58.306 CVE seguite
790 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.306 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2024-53138 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: kTLS, Fix incorrect page refcounting The kTLS tx handling code is using a mix of get_page() and page_ref_inc() APIs to increment the page reference. But on the release path (mlx5e | 0,5% | — |
| CVE-2024-43644 | HIGH 7.8 | microsoft windows_10_1507 Windows Client-Side Caching Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2024-20278 | MED 6.5 | cisco ios_xe A vulnerability in the NETCONF feature of Cisco IOS XE Software could allow an authenticated, remote attacker to elevate privileges to root on an affected device. This vulnerability is due to improper validation of user-supplied input. An attacker could exp | 0,5% | — |
| CVE-2024-1221 | LOW 3.1 | papercut papercut_mf This vulnerability potentially allows files on a PaperCut NG/MF server to be exposed using a specifically formed payload against the impacted API endpoint. The attacker must carry out some reconnaissance to gain knowledge of a system token. This CVE only affec | 0,5% | — |
| CVE-2024-26583 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tls: fix race between async notify and socket close The submitting thread (one which called recvmsg/sendmsg) may exit as soon as the async crypto handler calls complete() so any code past th | 0,5% | — |
| CVE-2023-20271 | MED 6.5 | cisco evolved_programmable_network_manager A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability i | 0,5% | — |
| CVE-2023-32052 | MED 5.4 | microsoft power_apps Microsoft Power Apps (online) Spoofing Vulnerability | 0,5% | — |
| CVE-2022-41780 | MED 5.5 | f5 f5os-a In F5OS-A version 1.x before 1.1.0 and F5OS-C version 1.x before 1.4.0, a directory traversal vulnerability exists in an undisclosed location of the F5OS CLI that allows an attacker to read arbitrary files. | 0,5% | — |
| CVE-2022-23442 | MED 4.3 | fortinet fortios An improper access control vulnerability [CWE-284] in FortiOS versions 6.2.0 through 6.2.11, 6.4.0 through 6.4.8 and 7.0.0 through 7.0.5 may allow an authenticated attacker with a restricted user profile to gather the checksum information about the other VDOMs | 0,5% | — |
| CVE-2021-42285 | HIGH 7.8 | microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2021-0253 | HIGH 7.8 | juniper junos NFX Series devices using Juniper Networks Junos OS are susceptible to a local command execution vulnerability thereby allowing an attacker to elevate their privileges via the Junos Device Management Daemon (JDMD) process. This issue affects Juniper Networks Ju | 0,5% | — |
| CVE-2021-24102 | HIGH 7.8 | microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2016-3138 | MED 4.6 | canonical ubuntu_linux The acm_probe function in drivers/usb/class/cdc-acm.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a USB device without both a control and a data endpoint de | 0,5% | — |
| CVE-2016-3137 | MED 4.6 | canonical ubuntu_linux drivers/usb/serial/cypress_m8.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a USB device without both an interrupt-in and an interrupt-out endpoint descript | 0,5% | — |
| CVE-2014-7283 | MED 4.9 | linux linux_kernel The xfs_da3_fixhashpath function in fs/xfs/xfs_da_btree.c in the xfs implementation in the Linux kernel before 3.14.2 does not properly compare btree hash values, which allows local users to cause a denial of service (filesystem corruption, and OOPS or panic) | 0,5% | — |
| CVE-2004-2515 | HIGH 7.2 | vmware workstation Format string vulnerability in VMware Workstation 4.5.2 build-8848, if running with elevated privileges, might allow local users to execute arbitrary code via format string specifiers in command line arguments. NOTE: it is not clear if there are any default or | 0,5% | — |
| CVE-2026-77907 | HIGH 8.8 | microsoft visual_studio_2026 Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network. | 0,5% | — |
| CVE-2026-77486 | HIGH 8.8 | microsoft sql_server_2017 Integer overflow or wraparound in SQL Server allows an unauthorized attacker to execute code over a network. | 0,5% | — |
| CVE-2026-69529 | HIGH 8.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network. | 0,5% | — |
| CVE-2026-79048 | HIGH 8.8 | google chrome Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | 0,5% | — |
| CVE-2026-78989 | CRIT 9.6 | google chrome Out of bounds read in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | 0,5% | — |
| CVE-2026-63512 | MED 6.5 | microsoft sharepoint_server Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network. | 0,5% | — |
| CVE-2026-43951 | MED 6.5 | apache http_server Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple response languages. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. | 0,5% | — |
| CVE-2025-37947 | HIGH 8.8 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent out-of-bounds stream writes by validating *pos ksmbd_vfs_stream_write() did not validate whether the write offset (*pos) was within the bounds of the existing stream data leng | 0,5% | — |
| CVE-2025-30383 | HIGH 7.8 | microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0,5% | — |