58.304 CVE seguite
789 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.304 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2015-8953 | MED 5.5 | linux linux_kernel fs/overlayfs/copy_up.c in the Linux kernel before 4.2.6 uses an incorrect cleanup code path, which allows local users to cause a denial of service (dentry reference leak) via filesystem operations on a large file in a lower overlayfs layer. | 0,6% | — |
| CVE-2005-0124 | LOW 2.1 | linux linux_kernel The coda_pioctl function in the coda functionality (pioctl.c) for Linux kernel 2.6.9 and 2.4.x before 2.4.29 may allow local users to cause a denial of service (crash) or execute arbitrary code via negative vi.in_size or vi.out_size values, which may trigger a | 0,6% | — |
| CVE-2002-1233 | LOW 2.6 | apache http_server A regression error in the Debian distributions of the apache-ssl package (before 1.3.9 on Debian 2.2, and before 1.3.26 on Debian 3.0), for Apache 1.3.27 and earlier, allows local users to read or modify the Apache password file via a symlink attack on tempora | 0,6% | — |
| CVE-2026-69416 | MED 5.7 | microsoft windows_10_1607 Buffer over-read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network. | 0,6% | — |
| CVE-2026-69405 | MED 5.7 | microsoft windows_10_1607 Missing release of memory after effective lifetime in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network. | 0,6% | — |
| CVE-2026-76986 | MED 6.1 | apache wicket Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicket.markup.html.form.AbstractSingleSelectChoice, the base class of DropDownChoice, writes the body of the default option — the entry shown when no choice is selected — | 0,6% | — |
| CVE-2026-50481 | CRIT 9.9 | microsoft azure_active_directory Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. | 0,6% | — |
| CVE-2026-50528 | HIGH 8.2 | microsoft .net Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network. | 0,6% | — |
| CVE-2026-54475 | HIGH 7.5 | apache activemq Missing Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Apache ActiveMQ Classic temporary destinations are expected to be isolated to the connection that created them. The isolation can be broken as this is only ch | 0,6% | — |
| CVE-2026-43037 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() Oskar Kjos reported the following problem. ip4ip6_err() calls icmp_send() on a cloned skb whose cb[] was written by the IPv6 receive path as str | 0,6% | — |
| CVE-2026-26149 | CRIT 9.0 | microsoft power_apps Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to perform spoofing over a network. | 0,6% | — |
| CVE-2025-64660 | HIGH 8.0 | microsoft visual_studio_code Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to execute code over a network. | 0,6% | — |
| CVE-2025-47181 | HIGH 8.8 | microsoft edge_update Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally. | 0,6% | — |
| CVE-2023-36888 | MED 6.3 | microsoft edge_chromium Microsoft Edge for Android (Chromium-based) Tampering Vulnerability | 0,6% | — |
| CVE-2023-28962 | MED 5.3 | juniper junos An Improper Authentication vulnerability in upload-file.php, used by the J-Web component of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to upload arbitrary files to temporary folders on the device. This issue affects Juniper Net | 0,6% | — |
| CVE-2023-22396 | HIGH 7.5 | juniper junos An Uncontrolled Resource Consumption vulnerability in TCP processing on the Routing Engine (RE) of Juniper Networks Junos OS allows an unauthenticated network-based attacker to send crafted TCP packets destined to the device, resulting in an MBUF leak that ult | 0,6% | — |
| CVE-2022-29057 | MED 5.4 | fortinet fortiedr A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiEDR version 5.1.0, 5.0.0 through 5.0.3 Patch 6 and 4.0.0 allows a remote authenticated attacker to perform a reflected cross site scripting attack (XSS) by | 0,6% | — |
| CVE-2021-40455 | MED 5.5 | microsoft windows_10 Windows Installer Spoofing Vulnerability | 0,6% | — |
| CVE-2021-40832 | MED 5.5 | f-secure atlant A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the AVRDL unpacking module component used in certain F-Secure products can crash while scanning a fuzzed files. The exploit can be triggered remotely by an attacker. A successful | 0,6% | — |
| CVE-2021-33603 | MED 5.5 | f-secure atlant A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the AVPACK module component used in certain F-Secure products can crash while scanning a fuzzed files. The exploit can be triggered remotely by an attacker. A successful attack w | 0,6% | — |
| CVE-2021-22000 | HIGH 7.8 | vmware thinapp VMware Thinapp version 5.x prior to 5.2.10 contain a DLL hijacking vulnerability due to insecure loading of DLLs. A malicious actor with non-administrative privileges may exploit this vulnerability to elevate privileges to administrator level on the Windows op | 0,6% | — |
| CVE-2021-24005 | MED 4.0 | fortinet fortiauthenticator Usage of hard-coded cryptographic keys to encrypt configuration files and debug logs in FortiAuthenticator versions before 6.3.0 may allow an attacker with access to the files or the CLI configuration to decrypt the sensitive data, via knowledge of the hard-co | 0,6% | — |
| CVE-2021-27088 | HIGH 7.8 | microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2020-14331 | MED 6.6 | linux linux_kernel A flaw was found in the Linux kernel’s implementation of the invert video code on VGA consoles when a local attacker attempts to resize the console, calling an ioctl VT_RESIZE, which causes an out-of-bounds write to occur. This flaw allows a local user with ac | 0,6% | — |
| CVE-2019-17653 | HIGH 8.8 | fortinet fortisiem A Cross-Site Request Forgery (CSRF) vulnerability in the user interface of Fortinet FortiSIEM 5.2.5 could allow a remote, unauthenticated attacker to perform arbitrary actions using an authenticated user's session by persuading the victim to follow a malicious | 0,6% | — |