EN
58.507 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.507 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2026-62904 MED 5.4 microsoft edge_chromium Incorrect authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. 0,4% —
CVE-2026-66325 MED 6.1 microsoft edge_chromium Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. 0,4% —
CVE-2026-57980 MED 5.4 microsoft edge_chromium Authentication bypass using an alternate path or channel in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network. 0,4% —
CVE-2026-0250 HIGH 8.1 paloaltonetworks globalprotect A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man in the middle attacker to disrupt system processes and potentially execute arbitrary code with SYSTEM privileges. This vulnerability is triggered during the 0,4% —
CVE-2026-41705 HIGH 8.6 vmware spring_ai Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injection via unsanitized document IDs. Spring AI 1.0.x: affected from 1.0.0 through latest 1.0.x; upgrade to 1.0.7 or greater. Spring AI 1.1.x: affected from 1.1.0 0,4% —
CVE-2026-40967 HIGH 8.6 vmware spring_ai In Spring AI, various FilterExpressionConverter implementations accept a filter expression object and translate them to specific vector store query languages. In several cases, keys and values are not properly escaped, leading to the ability to alter the query 0,4% —
CVE-2026-23364 HIGH 7.4 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: Compare MACs in constant time To prevent timing attacks, MAC comparisons need to be constant-time. Replace the memcmp() with the correct function, crypto_memneq(). 0,4% —
CVE-2026-23665 HIGH 7.8 microsoft linux_diagnostic_extension Heap-based buffer overflow in Azure Linux Virtual Machines allows an authorized attacker to elevate privileges locally. 0,4% —
CVE-2025-47148 MED 6.5 f5 big-ip_access_policy_manager When the BIG-IP system is configured as both a Security Assertion Markup Language (SAML) service provider (SP) and Identity Provider (IdP), with single logout (SLO) enabled on an access policy, undisclosed requests can cause an increase in memory resource util 0,4% —
CVE-2022-50373 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: fs: dlm: fix race in lowcomms This patch fixes a race between queue_work() in _dlm_lowcomms_commit_msg() and srcu_read_unlock(). The queue_work() can take the final reference of a dlm_msg an 0,4% —
CVE-2025-54919 HIGH 7.5 microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to execute code locally. 0,4% —
CVE-2025-47986 HIGH 8.8 microsoft windows_10_1507 Use after free in Universal Print Management Service allows an authorized attacker to elevate privileges locally. 0,4% —
CVE-2024-55909 MED 6.5 ibm concert IBM Concert Software 1.0.0 through 1.0.5 could allow an authenticated user to cause a denial of service due to the expansion of archive files without controlling resource consumption. 0,4% —
CVE-2022-49768 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: 9p: trans_fd/p9_conn_cancel: drop client lock earlier syzbot reported a double-lock here and we no longer need this lock after requests have been moved off to local list: just drop the lock 0,4% —
CVE-2024-50565 LOW 3.1 fortinet fortianalyzer A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0.0 through 7.0.14, 6.4.0 through 6.4.15 and 6.2.0 through 6.2.16, Fortinet FortiProxy version 0,4% —
CVE-2025-21805 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs: Add missing deinit() call A warning is triggered when repeatedly connecting and disconnecting the rnbd: list_add corruption. prev->next should be next (ffff88800b13e480), but was 0,4% —
CVE-2025-21262 MED 5.4 microsoft edge_chromium User Interface (UI) Misrepresentation of Critical Information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network 0,4% —
CVE-2024-12751 HIGH 7.8 foxit pdf_editor Foxit PDF Reader AcroForm Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in 0,4% —
CVE-2023-32162 HIGH 7.8 wacom driver Wacom Drivers for Windows Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Wacom Drivers for Windows. An attacker must first obtain the abili 0,4% —
CVE-2022-43952 LOW 3.5 fortinet fortiadc An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiADC version 7.1.1 and below, version 7.0.3 and below, version 6.2.5 and below may allow an authenticated attacker to perform a cross-site scr 0,4% —
CVE-2022-34330 MED 6.1 ibm sterling_b2b_integrator IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credent 0,4% —
CVE-2022-41950 MED 6.4 super_xray_project super_xray super-xray is the GUI alternative for vulnerability scanning tool xray. In 0.2-beta, a privilege escalation vulnerability was discovered. This caused inaccurate default xray permissions. Note: this vulnerability only affects Linux and Mac OS systems. Users sho 0,4% —
CVE-2022-38027 HIGH 7.0 microsoft windows_10 Windows Storage Elevation of Privilege Vulnerability 0,4% —
CVE-2022-38021 HIGH 7.0 microsoft windows_10 Connected User Experiences and Telemetry Elevation of Privilege Vulnerability 0,4% —
CVE-2021-36189 MED 6.8 fortinet forticlient_enterprise_management_server A missing encryption of sensitive data in Fortinet FortiClientEMS version 7.0.1 and below, version 6.4.4 and below allows attacker to information disclosure via inspecting browser decrypted data 0,4% —