EN
58.352 CVE seguite
790 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.352 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2021-41370 HIGH 7.8 microsoft windows_10 NTFS Elevation of Privilege Vulnerability 0,5% —
CVE-2021-41367 HIGH 7.8 microsoft windows_10 NTFS Elevation of Privilege Vulnerability 0,5% —
CVE-2021-41366 HIGH 7.8 microsoft windows_10 Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability 0,5% —
CVE-2021-36957 HIGH 7.8 microsoft windows_10 Windows Desktop Bridge Elevation of Privilege Vulnerability 0,5% —
CVE-2021-3564 MED 5.5 debian debian_linux A flaw double-free memory corruption in the Linux kernel HCI device initialization subsystem was found in the way user attach malicious HCI TTY Bluetooth device. A local user could use this flaw to crash the system. This flaw affects all the Linux kernel versi 0,5% —
CVE-2020-5869 CRIT 9.1 f5 big-iq_centralized_management In BIG-IQ 5.2.0-7.0.0, high availability (HA) synchronization is not secure by TLS and may allow on-path attackers to read / modify confidential data in transit. 0,5% —
CVE-2015-8569 LOW 2.3 linux linux_kernel The (1) pptp_bind and (2) pptp_connect functions in drivers/net/ppp/pptp.c in the Linux kernel through 4.3.3 do not verify an address length, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR protection mechanism 0,5% —
CVE-2011-1182 LOW 3.6 linux linux_kernel kernel/signal.c in the Linux kernel before 2.6.39 allows local users to spoof the uid and pid of a signal sender via a sigqueueinfo system call. 0,5% —
CVE-2011-1023 MED 4.9 linux linux_kernel The Reliable Datagram Sockets (RDS) subsystem in the Linux kernel before 2.6.38 does not properly handle congestion map updates, which allows local users to cause a denial of service (BUG_ON and system crash) via vectors involving (1) a loopback (aka loop) tra 0,5% —
CVE-2009-1630 MED 4.4 canonical ubuntu_linux The nfs_permission function in fs/nfs/dir.c in the NFS client implementation in the Linux kernel 2.6.29.3 and earlier, when atomic_open is available, does not check execute (aka EXEC or MAY_EXEC) permission bits, which allows local users to bypass permissions 0,5% —
CVE-2003-1161 HIGH 7.2 linux linux_kernel exit.c in Linux kernel 2.6-test9-CVS, as stored on kernel.bkbits.net, was modified to contain a backdoor, which could allow local users to elevate their privileges by passing __WCLONE|__WALL to the sys_wait4 function. 0,5% —
CVE-2026-58076 HIGH 8.8 apache airflow Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized blob and instantiating it with arguments from the same blob, with no restriction on what could be imported. An operator's 0,5% —
CVE-2026-62915 MED 6.5 microsoft exchange_server Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network. 0,5% —
CVE-2026-67588 HIGH 7.5 apache qpid_protonj2 A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the 0,5% —
CVE-2026-57106 CRIT 10.0 microsoft purview_data_governance Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network. 0,5% —
CVE-2025-71120 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: SUNRPC: svcauth_gss: avoid NULL deref on zero length gss_token in gss_read_proxy_verf A zero length gss_token results in pages == 0 and in_token->pages[0] is NULL. The code unconditionally e 0,5% —
CVE-2026-20859 HIGH 7.8 microsoft windows_11_24h2 Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. 0,5% —
CVE-2025-59232 HIGH 7.1 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 0,5% —
CVE-2025-47857 MED 6.7 fortinet fortiweb A improper neutralization of special elements used in an os command ('os command injection') vulnerability [CWE-78] in Fortinet FortiWeb CLI version 7.6.0 through 7.6.3 and before 7.4.8 allows a privileged attacker to execute arbitrary code or command via craf 0,5% —
CVE-2025-53732 HIGH 7.8 microsoft 365_copilot Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. 0,5% —
CVE-2024-33505 MED 5.6 fortinet fortianalyzer A heap-based buffer overflow in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14 allow 0,5% —
CVE-2024-20675 MED 6.3 microsoft edge_chromium Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability 0,5% —
CVE-2023-27998 MED 5.3 fortinet fortipresence A lack of custom error pages vulnerability [CWE-756] in FortiPresence versions 1.2.0 through 1.2.1 and all versions of 1.1 and 1.0 may allow an unauthenticated attacker with the ability to navigate to the login GUI to gain sensitive information via navigating 0,5% —
CVE-2023-25840 LOW 3.4 esri arcgis_server There is a Cross-site Scripting vulnerability in ArcGIS Server in versions 11.1 and below that may allow a remote, authenticated attacker to create a crafted link which onmouseover wont execute but could potentially render an image in the victims browser.  The 0,5% —
CVE-2023-32053 HIGH 7.8 microsoft windows_10_1507 Windows Installer Elevation of Privilege Vulnerability 0,5% —