EN
58.587 CVE seguite
797 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.587 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più alto In KEV dal, ordina dal più alto
CVE-2019-25160 CRIT 9.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netlabel: fix out-of-bounds memory accesses There are two array out-of-bounds memory accesses, one in cipso_v4_map_lvl_valid(), the other in netlbl_bitmap_walk(). Both errors are embarassin 0,8% —
CVE-2018-10878 HIGH 7.8 canonical ubuntu_linux A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bounds write and a denial of service or unspecified other impact is possible by mounting and operating a crafted ext4 filesystem image. 0,8% —
CVE-2017-5646 MED 6.8 apache knox For versions of Apache Knox from 0.2.0 to 0.11.0 - an authenticated user may use a specially crafted URL to impersonate another user while accessing WebHDFS through Apache Knox. This may result in escalated privileges and unauthorized data access. While this a 0,8% —
CVE-2025-26413 HIGH 7.5 apache kvrocks Improper Input Validation vulnerability in Apache Kvrocks. The SETRANGE command didn't check if the `offset` input is a positive integer and use it as an index of a string. So it will cause the server to crash due to its index is  out of range. This issue aff 0,8% —
CVE-2025-21264 HIGH 7.1 microsoft visual_studio_code Files or directories accessible to external parties in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. 0,8% —
CVE-2024-41036 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: ks8851: Fix deadlock with the SPI chip variant When SMP is enabled and spinlocks are actually functional then there is a deadlock with the 'statelock' spinlock between ks8851_start_xmit 0,8% —
CVE-2024-30341 HIGH 7.8 foxit pdf_editor Foxit PDF Reader Doc Object Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability i 0,8% —
CVE-2023-27497 CRIT 10.0 sap diagnostics_agent Due to missing authentication and input sanitization of code the EventLogServiceCollector of SAP Diagnostics Agent - version 720, allows an attacker to execute malicious scripts on all connected Diagnostics Agents running on Windows. On successful exploitation 0,8% —
CVE-2021-3679 MED 5.5 debian debian_linux A lack of CPU resource in the Linux kernel tracing module functionality in versions prior to 5.14-rc3 was found in the way user uses trace ring buffer in a specific way. Only privileged local users (with CAP_SYS_ADMIN capability) could use this flaw to starve 0,8% —
CVE-2012-2853 MED 6.8 google chrome The webRequest API in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, does not properly interact with the Chrome Web Store, which allows remote attackers to cause a denial of service or possibly hav 0,8% —
CVE-2012-2847 MED 4.3 google chrome Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, does not request user confirmation before continuing a large series of downloads, which allows user-assisted remote attackers to cause a denial of ser 0,8% —
CVE-2026-26035 CRIT 9.8 fortinet fortiweb An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow a remote unauthentica 0,8% —
CVE-2026-20834 MED 4.6 microsoft windows_10_1607 Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a physical attack. 0,8% —
CVE-2026-0279 MED 6.1 paloaltonetworks pan-os Multiple cross site scripting vulnerabilities in the User-ID™ Authentication Portal (aka Captive Portal) service, GlobalProtect™ gateway/portal features and Clientless VPN of Palo Alto Networks PAN-OS® software enables a malicious unauthenticated user to store 0,8% —
CVE-2024-49044 MED 6.7 microsoft visual_studio_2022 Visual Studio Elevation of Privilege Vulnerability 0,8% —
CVE-2024-38166 HIGH 8.2 microsoft dynamics_crm_service_portal_web_resource An unauthenticated attacker can exploit improper neutralization of input during web page generation in Microsoft Dynamics 365 to spoof over a network by tricking a user to click on a link. 0,8% —
CVE-2024-36471 HIGH 7.5 apache allura Import functionality is vulnerable to DNS rebinding attacks between verification and processing of the URL.  Project administrators can run these imports, which could cause Allura to read from internal services and expose them. This issue affects Apache Allur 0,8% —
CVE-2024-36288 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Fix loop termination condition in gss_free_in_token_pages() The in_token->pages[] array is not NULL terminated. This results in the following KASAN splat: KASAN: maybe wild-memory 0,8% —
CVE-2023-32051 HIGH 7.8 microsoft raw_image_extension Raw Image Extension Remote Code Execution Vulnerability 0,8% —
CVE-2023-20030 MED 6.0 cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access sensitive information, conduct a server-side request forgery (SSRF) attack through an affected device, or nega 0,8% —
CVE-2022-20740 MED 6.1 cisco secure_firewall_management_center A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting attack. This vulnerability is due to improper validation of user-supplie 0,8% —
CVE-2021-47131 HIGH 8.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/tls: Fix use-after-free after the TLS device goes down and up When a netdev with active TLS offload goes down, tls_device_down is called to stop the offload and tear down the TLS context 0,8% —
CVE-2021-43246 MED 5.6 microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability 0,8% —
CVE-2021-24023 HIGH 7.8 fortinet fortiai_firmware An improper input validation in FortiAI v1.4.0 and earlier may allow an authenticated user to gain system shell access via a malicious payload in the "diagnose" command. 0,8% —
CVE-2020-1312 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations.To exploit the vulnerability, an attacker would require unprivileged execution on the victim system, aka 'Windows Ins 0,8% —