EN
58.306 CVE seguite
790 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.306 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2022-22373 MED 5.4 ibm infosphere_information_server An improper validation vulnerability in IBM InfoSphere Information Server 11.7 Pack for SAP Apps and BW Packs may lead to creation of directories and files on the server file system that may contain non-sensitive debugging information like stack traces. IBM X- 0,5% —
CVE-2022-30151 HIGH 7.0 microsoft windows_10 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability 0,5% —
CVE-2022-24549 HIGH 7.8 microsoft windows_10 Windows AppX Package Manager Elevation of Privilege Vulnerability 0,5% —
CVE-2022-27505 MED 6.1 citrix sd-wan_1000_firmware Reflected cross site scripting (XSS) 0,5% —
CVE-2020-24349 MED 5.5 f5 njs njs through 0.4.3, used in NGINX, allows control-flow hijack in njs_value_property in njs_value.c. NOTE: the vendor considers the issue to be "fluff" in the NGINX use case because there is no remote attack surface. 0,5% —
CVE-2017-0301 HIGH 7.6 f5 big-ip_access_policy_manager In F5 BIG-IP APM software versions 11.5.0, 11.5.1, 11.5.2, 11.5.3, 11.5.4, 11.6.0, 11.6.1, 12.0.0, 12.1.0, 12.1.1 and 12.1.2 BIG-IP APM portal access requests do not return the intended resources in some cases. This may allow access to internal BIG-IP APM reso 0,5% —
CVE-2013-2232 MED 4.9 linux linux_kernel The ip6_sk_dst_check function in net/ipv6/ip6_output.c in the Linux kernel before 3.10 allows local users to cause a denial of service (system crash) by using an AF_INET6 socket for a connection to an IPv4 interface. 0,5% —
CVE-2026-63508 CRIT 10.0 microsoft planetary_computer Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network. 0,5% —
CVE-2026-40412 CRIT 10.0 microsoft azure_orbital_spatio Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attacker to execute code over a network. 0,5% —
CVE-2026-20952 HIGH 8.4 microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 0,5% —
CVE-2025-49553 CRIT 9.3 adobe connect Adobe Connect versions 12.9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute malicious scripts in a victim's browser. Exploitation of this issue requires user interaction in that 0,5% —
CVE-2024-50251 MED 6.2 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_payload: sanitize offset and length before calling skb_checksum() If access to offset + length is larger than the skbuff length, then skb_checksum() triggers BUG_ON(). skb_ch 0,5% —
CVE-2022-42478 HIGH 8.1 fortinet fortisiem An Improper Restriction of Excessive Authentication Attempts [CWE-307] in FortiSIEM below 7.0.0 may allow a non-privileged user with access to several endpoints to brute force attack these endpoints. 0,5% —
CVE-2023-21760 HIGH 7.1 microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability 0,5% —
CVE-2022-41114 HIGH 7.0 microsoft windows_10 Windows Bind Filter Driver Elevation of Privilege Vulnerability 0,5% —
CVE-2021-28129 HIGH 7.8 apache openoffice While working on Apache OpenOffice 4.1.8 a developer discovered that the DEB package did not install using root, but instead used a userid and groupid of 500. This both caused issues with desktop integration and could allow a crafted attack on files owned by t 0,5% —
CVE-2021-33597 LOW 3.5 f-secure business_suite A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the SAVAPI component used in certain F-Secure products can crash while scanning fuzzed files. The exploit can be triggered remotely by an attacker. A successful attack will resul 0,5% —
CVE-2020-11608 MED 4.3 canonical ubuntu_linux An issue was discovered in the Linux kernel before 5.6.1. drivers/media/usb/gspca/ov519.c allows NULL pointer dereferences in ov511_mode_init_regs and ov518_mode_init_regs when there are zero endpoints, aka CID-998912346c0d. 0,5% —
CVE-2019-19047 MED 5.5 canonical ubuntu_linux A memory leak in the mlx5_fw_fatal_reporter_dump() function in drivers/net/ethernet/mellanox/mlx5/core/health.c in the Linux kernel before 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering mlx5_crdump_collect() failures, a 0,5% —
CVE-2019-0030 HIGH 7.2 juniper advanced_threat_prevention_firmware Juniper ATP uses DES and a hardcoded salt for password hashing, allowing for trivial de-hashing of the password file contents. This issue affects Juniper ATP 5.0 versions prior to 5.0.3. 0,5% —
CVE-2015-2150 MED 4.9 linux linux_kernel Xen 3.3.x through 4.5.x and the Linux kernel through 3.19.1 do not properly restrict access to PCI command registers, which might allow local guest OS users to cause a denial of service (non-maskable interrupt and host crash) by disabling the (1) memory or (2) 0,5% —
CVE-2013-4516 MED 4.9 linux linux_kernel The mp_get_count function in drivers/staging/sb105x/sb_pci_mp.c in the Linux kernel before 3.12 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via a TIOCGICOUNT ioctl call. 0,5% —
CVE-2013-2164 LOW 2.1 linux linux_kernel The mmc_ioctl_cdrom_read_data function in drivers/cdrom/cdrom.c in the Linux kernel through 3.10 allows local users to obtain sensitive information from kernel memory via a read operation on a malfunctioning CD-ROM drive. 0,5% —
CVE-2011-4077 MED 6.9 linux linux_kernel Buffer overflow in the xfs_readlink function in fs/xfs/xfs_vnodeops.c in XFS in the Linux kernel 2.6, when CONFIG_XFS_DEBUG is disabled, allows local users to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via an XF 0,5% —
CVE-2009-2977 LOW 3.3 cisco cs-mars The Cisco Security Monitoring, Analysis and Response System (CS-MARS) 6.0.4 and earlier stores cleartext passwords in log/sysbacktrace.## files within error-logs.tar.gz archives, which allows context-dependent attackers to obtain sensitive information by readi 0,5% —