58.507 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.507 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2014-2038 | LOW 2.1 | canonical ubuntu_linux The nfs_can_extend_write function in fs/nfs/write.c in the Linux kernel before 3.13.3 relies on a write delegation to extend a write operation without a certain up-to-date verification, which allows local users to obtain sensitive information from kernel memor | 0,4% | — |
| CVE-2013-5972 | HIGH 7.2 | vmware player VMware Workstation 9.x before 9.0.3 and VMware Player 5.x before 5.0.3 on Linux do not properly handle shared libraries, which allows host OS users to gain host OS privileges via unspecified vectors. | 0,4% | — |
| CVE-2013-1715 | MED 6.9 | mozilla firefox Multiple untrusted search path vulnerabilities in the (1) full installer and (2) stub installer in Mozilla Firefox before 23.0 on Windows allow local users to gain privileges via a Trojan horse DLL in the default downloads directory. NOTE: this issue exists b | 0,4% | — |
| CVE-2012-1601 | MED 4.9 | linux linux_kernel The KVM implementation in the Linux kernel before 3.3.6 allows host OS users to cause a denial of service (NULL pointer dereference and host OS crash) by making a KVM_CREATE_IRQCHIP ioctl call after a virtual CPU already exists. | 0,4% | — |
| CVE-2009-4021 | MED 4.9 | linux linux_kernel The fuse_direct_io function in fs/fuse/file.c in the fuse subsystem in the Linux kernel before 2.6.32-rc7 might allow attackers to cause a denial of service (invalid pointer dereference and OOPS) via vectors possibly related to a memory-consumption attack. | 0,4% | — |
| CVE-2009-1336 | MED 4.9 | linux linux_kernel fs/nfs/client.c in the Linux kernel before 2.6.23 does not properly initialize a certain structure member that stores the maximum NFS filename length, which allows local users to cause a denial of service (OOPS) via a long filename, related to the encode_looku | 0,4% | — |
| CVE-2008-1669 | MED 6.9 | linux linux_kernel Linux kernel before 2.6.25.2 does not apply a certain protection mechanism for fcntl functionality, which allows local users to (1) execute code in parallel or (2) exploit a race condition to obtain "re-ordered access to the descriptor table." | 0,4% | — |
| CVE-2006-2071 | LOW 2.1 | linux linux_kernel Linux kernel 2.4.x and 2.6.x up to 2.6.16 allows local users to bypass IPC permissions and modify a readonly attachment of shared memory by using mprotect to give write permission to the attachment. NOTE: some original raw sources combined this issue with CVE | 0,4% | — |
| CVE-2006-0096 | HIGH 7.2 | linux linux_kernel wan/sdla.c in Linux kernel 2.6.x before 2.6.11 and 2.4.x before 2.4.29 does not require the CAP_SYS_RAWIO privilege for an SDLA firmware upgrade, with unknown impact and local attack vectors. NOTE: further investigation suggests that this issue requires root | 0,4% | — |
| CVE-2026-54999 | HIGH 8.8 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over an adjacent network. | 0,4% | — |
| CVE-2026-45482 | HIGH 8.4 | microsoft visual_studio_code Improper limitation of a pathname to a restricted directory ('path traversal') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | 0,4% | — |
| CVE-2026-46099 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels seg6_input_core() and rpl_input() call ip6_route_input() which sets a NOREF dst on the skb, then pass it to dst_cache_set_ip6() invokin | 0,4% | — |
| CVE-2025-71183 | CRIT 9.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: btrfs: always detect conflicting inodes when logging inode refs After rename exchanging (either with the rename exchange operation or regular renames in multiple non-atomic steps) two inodes | 0,4% | — |
| CVE-2025-66723 | HIGH 7.5 | inmusicbrands engine_dj_desktop inMusic Brands Engine DJ before 4.3.4 suffers from Insecure Permissions due to exposed HTTP service in the Remote Library, which allows attackers to access all files and network paths. | 0,4% | — |
| CVE-2025-59790 | MED 5.4 | apache kvrocks Improper Privilege Management vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from v2.9.0 through v2.13.0. Users are recommended to upgrade to version 2.14.0, which fixes the issue. | 0,4% | — |
| CVE-2025-54103 | HIGH 7.4 | microsoft windows_10_21h2 Use after free in Windows Management Services allows an unauthorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-47976 | HIGH 7.8 | microsoft windows_10_1507 Use after free in Windows SSDP Service allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-25539 | MED 6.5 | onespan vasco_self-service_portal Local File Inclusion vulnerability in Vasco v3.14and before allows a remote attacker to obtain sensitive information via help menu. | 0,4% | — |
| CVE-2024-54026 | MED 4.3 | fortinet fortisandbox An improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiSandbox 4.4.0 through 4.4.6, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, Fo | 0,4% | — |
| CVE-2024-9468 | HIGH 7.5 | paloaltonetworks pan-os A memory corruption vulnerability in Palo Alto Networks PAN-OS software allows an unauthenticated attacker to crash PAN-OS due to a crafted packet through the data plane, resulting in a denial of service (DoS) condition. Repeated attempts to trigger this condi | 0,4% | — |
| CVE-2024-5909 | MED 5.5 | paloaltonetworks cortex_xdr_agent A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a low privileged local Windows user to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform mali | 0,4% | — |
| CVE-2024-33866 | MED 5.5 | linqi linqi An issue was discovered in linqi before 1.4.0.1 on Windows. There is /api/DocumentTemplate/{GUID] XSS. | 0,4% | — |
| CVE-2023-51561 | MED 5.5 | foxit pdf_editor Foxit PDF Reader PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this | 0,4% | — |
| CVE-2023-6270 | HIGH 7.0 | debian debian_linux A flaw was found in the ATA over Ethernet (AoE) driver in the Linux kernel. The aoecmd_cfg_pkts() function improperly updates the refcnt on `struct net_device`, and a use-after-free can be triggered by racing between the free on the struct and the access throu | 0,4% | — |
| CVE-2023-42029 | MED 4.8 | ibm cics_tx IBM CICS TX Standard 11.1, Advanced 10.1, 11.1, and TXSeries for Multiplatforms 8.1, 8.2, 9.1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality pote | 0,4% | — |