58.483 CVE seguite
793 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.483 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2011-1747 | MED 4.7 | linux linux_kernel The agp subsystem in the Linux kernel 2.6.38.5 and earlier does not properly restrict memory allocation by the (1) AGPIOC_RESERVE and (2) AGPIOC_ALLOCATE ioctls, which allows local users to cause a denial of service (memory consumption) by making many calls to | 0,4% | — |
| CVE-2008-2826 | MED 4.9 | canonical ubuntu_linux Integer overflow in the sctp_getsockopt_local_addrs_old function in net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) functionality in the Linux kernel before 2.6.25.9 allows local users to cause a denial of service (resource consumption and | 0,4% | — |
| CVE-2006-5174 | LOW 2.1 | linux linux_kernel The copy_from_user function in the uaccess code in Linux kernel 2.6 before 2.6.19-rc1, when running on s390, does not properly clear a kernel buffer, which allows local user space programs to read portions of kernel memory by "appending to a file from a bad ad | 0,4% | — |
| CVE-2026-47889 | HIGH 7.5 | vmware spring_framework A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 | 0,4% | — |
| CVE-2025-69624 | HIGH 7.5 | gonitro nitro_pdf_pro Nitro PDF Pro before 14.43 for Windows contains a NULL pointer dereference vulnerability in the JavaScript implementation of app.alert(). When app.alert() is called with more than one argument and the first argument evaluates to null (for example, app.alert(ap | 0,4% | — |
| CVE-2025-65114 | HIGH 7.5 | apache traffic_server Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.12, from 10.0.0 through 10.1.1. Users are recommended to upgrade to version 9.2.13 or 10.1.2, which fix the is | 0,4% | — |
| CVE-2025-58130 | CRIT 9.1 | apache fineract Insufficiently Protected Credentials vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.11.0. The issue is fixed in version 1.12.1. Users are encouraged to upgrade to version 1.13.0, the latest release. | 0,4% | — |
| CVE-2025-34190 | HIGH 7.8 | vasion virtual_appliance_application Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 25.1.102 and Application versions prior to 25.1.1413 (macOS/Linux client deployments) are vulnerable to an authentication bypass in PrinterInstallerClientService. The service require | 0,4% | — |
| CVE-2025-48820 | HIGH 7.8 | microsoft windows_10_1507 Improper link resolution before file access ('link following') in Windows AppX Deployment Service allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2023-38246 | HIGH 7.8 | adobe acrobat Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issu | 0,4% | — |
| CVE-2023-35328 | HIGH 7.8 | microsoft windows_10_1507 Windows Transaction Manager Elevation of Privilege Vulnerability | 0,4% | — |
| CVE-2023-35305 | HIGH 7.8 | microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability | 0,4% | — |
| CVE-2023-35304 | HIGH 7.8 | microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability | 0,4% | — |
| CVE-2023-21756 | HIGH 7.8 | microsoft windows_10_1507 Windows Win32k Elevation of Privilege Vulnerability | 0,4% | — |
| CVE-2023-34442 | LOW 3.3 | apache camel Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Camel.This issue affects Apache Camel: from 3.X through <=3.14.8, from 3.18.X through <=3.18.7, from 3.20.X through <= 3.20.5, from 4.X through <= 4.0 | 0,4% | — |
| CVE-2023-33693 | MED 5.5 | tsingsee easyplayerpro A buffer overflow in EasyPlayerPro-Win v3.2.19.0106 to v3.6.19.0823 allows attackers to cause a Denial of Service (DoS) via a crafted XML file. | 0,4% | — |
| CVE-2023-2236 | HIGH 7.8 | linux linux_kernel A use-after-free vulnerability in the Linux Kernel io_uring subsystem can be exploited to achieve local privilege escalation. Both io_install_fixed_file and its callers call fput in a file in case of an error, causing a reference underflow which leads to a us | 0,4% | — |
| CVE-2022-20953 | MED 5.5 | cisco roomos Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path traversal attacks, view sensitive data, or write arbitrary files on an affected device. For more information a | 0,4% | — |
| CVE-2021-43080 | MED 4.6 | fortinet fortios An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS version 7.2.0, version 6.4.0 through 6.4.9, version 7.0.0 through 7.0.5 may allow an authenticated attacker to perform a stored cross site scripting (XSS) attack t | 0,4% | — |
| CVE-2022-32296 | LOW 3.3 | linux linux_kernel The Linux kernel before 5.17.9 allows TCP servers to identify clients by observing what source ports are used. This occurs because of use of Algorithm 4 ("Double-Hash Port Selection Algorithm") of RFC 6056. | 0,4% | — |
| CVE-2022-26808 | HIGH 7.0 | microsoft windows_10 Windows File Explorer Elevation of Privilege Vulnerability | 0,4% | — |
| CVE-2022-24959 | MED 5.5 | debian debian_linux An issue was discovered in the Linux kernel before 5.16.5. There is a memory leak in yam_siocdevprivate in drivers/net/hamradio/yam.c. | 0,4% | — |
| CVE-2018-1799 | MED 6.2 | ibm db2 IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local unprivileged user to overwrite files on the system which could cause damage to the database. IBM X-Force ID: 149429. | 0,4% | — |
| CVE-2016-10208 | MED 4.3 | linux linux_kernel The ext4_fill_super function in fs/ext4/super.c in the Linux kernel through 4.9.8 does not properly validate meta block groups, which allows physically proximate attackers to cause a denial of service (out-of-bounds read and system crash) via a crafted ext4 im | 0,4% | — |
| CVE-2014-3646 | MED 5.5 | canonical ubuntu_linux arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel through 3.17.2 does not have an exit handler for the INVVPID instruction, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application. | 0,4% | — |