58.306 CVE seguite
789 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.306 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2025-30330 | HIGH 7.8 | adobe illustrator Illustrator versions 29.3, 28.7.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim mus | 0,6% | — |
| CVE-2025-29955 | MED 6.2 | microsoft windows_11_24h2 Improper input validation in Windows Hyper-V allows an unauthorized attacker to deny service locally. | 0,6% | — |
| CVE-2020-3525 | MED 4.3 | cisco identity_services_engine A vulnerability in the Admin portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to recover service account passwords that are saved on an affected system. The vulnerability is due to the incorrect inclusion of sa | 0,6% | — |
| CVE-2023-25922 | MED 4.3 | ibm security_guardium_key_lifecycle_manager IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment. IBM X-Force ID: 247621. | 0,6% | — |
| CVE-2022-33981 | LOW 3.3 | debian debian_linux drivers/block/floppy.c in the Linux kernel before 5.17.6 is vulnerable to a denial of service, because of a concurrency use-after-free flaw after deallocating raw_cmd in the raw_cmd_ioctl function. | 0,6% | — |
| CVE-2021-43070 | MED 5.4 | fortinet fortiwlm Multiple relative path traversal vulnerabilities [CWE-23] in FortiWLM management interface 8.6.2 and below, 8.5.2 and below, 8.4.2 and below, 8.3.3 and below, 8.2.2 may allow an authenticated attacker to retrieve arbitrary files from the underlying filesystem | 0,6% | — |
| CVE-2021-0247 | MED 5.1 | juniper junos A Race Condition (Concurrent Execution using Shared Resource with Improper Synchronization) vulnerability in the firewall process (dfwd) of Juniper Networks Junos OS allows an attacker to bypass the firewall rule sets applied to the input loopback filter on an | 0,6% | — |
| CVE-2021-27096 | HIGH 7.8 | microsoft windows_10 NTFS Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2021-27091 | HIGH 7.8 | microsoft windows_7 RPC Endpoint Mapper Service Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2021-26931 | MED 5.5 | debian debian_linux An issue was discovered in the Linux kernel 2.6.39 through 5.10.16, as used in Xen. Block, net, and SCSI backends consider certain errors a plain bug, deliberately causing a kernel crash. For errors potentially being at least under the influence of guests (suc | 0,6% | — |
| CVE-2020-3456 | HIGH 8.8 | cisco firepower_extensible_operating_system A vulnerability in the Cisco Firepower Chassis Manager (FCM) of Cisco FXOS Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of an affected device. The vulnerability is due to insuffic | 0,6% | — |
| CVE-2019-19045 | MED 4.4 | canonical ubuntu_linux A memory leak in the mlx5_fpga_conn_create_cq() function in drivers/net/ethernet/mellanox/mlx5/core/fpga/conn.c in the Linux kernel before 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering mlx5_vector2eqn() failures, aka C | 0,6% | — |
| CVE-2018-10124 | MED 5.5 | canonical ubuntu_linux The kill_something_info function in kernel/signal.c in the Linux kernel before 4.13, when an unspecified architecture and compiler is used, might allow local users to cause a denial of service via an INT_MIN argument. | 0,6% | — |
| CVE-2017-14497 | HIGH 7.8 | debian debian_linux The tpacket_rcv function in net/packet/af_packet.c in the Linux kernel before 4.13 mishandles vnet headers, which might allow local users to cause a denial of service (buffer overflow, and disk and memory corruption) or possibly have unspecified other impact v | 0,6% | — |
| CVE-2017-3803 | MED 4.7 | cisco ios A vulnerability in the Cisco IOS Software forwarding queue of Cisco 2960X and 3750X switches could allow an unauthenticated, adjacent attacker to cause a memory leak in the software forwarding queue that would eventually lead to a partial denial of service (Do | 0,6% | — |
| CVE-2013-0913 | HIGH 7.2 | linux linux_kernel Integer overflow in drivers/gpu/drm/i915/i915_gem_execbuffer.c in the i915 driver in the Direct Rendering Manager (DRM) subsystem in the Linux kernel through 3.8.3, as used in Google Chrome OS before 25.0.1364.173 and other products, allows local users to caus | 0,6% | — |
| CVE-2012-2313 | LOW 1.2 | linux linux_kernel The rio_ioctl function in drivers/net/ethernet/dlink/dl2k.c in the Linux kernel before 3.3.7 does not restrict access to the SIOCSMIIREG command, which allows local users to write data to an Ethernet adapter via an ioctl call. | 0,6% | — |
| CVE-2007-6151 | HIGH 7.2 | linux linux_kernel The isdn_ioctl function in isdn_common.c in Linux kernel 2.6.23 allows local users to cause a denial of service via a crafted ioctl struct in which iocts is not null terminated, which triggers a buffer overflow. | 0,6% | — |
| CVE-2026-82011 | CRIT 9.1 | adobe campaign Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to byp | 0,6% | — |
| CVE-2026-69782 | HIGH 8.1 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in DNS Server allows an unauthorized attacker to execute code over a network. | 0,6% | — |
| CVE-2026-40370 | HIGH 8.8 | microsoft sql_server_2016 External control of file name or path in SQL Server allows an authorized attacker to execute code over a network. | 0,6% | — |
| CVE-2026-33118 | MED 4.3 | microsoft edge_chromium User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | 0,6% | — |
| CVE-2025-47989 | HIGH 7.0 | microsoft azure_connected_machine_agent Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally. | 0,6% | — |
| CVE-2025-26639 | HIGH 7.8 | microsoft windows_10_21h2 Integer overflow or wraparound in Windows USB Print Driver allows an authorized attacker to elevate privileges locally. | 0,6% | — |
| CVE-2024-46958 | CRIT 9.1 | nextcloud desktop In Nextcloud Desktop Client 3.13.1 through 3.13.3 on Linux, synchronized files (between the server and client) may become world writable or world readable. This is fixed in 3.13.4. | 0,6% | — |