58.483 CVE seguite
793 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.483 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2014-3182 | MED 6.9 | linux linux_kernel Array index error in the logi_dj_raw_event function in drivers/hid/hid-logitech-dj.c in the Linux kernel before 3.16.2 allows physically proximate attackers to execute arbitrary code or cause a denial of service (invalid kfree) via a crafted device that provid | 0,4% | — |
| CVE-2011-2203 | LOW 2.1 | linux linux_kernel The hfs_find_init function in the Linux kernel 2.6 allows local users to cause a denial of service (NULL pointer dereference and Oops) by mounting an HFS file system with a malformed MDB extent record. | 0,4% | — |
| CVE-2010-3067 | MED 4.9 | canonical ubuntu_linux Integer overflow in the do_io_submit function in fs/aio.c in the Linux kernel before 2.6.36-rc4-next-20100915 allows local users to cause a denial of service or possibly have unspecified other impact via crafted use of the io_submit system call. | 0,4% | — |
| CVE-2026-82010 | CRIT 9.9 | adobe campaign Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could | 0,4% | — |
| CVE-2026-69477 | HIGH 7.3 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Access allows an authorized attacker to execute code locally. | 0,4% | — |
| CVE-2026-64067 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfs: Fix missing barriers when accessing stream->subrequests locklessly The list of subrequests attached to stream->subrequests is accessed without locks by netfs_collect_read_results() an | 0,4% | — |
| CVE-2026-34614 | MED 6.1 | adobe connect Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within | 0,4% | — |
| CVE-2026-32149 | HIGH 7.3 | microsoft windows_10_1607 Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally. | 0,4% | — |
| CVE-2026-27912 | HIGH 8.0 | microsoft windows_server_2012 Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over an adjacent network. | 0,4% | — |
| CVE-2025-25255 | MED 5.3 | fortinet fortios An Improperly Implemented Security Check for Standard vulnerability [CWE-358] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.11, FortiProxy 7.2 all versions, FortiProxy 7.0.1 through 7.0.22 m | 0,4% | — |
| CVE-2022-50401 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nfsd: under NFSv4.1, fix double svc_xprt_put on rpc_create failure On error situation `clp->cl_cb_conn.cb_xprt` should not be given a reference to the xprt otherwise both client cleanup and | 0,4% | — |
| CVE-2025-38124 | HIGH 7.5 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: net: fix udp gso skb_segment after pull from frag_list Commit a1e40ac5b5e9 ("net: gso: fix udp gso fraglist segmentation after pull from frag_list") detected invalid geometry in frag_list sk | 0,4% | — |
| CVE-2025-20193 | MED 6.5 | cisco ios_xe A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, low-privileged, remote attacker to perform an injection attack against an affected device.r This vulnerability is due to insufficient input validatio | 0,4% | — |
| CVE-2025-27391 | MED 6.5 | apache artemis Insertion of Sensitive Information into Log File vulnerability in Apache ActiveMQ Artemis. All the values of the broker properties are logged when the org.apache.activemq.artemis.core.config.impl.ConfigurationImpl logger has the debug level enabled. This issu | 0,4% | — |
| CVE-2025-21855 | HIGH 8.6 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ibmvnic: Don't reference skb after sending to VIOS Previously, after successfully flushing the xmit buffer to VIOS, the tx_bytes stat was incremented by the length of the skb. It is invalid | 0,4% | — |
| CVE-2024-38158 | HIGH 7.0 | microsoft azure_iot_hub_device_client_sdk Azure IoT SDK Remote Code Execution Vulnerability | 0,4% | — |
| CVE-2024-38136 | HIGH 7.0 | microsoft windows_10_1809 Windows Resource Manager PSM Service Extension Elevation of Privilege Vulnerability | 0,4% | — |
| CVE-2023-35829 | HIGH 7.0 | linux linux_kernel An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in rkvdec_remove in drivers/staging/media/rkvdec/rkvdec.c. | 0,4% | — |
| CVE-2023-0007 | MED 6.5 | paloaltonetworks pan-os A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software on Panorama appliances enables an authenticated read-write administrator to store a JavaScript payload in the web interface that will execute in the context of another administrat | 0,4% | — |
| CVE-2022-2318 | MED 5.5 | debian debian_linux There are use-after-free vulnerabilities caused by timer handler in net/rose/rose_timer.c of linux that allow attackers to crash linux kernel without any privileges. | 0,4% | — |
| CVE-2021-42754 | LOW 3.2 | fortinet forticlient An improper control of generation of code vulnerability [CWE-94] in FortiClientMacOS versions 7.0.0 and below and 6.4.5 and below may allow an authenticated attacker to hijack the MacOS camera without the user permission via the malicious dylib file. | 0,4% | — |
| CVE-2021-32596 | MED 6.0 | fortinet fortiportal A use of one-way hash with a predictable salt vulnerability in the password storing mechanism of FortiPortal 6.0.0 through 6.04 may allow an attacker already in possession of the password store to decrypt the passwords by means of precomputed tables. | 0,4% | — |
| CVE-2020-28572 | HIGH 7.8 | trendmicro apex_one A vulnerability in Trend Micro Apex One could allow an unprivileged user to abuse the product installer to reinstall the agent with additional malicious code in the context of a higher privilege. | 0,4% | — |
| CVE-2018-16885 | MED 4.7 | linux linux_kernel A flaw was found in the Linux kernel that allows the userspace to call memcpy_fromiovecend() and similar functions with a zero offset and buffer length which causes the read beyond the buffer boundaries, in certain cases causing a memory access fault and a sys | 0,4% | — |
| CVE-2018-12930 | HIGH 7.8 | canonical ubuntu_linux ntfs_end_buffer_async_read in the ntfs.ko filesystem driver in the Linux kernel 4.15.0 allows attackers to trigger a stack-based out-of-bounds write and cause a denial of service (kernel oops or panic) or possibly have unspecified other impact via a crafted nt | 0,4% | — |