58.507 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.507 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2010-3296 | LOW 2.1 | canonical ubuntu_linux The cxgb_extension_ioctl function in drivers/net/cxgb3/cxgb3_main.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via | 0,4% | — |
| CVE-2010-2955 | LOW 2.1 | canonical ubuntu_linux The cfg80211_wext_giwessid function in net/wireless/wext-compat.c in the Linux kernel before 2.6.36-rc3-next-20100831 does not properly initialize certain structure members, which allows local users to leverage an off-by-one error in the ioctl_standard_iw_poin | 0,4% | — |
| CVE-2010-0003 | MED 5.4 | debian debian_linux The print_fatal_signal function in kernel/signal.c in the Linux kernel before 2.6.32.4 on the i386 platform, when print-fatal-signals is enabled, allows local users to discover the contents of arbitrary memory locations by jumping to an address and then readin | 0,4% | — |
| CVE-2001-1551 | LOW 2.1 | linux linux_kernel Linux kernel 2.2.19 enables CAP_SYS_RESOURCE for setuid processes, which allows local users to exceed disk quota restrictions during execution of setuid programs. | 0,4% | — |
| CVE-2026-69376 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-69367 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-69345 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-69308 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-69303 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-68895 | MED 5.5 | microsoft windows_10_1607 Numeric truncation error in Internet Storage Name Service allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-68881 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-68843 | MED 5.5 | microsoft windows_10_1607 Use after free in Microsoft Office Word allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-8671 | HIGH 7.5 | avantra avantra Insertion of sensitive information into log file vulnerability in syslink software AG Avantra on Linux, Windows allows Resource Leak Exposure. This issue affects Avantra: before 25.3.0. | 0,4% | — |
| CVE-2026-32077 | HIGH 7.8 | microsoft windows_10_1607 Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2026-3542 | HIGH 8.8 | google chrome Inappropriate implementation in WebAssembly in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) | 0,4% | — |
| CVE-2026-20068 | MED 5.8 | cisco cyber_vision Multiple Cisco products are affected by a vulnerability in the Snort 3 detection engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspection. This vulnerabil | 0,4% | — |
| CVE-2026-20053 | MED 5.8 | cisco cyber_vision Multiple Cisco products are affected by a vulnerability in the Snort 3 VBA feature that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash. This vulnerability is due to improper range checking when decompressing V | 0,4% | — |
| CVE-2026-23112 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec nvmet_tcp_build_pdu_iovec() could walk past cmd->req.sg when a PDU length or offset exceeds sg_cnt and then use bogus sg->length/off | 0,4% | — |
| CVE-2025-62216 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2025-62205 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2025-38527 | CRIT 9.8 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: smb: client: fix use-after-free in cifs_oplock_break A race condition can occur in cifs_oplock_break() leading to a use-after-free of the cinode structure when unmounting: cifs_oplock_bre | 0,4% | — |
| CVE-2025-27163 | MED 5.5 | adobe acrobat Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR | 0,4% | — |
| CVE-2024-57843 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: virtio-net: fix overflow inside virtnet_rq_alloc When the frag just got a page, then may lead to regression on VM. Specially if the sysctl net.core.high_order_alloc_disable value is 1, then | 0,4% | — |
| CVE-2024-21107 | MED 6.7 | oracle vm_virtualbox Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.16. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Ora | 0,4% | — |
| CVE-2022-45430 | LOW 3.7 | dahuasecurity dhi-dss4004-s2_firmware Some Dahua software products have a vulnerability of unauthenticated enable or disable SSHD service. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could enable or disable the S | 0,4% | — |