EN
58.352 CVE seguite
790 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.352 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2021-20455 LOW 3.7 ibm cognos_controller IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against th 0,5% —
CVE-2024-2551 HIGH 7.5 paloaltonetworks pan-os A null pointer dereference vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to stop a core system service on the firewall by sending a crafted packet through the data plane that causes a denial of service (DoS) condition. 0,5% —
CVE-2024-41879 HIGH 7.8 adobe acrobat_reader Acrobat Reader versions 127.0.2651.105 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must 0,5% —
CVE-2021-47496 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/tls: Fix flipped sign in tls_err_abort() calls sk->sk_err appears to expect a positive value, a convention that ktls doesn't always follow and that leads to memory corruption in other co 0,5% —
CVE-2024-28923 MED 6.4 microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability 0,5% —
CVE-2023-20223 HIGH 8.6 cisco dna_center A vulnerability in Cisco DNA Center could allow an unauthenticated, remote attacker to read and modify data in a repository that belongs to an internal service on an affected device. This vulnerability is due to insufficient access control enforcement on AP 0,5% —
CVE-2023-20188 MED 4.8 cisco sf200-24_firmware A vulnerability in the web-based management interface of Cisco Small Business 200 Series Smart Switches, Cisco Small Business 300 Series Managed Switches, and Cisco Small Business 500 Series Stackable Managed Switches could allow an authenticated, remote attac 0,5% —
CVE-2011-4917 MED 5.5 linux linux_kernel In the Linux kernel through 3.1 there is an information disclosure issue via /proc/stat. 0,5% —
CVE-2020-11668 HIGH 7.1 linux linux_kernel In the Linux kernel before 5.6.1, drivers/media/usb/gspca/xirlink_cit.c (aka the Xirlink camera USB driver) mishandles invalid descriptors, aka CID-a246b4d54770. 0,5% —
CVE-2019-6687 HIGH 7.4 f5 big-ip_application_security_manager On versions 15.0.0-15.0.1.1, the BIG-IP ASM Cloud Security Services profile uses a built-in verification mechanism that fails to properly authenticate the X.509 certificate of remote endpoints. 0,5% —
CVE-2017-12301 MED 6.7 cisco nx-os A vulnerability in the Python scripting subsystem of Cisco NX-OS Software could allow an authenticated, local attacker to escape the Python parser and gain unauthorized access to the underlying operating system of the device. The vulnerability exists due to in 0,5% —
CVE-2016-4565 HIGH 7.8 canonical ubuntu_linux The InfiniBand (aka IB) stack in the Linux kernel before 4.5.3 incorrectly relies on the write system call, which allows local users to cause a denial of service (kernel memory write operation) or possibly have unspecified other impact via a uAPI interface. 0,5% —
CVE-2015-4224 HIGH 7.2 cisco wireless_lan_controller_software Cisco Wireless LAN Controller (WLC) devices with software 7.0(240.0) allow local users to execute arbitrary OS commands in a privileged context via crafted CLI commands, aka Bug ID CSCuj39474. 0,5% —
CVE-2015-4106 MED 4.6 canonical ubuntu_linux QEMU does not properly restrict write access to the PCI config space for certain PCI pass-through devices, which might allow local x86 HVM guests to gain privileges, cause a denial of service (host crash), obtain sensitive information, or possibly have other u 0,5% —
CVE-2011-2495 LOW 2.1 linux linux_kernel fs/proc/base.c in the Linux kernel before 2.6.39.4 does not properly restrict access to /proc/#####/io files, which allows local users to obtain sensitive I/O statistics by polling a file, as demonstrated by discovering the length of another user's password. 0,5% —
CVE-2010-2962 HIGH 7.2 canonical ubuntu_linux drivers/gpu/drm/i915/i915_gem.c in the Graphics Execution Manager (GEM) in the Intel i915 driver in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 2.6.36 does not properly validate pointers to blocks of memory, which allows local users 0,5% —
CVE-2026-64607 MED 5.3 apache httpclient HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message. Please note this defect does not a 0,5% —
CVE-2026-57101 HIGH 7.1 microsoft visual_studio_code Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. 0,5% —
CVE-2026-55139 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. 0,5% —
CVE-2026-43074 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: eventpoll: defer struct eventpoll free to RCU grace period In certain situations, ep_free() in eventpoll.c will kfree the epi->ep eventpoll struct while it still being used by another concur 0,5% —
CVE-2026-20941 HIGH 7.8 microsoft windows_11_24h2 Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally. 0,5% —
CVE-2026-20936 MED 4.3 microsoft windows_10_1607 Out-of-bounds read in Windows NDIS allows an authorized attacker to disclose information with a physical attack. 0,5% —
CVE-2026-21860 MED 5.3 palletsprojects werkzeug Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.5, Werkzeug's safe_join function allows path segments with Windows device names that have file extensions or trailing spaces. On Windows, there are special device names such as CON, 0,5% —
CVE-2025-20350 HIGH 7.5 cisco desk_phone_9841_firmware A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 running Cisco SIP Software could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vu 0,5% —
CVE-2025-54915 MED 6.7 microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally. 0,5% —