Installer Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2021-34488 | HIGH 7.8 | microsoft windows_10 Windows Console Driver Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2021-34477 | HIGH 7.8 | microsoft .net_education_bundle_sdk_install_tool Visual Studio Code .NET Runtime Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2020-5025 | HIGH 7.8 | ibm db2 IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 db2fm is vulnerable to a buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code on the system with root | 0,6% | — |
| CVE-2021-1218 | MED 5.4 | cisco smart_software_manager_on-prem A vulnerability in the web management interface of Cisco Smart Software Manager satellite could allow an authenticated, remote attacker to redirect a user to an undesired web page. The vulnerability is due to improper input validation of the URL parameters in | 0,6% | — |
| CVE-2020-3314 | MED 6.1 | cisco advanced_malware_protection_for_endpoints A vulnerability in the file scan process of Cisco AMP for Endpoints Mac Connector Software could cause the scan engine to crash during the scan of local files, resulting in a restart of the AMP Connector and a denial of service (DoS) condition of the Cisco AMP | 0,6% | — |
| CVE-2018-19824 | HIGH 7.8 | canonical ubuntu_linux In the Linux kernel through 4.19.6, a local user could exploit a use-after-free in the ALSA driver by supplying a malicious USB Sound device (with zero interfaces) that is mishandled in usb_audio_probe in sound/usb/card.c. | 0,6% | — |
| CVE-2018-0306 | HIGH 7.8 | cisco nx-os A vulnerability in the CLI parser of Cisco NX-OS Software could allow an authenticated, local attacker to perform a command-injection attack on an affected device. The vulnerability is due to insufficient input validation of command arguments. An attacker coul | 0,6% | — |