EN
58.450 CVE seguite
793 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.450 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2026-20135 HIGH 8.6 A vulnerability in the TLS 1.3 implementation in Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This v 0,5% —
CVE-2026-69785 HIGH 7.8 microsoft windows_10_1607 Untrusted search path in Windows Smart Card allows an authorized attacker to elevate privileges locally. 0,5% —
CVE-2026-56174 HIGH 7.8 microsoft windows_10_1809 Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally. 0,5% —
CVE-2026-61487 MED 6.5 apache activemq Improper Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. An authenticated low-privilege user can bypass a per-destination write ACL by sending to an ActiveMQ temporary composite destination whose physical name is 0,5% —
CVE-2026-64391 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: use opener credentials for ADS I/O Alternate data streams are stored as xattrs. Unlike regular file I/O, their read and write paths therefore call VFS xattr helpers which recheck inod 0,5% —
CVE-2026-64387 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: client: fix query directory replay double-free A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_query_directory_init() fails before the nex 0,5% —
CVE-2026-64386 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: client: fix query_info() replay double-free A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_query_info_init() fails before the next send, 0,5% —
CVE-2026-64385 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_ioctl() replay A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_ioctl_init() fails before the next send, cl 0,5% —
CVE-2026-64384 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: client: fix change notify replay double-free A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_notify_init() fails before the next send, cle 0,5% —
CVE-2026-64383 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_flush() replay SMB2_flush() keeps its response buffer bookkeeping across replay attempts. If a replayable flush response is received and the retry then f 0,5% —
CVE-2026-64232 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: block: recompute nr_integrity_segments in blk_insert_cloned_request blk_insert_cloned_request() already recomputes nr_phys_segments against the bottom queue, because "the queue settings rela 0,5% —
CVE-2026-50462 HIGH 7.8 microsoft windows_10_1607 External control of file name or path in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0,5% —
CVE-2026-45501 MED 6.5 microsoft exchange_server Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network. 0,5% —
CVE-2026-46244 CRIT 9.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_inner: Fix IPv6 inner_thoff desync In nft_inner_parse_l2l3(), when processing inner IPv6 packets, ipv6_find_hdr() correctly computes the transport header offset traversing all 0,5% —
CVE-2025-59302 MED 4.7 apache cloudstack In Apache CloudStack improper control of generation of code ('Code Injection') vulnerability is found in the following APIs which are accessible only to admins. * quotaTariffCreate * quotaTariffUpdate * createSecondaryStorageSelector * updateSeco 0,5% —
CVE-2025-54894 HIGH 7.8 microsoft windows_10_1507 Local Security Authority Subsystem Service Elevation of Privilege Vulnerability 0,5% —
CVE-2025-54102 HIGH 7.8 microsoft windows_10_1607 Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally. 0,5% —
CVE-2025-54091 HIGH 7.8 microsoft windows_10_1507 Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to elevate privileges locally. 0,5% —
CVE-2025-53801 HIGH 7.8 microsoft windows_10_1507 Untrusted pointer dereference in Windows DWM allows an authorized attacker to elevate privileges locally. 0,5% —
CVE-2025-52980 HIGH 7.5 juniper junos A Use of Incorrect Byte Ordering vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS on SRX300 Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). When a BGP update is received over an 0,5% —
CVE-2025-49684 MED 5.5 microsoft windows_10_1507 Buffer over-read in Storage Port Driver allows an authorized attacker to disclose information locally. 0,5% —
CVE-2025-48809 MED 5.5 microsoft windows_11_24h2 Processor optimization removal or modification of security-critical code in Windows Kernel allows an authorized attacker to disclose information locally. 0,5% —
CVE-2024-49781 HIGH 7.1 ibm openpages_with_watson IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. 0,5% —
CVE-2024-39515 HIGH 7.5 juniper junos An Improper Validation of Consistency within Input vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker sending a specifically malformed BGP packet to cause rpd to 0,5% —
CVE-2024-34101 MED 5.5 adobe acrobat Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Expl 0,5% —