58.306 CVE seguite
790 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.306 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-20295 | HIGH 8.6 | A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software and Cisco Secure FTD Software could allow an unauthenticated, remote attacker to exhaust the available memory of an affected device. This vulnerability is due t | 0,5% | — |
| CVE-2026-20250 | HIGH 8.6 | A vulnerability in Datagram TLS (DTLS) message handling of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software for Cisco Secure Firewall 3100 Series and 4200 Series devices could allow an una | 0,5% | — |
| CVE-2026-59279 | HIGH 7.5 | vmware spring_ai The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not place any limit on the number of sessions it retains, and by default does not require clients to be authenticated. As a result, a remote attacker can cause the server to accumulate | 0,5% | — |
| CVE-2026-9071 | HIGH 7.5 | ibm websphere_application_server IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to c | 0,5% | — |
| CVE-2026-24206 | HIGH 7.3 | nvidia triton_inference_server NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of this vulnerability might lead to escalation of privileges, denial of service, or information disclosure. | 0,5% | — |
| CVE-2025-47972 | HIGH 8.0 | microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges over a network. | 0,5% | — |
| CVE-2025-24473 | LOW 3.7 | fortinet forticlient A exposure of sensitive system information to an unauthorized control sphere vulnerability in Fortinet FortiClientWindows 7.2.0 through 7.2.1, FortiClientWindows 7.0.13 through 7.0.14 may allow an unauthorized remote attacker to view application information vi | 0,5% | — |
| CVE-2025-26644 | MED 5.1 | microsoft windows_10_1809 Automated recognition mechanism with inadequate detection or handling of adversarial input perturbations in Windows Hello allows an unauthorized attacker to perform spoofing locally. | 0,5% | — |
| CVE-2025-21287 | HIGH 7.8 | microsoft windows_10_1507 Windows Installer Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2024-20493 | MED 5.3 | cisco adaptive_security_appliance_software A vulnerability in the login authentication functionality of the Remote Access SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to deny further | 0,5% | — |
| CVE-2023-36724 | MED 5.5 | microsoft windows_10_1507 Windows Power Management Service Information Disclosure Vulnerability | 0,5% | — |
| CVE-2022-22401 | MED 5.9 | ibm aspera_faspex IBM Aspera Faspex 5.0.5 could allow a remote attacker to gather or persuade a naive user to supply sensitive information. IBM X-Force ID: 222567. | 0,5% | — |
| CVE-2023-1206 | MED 5.7 | fedoraproject fedora A hash collision flaw was found in the IPv6 connection lookup table in the Linux kernel’s IPv6 functionality when a user makes a new kind of SYN flood attack. A user located in the local network or with a high bandwidth connection can increase the CPU usage of | 0,5% | — |
| CVE-2023-29359 | HIGH 7.8 | microsoft windows_10_1507 GDI Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2022-24530 | HIGH 7.8 | microsoft windows_10 Windows Installer Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2021-45469 | HIGH 7.8 | debian debian_linux In __f2fs_setxattr in fs/f2fs/xattr.c in the Linux kernel through 5.15.11, there is an out-of-bounds memory access when an inode has an invalid last xattr entry. | 0,5% | — |
| CVE-2020-36386 | HIGH 7.1 | linux linux_kernel An issue was discovered in the Linux kernel before 5.8.1. net/bluetooth/hci_event.c has a slab out-of-bounds read in hci_extended_inquiry_result_evt, aka CID-51c19bf3d5cf. | 0,5% | — |
| CVE-2015-5283 | MED 4.7 | linux linux_kernel The sctp_init function in net/sctp/protocol.c in the Linux kernel before 4.2.3 has an incorrect sequence of protocol-initialization steps, which allows local users to cause a denial of service (panic or memory corruption) by creating SCTP sockets before all of | 0,5% | — |
| CVE-2004-1387 | LOW 2.1 | apache http_server The check_forensic script in apache-utils package 1.3.31 allows local users to overwrite or create arbitrary files via a symlink attack on temporary files. | 0,5% | — |
| CVE-2026-66321 | HIGH 7.4 | microsoft edge_chromium Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0,5% | — |
| CVE-2026-64113 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ixgbevf: fix use-after-free in VEPA multicast source pruning ixgbevf_clean_rx_irq() prunes frames whose source MAC matches the VF's own address (VEPA multicast workaround) by freeing the skb | 0,5% | — |
| CVE-2026-9639 | MED 6.5 | canonical lxd Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticated user with can_create_storage_volumes permissions to cause a denial of service via a specially crafted custom-volume backup tarball that o | 0,5% | — |
| CVE-2025-14728 | MED 6.8 | rapid7 velociraptor Rapid7 Velociraptor versions before 0.75.6 contain a directory traversal issue on Linux servers that allows a rogue client to upload a file which is written outside the datastore directory. Velociraptor is normally only allowed to write in the datastore direct | 0,5% | — |
| CVE-2025-55683 | MED 5.5 | microsoft windows_server_2016 Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally. | 0,5% | — |
| CVE-2025-43576 | HIGH 7.8 | adobe acrobat Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction i | 0,5% | — |