58.450 CVE seguite
792 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.450 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-7980 | HIGH 8.8 | google chrome Use after free in WebAudio in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) | 0,5% | — |
| CVE-2026-7928 | HIGH 8.8 | google chrome Use after free in WebRTC in Google Chrome on Windows prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | 0,5% | — |
| CVE-2026-33822 | MED 6.1 | microsoft 365_apps Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | 0,5% | — |
| CVE-2026-34483 | HIGH 7.5 | apache tomcat Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.40 through 9.0.116. Users are recommended t | 0,5% | — |
| CVE-2026-5285 | HIGH 8.8 | google chrome Use after free in WebGL in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | 0,5% | — |
| CVE-2026-5280 | HIGH 8.8 | google chrome Use after free in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | 0,5% | — |
| CVE-2026-5278 | HIGH 8.8 | google chrome Use after free in Web MIDI in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) | 0,5% | — |
| CVE-2025-59355 | MED 6.5 | apache linkis A vulnerability. When org.apache.linkis.metadata.util.HiveUtils.decode() fails to perform Base64 decoding, it records the complete input parameter string in the log via logger.error(str + "decode failed", e). If the input parameter contains sensitive informat | 0,5% | — |
| CVE-2025-62465 | MED 6.5 | microsoft windows_11_23h2 Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally. | 0,5% | — |
| CVE-2025-62463 | MED 6.5 | microsoft windows_10_21h2 Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally. | 0,5% | — |
| CVE-2025-60708 | MED 6.5 | microsoft windows_10_1607 Untrusted pointer dereference in Storvsp.sys Driver allows an authorized attacker to deny service locally. | 0,5% | — |
| CVE-2025-53723 | HIGH 7.8 | microsoft windows_10_1507 Numeric truncation error in Windows Hyper-V allows an authorized attacker to elevate privileges locally. | 0,5% | — |
| CVE-2025-53155 | HIGH 7.8 | microsoft windows_10_1507 Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally. | 0,5% | — |
| CVE-2025-32703 | MED 5.5 | microsoft visual_studio_2017 Insufficient granularity of access control in Visual Studio allows an authorized attacker to disclose information locally. | 0,5% | — |
| CVE-2024-53090 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: afs: Fix lock recursion afs_wake_up_async_call() can incur lock recursion. The problem is that it is called from AF_RXRPC whilst holding the ->notify_lock, but it tries to take a ref on the | 0,5% | — |
| CVE-2024-32761 | MED 6.5 | f5 big-ip_access_policy_manager Under certain conditions, a data leak may occur in the Traffic Management Microkernels (TMMs) of BIG-IP tenants running on VELOS and rSeries platforms. This leak occurs randomly and cannot be deliberately triggered. If it occurs, it may leak up to 64 bytes of | 0,5% | — |
| CVE-2023-38106 | LOW 3.3 | foxit pdf_editor Foxit PDF Reader PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this | 0,5% | — |
| CVE-2023-38105 | LOW 3.3 | foxit pdf_editor Foxit PDF Reader PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this | 0,5% | — |
| CVE-2023-38046 | MED 5.5 | paloaltonetworks pan-os A vulnerability exists in Palo Alto Networks PAN-OS software that enables an authenticated administrator with the privilege to commit a specifically created configuration to read local files and resources from the system. | 0,5% | — |
| CVE-2023-28276 | MED 4.4 | microsoft windows_10_1507 Windows Group Policy Security Feature Bypass Vulnerability | 0,5% | — |
| CVE-2022-22944 | MED 5.4 | vmware workspace_one_boxer VMware Workspace ONE Boxer contains a stored cross-site scripting (XSS) vulnerability. Due to insufficient sanitization and validation, in VMware Workspace ONE Boxer calendar event descriptions, a malicious actor can inject script tags to execute arbitrary scr | 0,5% | — |
| CVE-2014-9584 | LOW 2.1 | canonical ubuntu_linux The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel before 3.18.2 does not validate a length value in the Extensions Reference (ER) System Use Field, which allows local users to obtain sensitive information from kernel memory vi | 0,5% | — |
| CVE-2014-7975 | MED 5.5 | canonical ubuntu_linux The do_umount function in fs/namespace.c in the Linux kernel through 3.17 does not require the CAP_SYS_ADMIN capability for do_remount_sb calls that change the root filesystem to read-only, which allows local users to cause a denial of service (loss of writabi | 0,5% | — |
| CVE-2013-7265 | MED 4.9 | linux linux_kernel The pn_recvmsg function in net/phonet/datagram.c in the Linux kernel before 3.12.4 updates a certain length value before ensuring that an associated data structure has been initialized, which allows local users to obtain sensitive information from kernel stack | 0,5% | — |
| CVE-2013-7263 | MED 4.9 | linux linux_kernel The Linux kernel before 3.12.4 updates certain length values before ensuring that associated data structures have been initialized, which allows local users to obtain sensitive information from kernel stack memory via a (1) recvfrom, (2) recvmmsg, or (3) recvm | 0,5% | — |