58.586 CVE seguite
797 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.586 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2012-6346 | MED 6.1 | fortinet fortiweb Multiple cross-site scripting (XSS) vulnerabilities in FortiWeb before 4.4.4 allow remote attackers to inject arbitrary web script or HTML via the (1) redir or (2) mkey parameter to waf/pcre_expression/validate. | 0,8% | — |
| CVE-2026-53176 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN In drivers/infiniband/ulp/isert/ib_isert.c, isert_login_recv_done() computes the login request payload length as wc->byte_len minus | 0,8% | — |
| CVE-2024-43579 | HIGH 7.6 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 0,8% | — |
| CVE-2024-43578 | HIGH 7.6 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 0,8% | — |
| CVE-2024-43489 | MED 6.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 0,8% | — |
| CVE-2023-36800 | HIGH 7.6 | microsoft dynamics_365 Dynamics Finance and Operations Cross-site Scripting Vulnerability | 0,8% | — |
| CVE-2023-36404 | MED 5.5 | microsoft windows_10_1607 Windows Kernel Information Disclosure Vulnerability | 0,8% | — |
| CVE-2023-3640 | HIGH 7.0 | linux linux_kernel A possible unauthorized memory access flaw was found in the Linux kernel's cpu_entry_area mapping of X86 CPU data to memory, where a user may guess the location of exception stacks or other important data. Based on the previous CVE-2023-0597, the 'Randomize pe | 0,8% | — |
| CVE-2022-33876 | MED 5.4 | fortinet fortiadc Multiple instances of improper input validation vulnerability in Fortinet FortiADC version 7.1.0, version 7.0.0 through 7.0.2 and version 6.2.4 and below allows an authenticated attacker to retrieve files with specific extension from the underlying Linux syste | 0,8% | — |
| CVE-2021-27086 | HIGH 7.8 | microsoft windows_10 Windows Services and Controller App Elevation of Privilege Vulnerability | 0,8% | — |
| CVE-2020-9383 | HIGH 7.1 | canonical ubuntu_linux An issue was discovered in the Linux kernel 3.16 through 5.5.6. set_fdc in drivers/block/floppy.c leads to a wait_til_ready out-of-bounds read because the FDC index is not checked for errors before assigning it, aka CID-2e90ca68b0d2. | 0,8% | — |
| CVE-2019-15118 | MED 5.5 | canonical ubuntu_linux check_input_term in sound/usb/mixer.c in the Linux kernel through 5.2.9 mishandles recursion, leading to kernel stack exhaustion. | 0,8% | — |
| CVE-2017-3849 | HIGH 7.4 | cisco ios A vulnerability in the Autonomic Networking Infrastructure (ANI) registrar feature of Cisco IOS Software (possibly 15.2 through 15.6) and Cisco IOS XE Software (possibly 3.7 through 3.18, and 16) could allow an unauthenticated, adjacent attacker to cause a den | 0,8% | — |
| CVE-2012-2860 | MED 6.8 | google chrome The date-picker implementation in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allows user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact via a c | 0,8% | — |
| CVE-2007-4571 | LOW 2.1 | linux linux_kernel The snd_mem_proc_read function in sound/core/memalloc.c in the Advanced Linux Sound Architecture (ALSA) in the Linux kernel before 2.6.22.8 does not return the correct write size, which allows local users to obtain sensitive information (kernel memory contents | 0,8% | — |
| CVE-2026-78689 | HIGH 8.1 | Description NGINX JavaScript (njs) has a vulnerability in the XML module's namespace prefix list parser, reachable through the xml.exclusiveC14n() method. An unauthenticated remote attacker can trigger it when an affected NGINX configuration passes an extern | 0,8% | — |
| CVE-2025-62199 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 0,8% | — |
| CVE-2025-27737 | HIGH 8.6 | microsoft windows_10_1507 Improper input validation in Windows Security Zone Mapping allows an unauthorized attacker to bypass a security feature locally. | 0,8% | — |
| CVE-2024-42232 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: libceph: fix race between delayed_work() and ceph_monc_stop() The way the delayed work is handled in ceph_monc_stop() is prone to races with mon_fault() and possibly also finish_hunting(). | 0,8% | — |
| CVE-2024-26817 | MED 5.5 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: amdkfd: use calloc instead of kzalloc to avoid integer overflow This uses calloc instead of doing the multiplication which might overflow. | 0,8% | — |
| CVE-2023-23487 | MED 4.3 | ibm db2 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to insufficient audit logging. IBM X-Force ID: 245918. | 0,8% | — |
| CVE-2022-22048 | MED 6.1 | microsoft windows_10 BitLocker Security Feature Bypass Vulnerability | 0,8% | — |
| CVE-2021-31972 | MED 5.5 | microsoft windows_10 Event Tracing for Windows Information Disclosure Vulnerability | 0,8% | — |
| CVE-2021-31960 | MED 5.5 | microsoft windows_10 Windows Bind Filter Driver Information Disclosure Vulnerability | 0,8% | — |
| CVE-2021-31191 | MED 5.5 | microsoft windows_10 Windows Projected File System FS Filter Driver Information Disclosure Vulnerability | 0,8% | — |