58.507 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.507 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2022-35754 | MED 6.7 | microsoft windows_10_1507 Unified Write Filter Elevation of Privilege Vulnerability | 0,4% | — |
| CVE-2022-28893 | HIGH 7.8 | debian debian_linux The SUNRPC subsystem in the Linux kernel through 5.17.2 can call xs_xprt_free before ensuring that sockets are in the intended state. | 0,4% | — |
| CVE-2020-3588 | HIGH 7.3 | cisco webex_meetings A vulnerability in virtualization channel messaging in Cisco Webex Meetings Desktop App for Windows could allow a local attacker to execute arbitrary code on a targeted system. This vulnerability occurs when this app is deployed in a virtual desktop environmen | 0,4% | — |
| CVE-2020-5867 | HIGH 8.1 | f5 nginx_controller In versions prior to 3.3.0, the NGINX Controller Agent installer script 'install.sh' uses HTTP instead of HTTPS to check and install packages | 0,4% | — |
| CVE-2018-20510 | MED 5.5 | linux linux_kernel The print_binder_transaction_ilocked function in drivers/android/binder.c in the Linux kernel 4.14.90 allows local users to obtain sensitive address information by reading "*from *code *flags" lines in a debugfs file. | 0,4% | — |
| CVE-2017-4903 | HIGH 8.8 | vmware esxi VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 without patch ESXi600-201703402-SG, and 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior | 0,4% | — |
| CVE-2017-8063 | HIGH 7.8 | linux linux_kernel drivers/media/usb/dvb-usb/cxusb.c in the Linux kernel 4.9.x and 4.10.x before 4.10.12 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash) or possibly have unspecified other impact by lev | 0,4% | — |
| CVE-2017-8062 | HIGH 7.8 | linux linux_kernel drivers/media/usb/dvb-usb/dw2102.c in the Linux kernel 4.9.x and 4.10.x before 4.10.4 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly have unspecifie | 0,4% | — |
| CVE-2012-4398 | MED 4.9 | linux linux_kernel The __request_module function in kernel/kmod.c in the Linux kernel before 3.4 does not set a certain killable attribute, which allows local users to cause a denial of service (memory consumption) via a crafted application. | 0,4% | — |
| CVE-2012-4897 | MED 6.9 | vmware movie_decoder Untrusted search path vulnerability in the installer in VMware Movie Decoder before 9.0 allows local users to gain privileges via a Trojan horse executable file in the installer directory. | 0,4% | — |
| CVE-2005-0207 | LOW 2.1 | conectiva linux Unknown vulnerability in Linux kernel 2.4.x, 2.5.x, and 2.6.x allows NFS clients to cause a denial of service via O_DIRECT. | 0,4% | — |
| CVE-1999-0317 | HIGH 7.2 | linux linux_kernel Buffer overflow in Linux su command gives root access to local users. | 0,4% | — |
| CVE-1999-0330 | HIGH 7.2 | linux linux_kernel Linux bdash game has a buffer overflow that allows local users to gain root access. | 0,4% | — |
| CVE-2026-9138 | MED 6.5 | langflow langflow IBM Langflow OSS 1.0.0 through 1.11.2 Langflow could allow an authenticated attacker to write arbitrary files to the server due to improper input validation in the SaveToFileComponent. The application constructs local file paths using attacker‑controlled input | 0,4% | — |
| CVE-2026-64444 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop The IE parsing loop in OnAssocRsp() advances by (pIE->length + 2) each iteration but only guards on i < pkt_len. When a malicious AP | 0,4% | — |
| CVE-2026-64443 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop The IE parsing loop in update_beacon_info() advances by (pIE->length + 2) each iteration but only guards on i < len. When a m | 0,4% | — |
| CVE-2026-50377 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2026-9154 | HIGH 7.1 | gnu sed Arbitrary File Write vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to write attacker-controlled content to arbitrary file paths via the expression parameter. | 0,4% | — |
| CVE-2026-34694 | MED 4.8 | adobe experience_manager Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious Ja | 0,4% | — |
| CVE-2026-41863 | MED 6.5 | vmware spring_ai Spring AI's support for Anthropic's Skills API used LLM-influenced filenames unsanitized in Path.resolve before writing files to disk. This could allow a malicious user to write files outside the intended target directory, including restricted directories. Af | 0,4% | — |
| CVE-2026-43291 | HIGH 8.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: nfc: nci: Fix parameter validation for packet data Since commit 9c328f54741b ("net: nfc: nci: Add parameter validation for packet data") communication with nci nfc chips is not working | 0,4% | — |
| CVE-2026-43215 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: cifs: Fix locking usage for tcon fields We used to use the cifs_tcp_ses_lock to protect a lot of objects that are not just the server, ses or tcon lists. We later introduced srv_lock, ses_lo | 0,4% | — |
| CVE-2026-31779 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: fix potential out-of-bounds read in iwl_mvm_nd_match_info_handler() The memcpy function assumes the dynamic array notif->matches is at least as large as the number of byt | 0,4% | — |
| CVE-2026-27906 | MED 4.4 | microsoft windows_10_21h2 Improper input validation in Windows Hello allows an authorized attacker to bypass a security feature locally. | 0,4% | — |
| CVE-2025-13633 | HIGH 8.8 | google chrome Use after free in Digital Credentials in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 0,4% | — |