58.462 CVE seguite
793 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.462 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2015-4237 | MED 4.6 | cisco nx-os The CLI parser in Cisco NX-OS 4.1(2)E1(1), 6.2(11b), 6.2(12), 7.2(0)ZZ(99.1), 7.2(0)ZZ(99.3), and 9.1(1)SV1(3.1.8) on Nexus devices allows local users to execute arbitrary OS commands via crafted characters in a filename, aka Bug IDs CSCuv08491, CSCuv08443, CS | 0,4% | — |
| CVE-2009-3288 | MED 4.9 | kernel linux_kernel The sg_build_indirect function in drivers/scsi/sg.c in Linux kernel 2.6.28-rc1 through 2.6.31-rc8 uses an incorrect variable when accessing an array, which allows local users to cause a denial of service (kernel OOPS and NULL pointer dereference), as demonstra | 0,4% | — |
| CVE-2006-3741 | MED 4.9 | linux linux_kernel The perfmonctl system call (sys_perfmonctl) in Linux kernel 2.4.x and 2.6 before 2.6.18, when running on Itanium systems, does not properly track the reference count for file descriptors, which allows local users to cause a denial of service (file descriptor c | 0,4% | — |
| CVE-2006-1528 | MED 4.9 | linux linux_kernel Linux kernel before 2.6.13 allows local users to cause a denial of service (crash) via a dio transfer from the sg driver to memory mapped (mmap) IO space. | 0,4% | — |
| CVE-2006-1525 | MED 4.9 | linux linux_kernel ip_route_input in Linux kernel 2.6 before 2.6.16.8 allows local users to cause a denial of service (panic) via a request for a route for a multicast IP address, which triggers a null dereference. | 0,4% | — |
| CVE-2005-4412 | LOW 2.1 | citrix program_neighborhood_client Citrix Program Neighborhood client before 9.150 caches the user password in plaintext in the GUI while asterisks are used to visually obfuscate the password, which allows attackers with access to the session to obtain the password by using a tool to directly a | 0,4% | — |
| CVE-2026-69364 | HIGH 7.1 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to elevate privileges over a network. | 0,4% | — |
| CVE-2025-53725 | HIGH 7.8 | microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-53154 | HIGH 7.8 | microsoft windows_10_1507 Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-53151 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-53141 | HIGH 7.8 | microsoft windows_10_1507 Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-50155 | HIGH 7.8 | microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-50153 | HIGH 7.8 | microsoft windows_10_1507 Use after free in Desktop Windows Manager allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-49761 | HIGH 7.8 | microsoft windows_10_1507 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-21199 | MED 6.7 | microsoft azure_agent Improper privilege management in Azure Agent Installer allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2022-49051 | MED 6.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: usb: aqc111: Fix out-of-bounds accesses in RX fixup aqc111_rx_fixup() contains several out-of-bounds accesses that can be triggered by a malicious (or defective) USB device, in particul | 0,4% | — |
| CVE-2024-45072 | MED 5.5 | ibm websphere_application_server IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sensitive information or consume memory resources. | 0,4% | — |
| CVE-2024-20390 | MED 5.3 | cisco ios_xr A vulnerability in the Dedicated XML Agent feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) on XML TCP listen port 38751. This vulnerability is due to a lack of proper error validation of in | 0,4% | — |
| CVE-2024-39531 | HIGH 7.5 | juniper junos_os_evolved An Improper Handling of Values vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved on ACX 7000 Series allows a network-based, unauthenticated attacker to cause a Denial-of-Service (DoS). If a value is configured for DDoS b | 0,4% | — |
| CVE-2021-39859 | MED 5.5 | adobe acrobat Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerabili | 0,4% | — |
| CVE-2023-3141 | HIGH 7.1 | debian debian_linux A use-after-free flaw was found in r592_remove in drivers/memstick/host/r592.c in media access in the Linux Kernel. This flaw allows a local attacker to crash the system at device disconnect, possibly leading to a kernel information leak. | 0,4% | — |
| CVE-2022-42469 | MED 4.3 | fortinet fortios A permissive list of allowed inputs vulnerability [CWE-183] in FortiGate version 7.2.3 and below, version 7.0.9 and below Policy-based NGFW Mode may allow an authenticated SSL-VPN user to bypass the policy via bookmarks in the web portal. | 0,4% | — |
| CVE-2023-25883 | HIGH 7.8 | adobe dimension Adobe Dimension versions 3.4.7 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must | 0,4% | — |
| CVE-2023-25882 | HIGH 7.8 | adobe dimension Adobe Dimension versions 3.4.7 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must | 0,4% | — |
| CVE-2022-22237 | MED 6.5 | juniper junos An Improper Authentication vulnerability in the kernel of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause an impact on confidentiality or integrity. A vulnerability in the processing of TCP-AO will allow a BGP or LDP peer n | 0,4% | — |