58.450 CVE seguite
793 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.450 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-20135 | HIGH 8.6 | A vulnerability in the TLS 1.3 implementation in Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This v | 0,5% | — |
| CVE-2026-69785 | HIGH 7.8 | microsoft windows_10_1607 Untrusted search path in Windows Smart Card allows an authorized attacker to elevate privileges locally. | 0,5% | — |
| CVE-2026-56174 | HIGH 7.8 | microsoft windows_10_1809 Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally. | 0,5% | — |
| CVE-2026-61487 | MED 6.5 | apache activemq Improper Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. An authenticated low-privilege user can bypass a per-destination write ACL by sending to an ActiveMQ temporary composite destination whose physical name is | 0,5% | — |
| CVE-2026-64391 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: use opener credentials for ADS I/O Alternate data streams are stored as xattrs. Unlike regular file I/O, their read and write paths therefore call VFS xattr helpers which recheck inod | 0,5% | — |
| CVE-2026-64387 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: client: fix query directory replay double-free A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_query_directory_init() fails before the nex | 0,5% | — |
| CVE-2026-64386 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: client: fix query_info() replay double-free A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_query_info_init() fails before the next send, | 0,5% | — |
| CVE-2026-64385 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_ioctl() replay A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_ioctl_init() fails before the next send, cl | 0,5% | — |
| CVE-2026-64384 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: client: fix change notify replay double-free A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_notify_init() fails before the next send, cle | 0,5% | — |
| CVE-2026-64383 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_flush() replay SMB2_flush() keeps its response buffer bookkeeping across replay attempts. If a replayable flush response is received and the retry then f | 0,5% | — |
| CVE-2026-64232 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: block: recompute nr_integrity_segments in blk_insert_cloned_request blk_insert_cloned_request() already recomputes nr_phys_segments against the bottom queue, because "the queue settings rela | 0,5% | — |
| CVE-2026-50462 | HIGH 7.8 | microsoft windows_10_1607 External control of file name or path in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0,5% | — |
| CVE-2026-45501 | MED 6.5 | microsoft exchange_server Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network. | 0,5% | — |
| CVE-2026-46244 | CRIT 9.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_inner: Fix IPv6 inner_thoff desync In nft_inner_parse_l2l3(), when processing inner IPv6 packets, ipv6_find_hdr() correctly computes the transport header offset traversing all | 0,5% | — |
| CVE-2025-59302 | MED 4.7 | apache cloudstack In Apache CloudStack improper control of generation of code ('Code Injection') vulnerability is found in the following APIs which are accessible only to admins. * quotaTariffCreate * quotaTariffUpdate * createSecondaryStorageSelector * updateSeco | 0,5% | — |
| CVE-2025-54894 | HIGH 7.8 | microsoft windows_10_1507 Local Security Authority Subsystem Service Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2025-54102 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally. | 0,5% | — |
| CVE-2025-54091 | HIGH 7.8 | microsoft windows_10_1507 Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to elevate privileges locally. | 0,5% | — |
| CVE-2025-53801 | HIGH 7.8 | microsoft windows_10_1507 Untrusted pointer dereference in Windows DWM allows an authorized attacker to elevate privileges locally. | 0,5% | — |
| CVE-2025-52980 | HIGH 7.5 | juniper junos A Use of Incorrect Byte Ordering vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS on SRX300 Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). When a BGP update is received over an | 0,5% | — |
| CVE-2025-49684 | MED 5.5 | microsoft windows_10_1507 Buffer over-read in Storage Port Driver allows an authorized attacker to disclose information locally. | 0,5% | — |
| CVE-2025-48809 | MED 5.5 | microsoft windows_11_24h2 Processor optimization removal or modification of security-critical code in Windows Kernel allows an authorized attacker to disclose information locally. | 0,5% | — |
| CVE-2024-49781 | HIGH 7.1 | ibm openpages_with_watson IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. | 0,5% | — |
| CVE-2024-39515 | HIGH 7.5 | juniper junos An Improper Validation of Consistency within Input vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker sending a specifically malformed BGP packet to cause rpd to | 0,5% | — |
| CVE-2024-34101 | MED 5.5 | adobe acrobat Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Expl | 0,5% | — |