58.352 CVE seguite
792 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.352 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-82434 | MED 6.5 | Description When ZooKeeper authentication is configured, Storm deliberately retains `storm.zookeeper.topology.auth.payload` in the topology configuration, because workers need it. Nimbus then served that configuration verbatim to any caller holding read-only | 0,5% | — |
| CVE-2026-62742 | MED 6.5 | microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. | 0,5% | — |
| CVE-2026-62718 | MED 6.5 | microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. | 0,5% | — |
| CVE-2026-62715 | MED 6.5 | microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. | 0,5% | — |
| CVE-2026-33582 | MED 6.5 | apache answer Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the | 0,5% | — |
| CVE-2026-42930 | HIGH 8.7 | f5 big-ip_access_policy_manager When running in Appliance mode, an authenticated attacker assigned the 'Administrator' role may be able to bypass Appliance mode restrictions on a BIG-IP system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0,5% | — |
| CVE-2026-5860 | HIGH 8.8 | google chrome Use after free in WebRTC in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | 0,5% | — |
| CVE-2026-22732 | CRIT 9.1 | vmware spring_security When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written. This issue affects Spring Security Servlet applications using lazy (default) writing of HTTP He | 0,5% | — |
| CVE-2025-12382 | HIGH 8.8 | algosec firewall_analyzer Improper Limitation of a Pathname 'Path Traversal') vulnerability in Algosec Firewall Analyzer on Linux, 64 bit allows an authenticated user to upload files to a restricted directory leading to code injection. This issue affects Algosec Firewall Analyzer: A33. | 0,5% | — |
| CVE-2025-25004 | HIGH 7.3 | microsoft powershell Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges locally. | 0,5% | — |
| CVE-2024-20299 | MED 5.8 | cisco adaptive_security_appliance_software A vulnerability in the AnyConnect firewall for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access control list (ACL) and allow traffic | 0,5% | — |
| CVE-2024-20297 | MED 5.8 | cisco adaptive_security_appliance_software A vulnerability in the AnyConnect firewall for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access control list (ACL) and allow traffic | 0,5% | — |
| CVE-2024-38157 | HIGH 7.0 | microsoft azure_iot_hub_device_client_sdk Azure IoT SDK Remote Code Execution Vulnerability | 0,5% | — |
| CVE-2022-35762 | HIGH 7.8 | microsoft windows_10 Storage Spaces Direct Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2021-24012 | MED 6.5 | fortinet fortios An improper following of a certificate's chain of trust vulnerability in FortiGate versions 6.4.0 to 6.4.4 may allow an LDAP user to connect to SSLVPN with any certificate that is signed by a trusted Certificate Authority. | 0,5% | — |
| CVE-2021-28460 | HIGH 8.1 | microsoft azure_sphere Azure Sphere Unsigned Code Execution Vulnerability | 0,5% | — |
| CVE-2020-4363 | HIGH 7.8 | ibm db2 IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code on the system with root privil | 0,5% | — |
| CVE-2019-20406 | HIGH 7.8 | atlassian confluence The usage of Tomcat in Confluence on the Microsoft Windows operating system before version 7.0.5, and from version 7.1.0 before version 7.1.1 allows local system attackers who have permission to write a DLL file in a directory in the global path environmental | 0,5% | — |
| CVE-2017-17558 | MED 6.6 | linux linux_kernel The usb_destroy_configuration function in drivers/usb/core/config.c in the USB core subsystem in the Linux kernel through 4.14.5 does not consider the maximum number of configurations and interfaces before attempting to release resources, which allows local us | 0,5% | — |
| CVE-2017-8924 | MED 4.6 | debian debian_linux The edge_bulk_in_callback function in drivers/usb/serial/io_ti.c in the Linux kernel before 4.10.4 allows local users to obtain sensitive information (in the dmesg ringbuffer and syslog) from uninitialized kernel memory by using a crafted USB device (posing as | 0,5% | — |
| CVE-2016-4805 | HIGH 7.8 | canonical ubuntu_linux Use-after-free vulnerability in drivers/net/ppp/ppp_generic.c in the Linux kernel before 4.5.2 allows local users to cause a denial of service (memory corruption and system crash, or spinlock) or possibly have unspecified other impact by removing a network nam | 0,5% | — |
| CVE-2015-1333 | MED 4.9 | linux linux_kernel Memory leak in the __key_link_end function in security/keys/keyring.c in the Linux kernel before 4.1.4 allows local users to cause a denial of service (memory consumption) via many add_key system calls that refer to existing keys. | 0,5% | — |
| CVE-2013-7281 | MED 4.9 | linux linux_kernel The dgram_recvmsg function in net/ieee802154/dgram.c in the Linux kernel before 3.12.4 updates a certain length value without ensuring that an associated data structure has been initialized, which allows local users to obtain sensitive information from kernel | 0,5% | — |
| CVE-2013-7271 | MED 4.9 | linux linux_kernel The x25_recvmsg function in net/x25/af_x25.c in the Linux kernel before 3.12.4 updates a certain length value without ensuring that an associated data structure has been initialized, which allows local users to obtain sensitive information from kernel memory v | 0,5% | — |
| CVE-2013-7270 | MED 4.9 | linux linux_kernel The packet_recvmsg function in net/packet/af_packet.c in the Linux kernel before 3.12.4 updates a certain length value before ensuring that an associated data structure has been initialized, which allows local users to obtain sensitive information from kernel | 0,5% | — |