56.705 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.705 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più alto |
|---|---|---|---|---|
| CVE-2018-14634 | HIGH 7.8 | canonical ubuntu_linux An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use this flaw to escalate their privileges on the system. Kernel versions 2.6.x, 3.10.x | 14,7% | |
| CVE-2024-37079 | CRIT 9.8 | vmware cloud_foundation vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remo | 22,4% | |
| CVE-2025-54313 | HIGH 7.5 | alexghr got-fetch eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows. | 4,1% | |
| CVE-2026-20045 | HIGH 8.2 | cisco unified_communications_manager A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unity Connection | 4,4% | |
| CVE-2026-20805 | MED 5.5 | microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally. | 5,1% | |
| CVE-2009-0556 | HIGH 8.8 | microsoft office_powerpoint Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an an invalid index value that triggers | 67,5% | |
| CVE-2025-20393 | CRIT 10.0 | cisco asyncos A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to execute arbitrary system commands on an affected device with root | 29,9% | |
| CVE-2025-59718 | CRIT 9.8 | fortinet fortios A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, | 68,7% | |
| CVE-2025-14174 | HIGH 8.8 | apple ipados Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) | 22,6% | |
| CVE-2025-62221 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. | 2,4% | |
| CVE-2025-6218 | HIGH 7.8 | rarlab winrar RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of RARLAB WinRAR. User interaction is required to exploit this vulnerability in that the targe | 90,5% | |
| CVE-2021-26828 | HIGH 8.8 | scadabr scadabr OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm. | 39,4% | |
| CVE-2021-26829 | MED 5.4 | scadabr scadabr OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm. | 48,0% | |
| CVE-2025-58034 | HIGH 7.2 | fortinet fortiweb An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2 | 55,6% | |
| CVE-2025-64446 | CRIT 9.8 | fortinet fortiweb A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an attacker to execute administrative commands | 91,8% | |
| CVE-2025-62215 | HIGH 7.0 | microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally. | 6,0% | |
| CVE-2025-41244 | HIGH 7.8 | debian debian_linux VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploi | 8,1% | |
| CVE-2025-59287 | CRIT 9.8 | microsoft windows_server_2012 Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network. | 100,0% | |
| CVE-2025-33073 | HIGH 8.8 | microsoft windows_10_1507 Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network. | 80,4% | |
| CVE-2025-59230 | HIGH 7.8 | microsoft windows_10_1507 Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. | 2,7% | |
| CVE-2025-47827 | MED 4.6 | igel igel_os In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a crafted root filesystem can be mounted from an unverified SquashFS image. | 4,0% | |
| CVE-2025-24990 | HIGH 7.8 | microsoft windows_10_1507 Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an announcement of the upcoming removal of ltmdm64.sys driver. The driver has been removed in the October cumula | 6,3% | |
| CVE-2021-43226 | HIGH 7.8 | ransomware microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 3,1% | |
| CVE-2021-22555 | HIGH 8.3 | brocade fabric_operating_system A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space | 78,7% | |
| CVE-2013-3918 | HIGH 8.8 | microsoft windows_7 The InformationCardSigninHelper Class ActiveX control in icardie.dll in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, an | 73,9% |