58.507 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.507 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2025-38472 | CRIT 9.8 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack: fix crash due to removal of uninitialised entry A crash in conntrack was reported while trying to unlink the conntrack entry from the hash bucket list: [exceptio | 0,4% | — |
| CVE-2025-49705 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2025-49700 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2024-41768 | MED 6.5 | ibm engineering_lifecycle_optimization_publishing IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 could allow a remote attacker to cause an unhandled SSL exception which could leave the connection in an unexpected or insecure state. | 0,4% | — |
| CVE-2024-8687 | HIGH 7.1 | paloaltonetworks globalprotect An information exposure vulnerability exists in Palo Alto Networks PAN-OS software that enables a GlobalProtect end user to learn both the configured GlobalProtect uninstall password and the configured disable or disconnect passcode. After the password or pass | 0,4% | — |
| CVE-2024-30057 | MED 5.4 | microsoft edge Microsoft Edge for iOS Spoofing Vulnerability | 0,4% | — |
| CVE-2021-43753 | HIGH 7.8 | adobe lightroom Adobe Lightroom versions 4.4 (and earlier) are affected by a use-after-free vulnerability in the processing of parsing TIF files that could result in privilege escalation. Exploitation of this issue requires user interaction in that a victim must open a malici | 0,4% | — |
| CVE-2023-20229 | HIGH 7.1 | cisco duo_device_health_application A vulnerability in the CryptoService function of Cisco Duo Device Health Application for Windows could allow an authenticated, local attacker with low privileges to conduct directory traversal attacks and overwrite arbitrary files on an affected system. Thi | 0,4% | — |
| CVE-2023-20224 | HIGH 7.8 | cisco thousandeyes_enterprise_agent A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent, Virtual Appliance installation type, could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability is due to insufficient input validat | 0,4% | — |
| CVE-2022-38448 | HIGH 7.8 | adobe dimension Adobe Dimension versions 3.4.5 is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | 0,4% | — |
| CVE-2022-38447 | HIGH 7.8 | adobe dimension Adobe Dimension versions 3.4.5 is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | 0,4% | — |
| CVE-2022-38446 | HIGH 7.8 | adobe dimension Adobe Dimension versions 3.4.5 is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | 0,4% | — |
| CVE-2022-38445 | HIGH 7.8 | adobe dimension Adobe Dimension versions 3.4.5 is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | 0,4% | — |
| CVE-2022-37173 | HIGH 7.8 | vim gvim An issue in the installer of gvim 9.0.0000 allows authenticated attackers to execute arbitrary code via a binary hijacking attack on C:\Program.exe. | 0,4% | — |
| CVE-2022-25946 | HIGH 8.7 | f5 big-ip_access_policy_manager On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP Advanced WAF, ASM, and ASM, and F5 BIG-IP Guided Configuration (GC) all versions prior to 9.0, when running in Appliance mode, an authenticated attacker with Administrator role | 0,4% | — |
| CVE-2022-26827 | HIGH 7.0 | microsoft windows_10 Windows File Server Resource Management Service Elevation of Privilege Vulnerability | 0,4% | — |
| CVE-2020-4004 | HIGH 8.2 | vmware cloud_foundation VMware ESXi (7.0 before ESXi70U1b-17168206, 6.7 before ESXi670-202011101-SG, 6.5 before ESXi650-202011301-SG), Workstation (15.x before 15.5.7), Fusion (11.x before 11.5.7) contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor wi | 0,4% | — |
| CVE-2019-19523 | MED 4.6 | debian debian_linux In the Linux kernel before 5.3.7, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/usb/misc/adutux.c driver, aka CID-44efc269db79. | 0,4% | — |
| CVE-2019-19043 | MED 5.5 | canonical ubuntu_linux A memory leak in the i40e_setup_macvlans() function in drivers/net/ethernet/intel/i40e/i40e_main.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering i40e_setup_channel() failures, aka CID-27d461 | 0,4% | — |
| CVE-2019-15315 | HIGH 7.8 | valvesoftware steam_client Valve Steam Client for Windows through 2019-08-16 allows privilege escalation (to NT AUTHORITY\SYSTEM) because local users can replace the current versions of SteamService.exe and SteamService.dll with older versions that lack the CVE-2019-14743 patch. | 0,4% | — |
| CVE-2018-19965 | MED 5.6 | citrix xenserver An issue was discovered in Xen through 4.11.x allowing 64-bit PV guest OS users to cause a denial of service (host OS crash) because #GP[0] can occur after a non-canonical address is passed to the TLB flushing code. NOTE: this issue exists because of an incorr | 0,4% | — |
| CVE-2018-19962 | HIGH 7.8 | citrix xenserver An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because small IOMMU mappings are unsafely combined into larger ones. | 0,4% | — |
| CVE-2018-19961 | HIGH 7.8 | citrix xenserver An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because TLB flushes do not always occur after IOMMU mapping changes. | 0,4% | — |
| CVE-2018-14678 | HIGH 7.8 | canonical ubuntu_linux An issue was discovered in the Linux kernel through 4.17.11, as used in Xen through 4.11.x. The xen_failsafe_callback entry point in arch/x86/entry/entry_64.S does not properly maintain RBX, which allows local users to cause a denial of service (uninitialized | 0,4% | — |
| CVE-2017-12552 | MED 5.6 | hp system_management_homepage A local arbitrary execution of commands vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found. | 0,4% | — |