58.462 CVE seguite
793 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.462 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2011-4330 | HIGH 7.2 | linux linux_kernel Stack-based buffer overflow in the hfs_mac2asc function in fs/hfs/trans.c in the Linux kernel 2.6 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via an HFS image with a crafted len field. | 0,4% | — |
| CVE-2009-3939 | HIGH 7.1 | avaya aura_application_enablement_services The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world-writable permissions, which allows local users to change the I/O mode of the driver by modifying this file. | 0,4% | — |
| CVE-2008-3389 | MED 4.6 | ingres ingres Stack-based buffer overflow in the libbecompat library in Ingres 2.6, Ingres 2006 release 1 (aka 9.0.4), and Ingres 2006 release 2 (aka 9.1.0) on Linux and HP-UX allows local users to gain privileges by setting a long value of an environment variable before ru | 0,4% | — |
| CVE-2007-6267 | LOW 2.1 | citrix edgesight_for_endpoints Citrix EdgeSight 4.2 and 4.5 for Presentation Server, EdgeSight 4.2 and 4.5 for Endpoints, and EdgeSight for NetScaler 1.0 and 1.1 do not properly store database credentials in configuration files, which allows local users to obtain sensitive information. | 0,4% | — |
| CVE-2004-0565 | LOW 2.1 | gentoo linux Floating point information leak in the context switch code for Linux 2.4.x only checks the MFH bit but does not verify the FPH owner, which allows local users to read register values of other processes by setting the MFH bit. | 0,4% | — |
| CVE-2004-0003 | MED 4.6 | linux linux_kernel Unknown vulnerability in Linux kernel before 2.4.22 allows local users to gain privileges, related to "R128 DRI limits checking." | 0,4% | — |
| CVE-2026-62869 | HIGH 8.8 | microsoft entra_id Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing over a network. | 0,4% | — |
| CVE-2026-64380 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: client: harden POSIX SID length parsing posix_info_sid_size() reads sid[1] to obtain the subauthority count, but its existing boundary check still accepts buffers with only one remainin | 0,4% | — |
| CVE-2026-49177 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-45649 | HIGH 7.1 | microsoft excel Improper access control in Office for Android allows an unauthorized attacker to perform spoofing locally. | 0,4% | — |
| CVE-2026-21251 | HIGH 7.8 | microsoft windows_server_2016 Use after free in Windows Cluster Client Failover allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2026-21246 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2026-21245 | HIGH 7.8 | microsoft windows_11_24h2 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2026-21239 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2026-21236 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2026-21232 | HIGH 7.8 | microsoft windows_11_23h2 Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2026-20956 | HIGH 7.8 | microsoft 365_apps Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2025-55321 | CRIT 9.3 | microsoft azure_monitor Improper neutralization of input during web page generation ('cross-site scripting') in Azure Monitor allows an unauthorized attacker to perform spoofing over a network. | 0,4% | — |
| CVE-2025-20315 | HIGH 8.6 | cisco ios_xe A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, causing a denial of service (DoS) condition. This vulnerability is du | 0,4% | — |
| CVE-2025-4232 | HIGH 8.8 | paloaltonetworks globalprotect An improper neutralization of wildcards vulnerability in the log collection feature of Palo Alto Networks GlobalProtect™ app on macOS allows a non administrative user to escalate their privileges to root. | 0,4% | — |
| CVE-2025-43595 | HIGH 7.8 | msp360 backup An insecure file system permissions vulnerability in MSP360 Backup 4.3.1.115 allows a low privileged user to execute commands with root privileges in the 'Online Backup' folder. Upgrade to MSP360 Backup 4.4 (released on 2025-04-22). | 0,4% | — |
| CVE-2022-49743 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ovl: Use "buf" flexible array for memcpy() destination The "buf" flexible array needs to be the memcpy() destination to avoid false positive run-time warning from the recent FORTIFY_SOURCE h | 0,4% | — |
| CVE-2024-52982 | HIGH 7.8 | adobe animate Animate versions 23.0.8, 24.0.5 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must | 0,4% | — |
| CVE-2024-20408 | HIGH 7.7 | cisco adaptive_security_appliance_software A vulnerability in the Dynamic Access Policies (DAP) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause an affected device to reload unexpectedly. | 0,4% | — |
| CVE-2024-20517 | MED 6.8 | cisco rv042_firmware A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, Administrator-level, remote attacker to cause an unexpected reload of an affected device, resulting in a denial | 0,4% | — |