EN
58.306 CVE seguite
790 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.306 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2014-9644 LOW 2.1 canonical ubuntu_linux The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a parenthesized module template expression in the salg_name field, as demonstrated by the vfat(aes) expression 0,6% —
CVE-2026-55971 CRIT 9.8 apache thrift Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. 0,6% —
CVE-2026-23663 HIGH 7.5 microsoft global_secure_access Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network. 0,6% —
CVE-2026-44277 CRIT 9.8 fortinet fortiauthenticator A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, FortiAuthenticator 6.5.0 through 6.5.6 may allow attacker to execute unauthorized code or commands via crafted reque 0,6% —
CVE-2026-32177 HIGH 7.3 microsoft .net Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally. 0,6% —
CVE-2026-3087 HIGH 7.5 python python If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then the archive will be extracted outside the target directory which is different than other operating systems. Only Windows is affected by this v 0,6% —
CVE-2026-26139 HIGH 8.6 microsoft purview Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network. 0,6% —
CVE-2026-20819 MED 5.5 microsoft windows_11_23h2 Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally. 0,6% —
CVE-2024-20492 MED 6.0 cisco telepresence_video_communication_server A vulnerability in the restricted shell of Cisco Expressway Series could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, the attacker 0,6% —
CVE-2024-46865 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: fou: fix initialization of grc The grc must be initialize first. There can be a condition where if fou is NULL, goto out will be executed and grc would be used uninitialized. 0,6% —
CVE-2024-21339 MED 6.4 microsoft windows_10_1809 Windows USB Generic Parent Driver Remote Code Execution Vulnerability 0,6% —
CVE-2021-43975 MED 6.7 debian debian_linux In the Linux kernel through 5.15.2, hw_atl_utils_fw_rpc_wait in drivers/net/ethernet/aquantia/atlantic/hw_atl/hw_atl_utils.c allows an attacker (who can introduce a crafted device) to trigger an out-of-bounds write via a crafted length value. 0,6% —
CVE-2020-8607 MED 6.7 trendmicro antivirus_toolkit An input validation vulnerability found in multiple Trend Micro products utilizing a particular version of a specific rootkit protection driver could allow an attacker in user-mode with administrator permissions to abuse the driver to modify a kernel address t 0,6% —
CVE-2019-19807 HIGH 7.8 canonical ubuntu_linux In the Linux kernel before 5.3.11, sound/core/timer.c has a use-after-free caused by erroneous code refactoring, aka CID-e7af6307a8a5. This is related to snd_timer_open and snd_timer_close_locked. The timeri variable was originally intended to be for a newly c 0,6% —
CVE-2018-15594 MED 5.5 canonical ubuntu_linux arch/x86/kernel/paravirt.c in the Linux kernel before 4.18.1 mishandles certain indirect calls, which makes it easier for attackers to conduct Spectre-v2 attacks against paravirtual guests. 0,6% —
CVE-2013-6381 MED 6.9 linux linux_kernel Buffer overflow in the qeth_snmp_command function in drivers/s390/net/qeth_core_main.c in the Linux kernel through 3.12.1 allows local users to cause a denial of service or possibly have unspecified other impact via an SNMP ioctl call with a length value that 0,6% —
CVE-2007-1388 MED 4.4 linux linux_kernel The do_ipv6_setsockopt function in net/ipv6/ipv6_sockglue.c in Linux kernel before 2.6.20, and possibly other versions, allows local users to cause a denial of service (oops) by calling setsockopt with the IPV6_RTHDR option name and possibly a zero option leng 0,6% —
CVE-2026-20342 HIGH 7.7 A vulnerability in a specific file download API of Cisco Secure FMC Software could allow an authenticated, remote attacker to download arbitrary files from an affected system. This vulnerability exists because user input is not being sanitized. An attacker 0,5% —
CVE-2026-13476 HIGH 7.3 ibm informix_dynamic_server IBM Informix Dynamic Server 14.10, 15.0, and 12.10 could allow an unauthenticated user to execute arbitrary commands with service account privileges on the system due to improper validation of user supplied input. 0,5% —
CVE-2026-66803 CRIT 10.0 microsoft azure_cosmos_db Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network. 0,5% —
CVE-2026-50659 MED 6.5 microsoft .net Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network. 0,5% —
CVE-2026-46591 HIGH 8.2 apache camel Improper Neutralization of Special Elements in Data Query Logic vulnerability in Apache Camel Neo4J component. The camel-neo4j producer builds the Cypher WHERE clause for its match/retrieve and delete operations from the CamelNeo4jMatchProperties map. CVE-202 0,5% —
CVE-2026-45172 HIGH 8.8 paloaltonetworks idira_privileged_session_manager_for_ssh Due to incomplete input validation in Idira Privileged Session Manager for SSH (PSMP) versions prior to 15.0.2, 14.6.3, 14.2.5, and 14.0.6, an authenticated, low-privileged user could potentially execute arbitrary commands on the PSMP host. CyberArk Security B 0,5% —
CVE-2026-48563 HIGH 7.5 microsoft windows_10_1809 Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. 0,5% —
CVE-2026-47654 HIGH 7.5 microsoft windows_server_2016 Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. 0,5% —