58.650 CVE seguite
798 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.650 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-32773 | MED 6.1 | apache spark There is a lack of XSS escaping in the Spark History Server prior to 3.5.8 which allows a malicious Spark job to generate arbitrary unescaped frontend code which could lead to a minimal privilege escalation in browser. Users are encouraged to upgrade to Spark | 0,7% | — |
| CVE-2025-4178 | MED 5.4 | xiaowei1118 java_server A vulnerability was found in xiaowei1118 java_server up to 11a5bac8f4ba1c17e4bc1b27cad6d24868500e3a on Windows and classified as critical. This issue affects some unknown processing of the file /src/main/java/com/changyu/foryou/controller/FoodController.java o | 0,7% | — |
| CVE-2025-26683 | HIGH 8.1 | microsoft azure_playwright Improper authorization in Azure Playwright allows an unauthorized attacker to elevate privileges over a network. | 0,7% | — |
| CVE-2025-21399 | HIGH 7.4 | microsoft edge_update Microsoft Edge (Chromium-based) Update Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2024-47739 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: padata: use integer wrap around to prevent deadlock on seq_nr overflow When submitting more than 2^32 padata objects to padata_do_serial, the current sorting implementation incorrectly sorts | 0,7% | — |
| CVE-2023-52441 | CRIT 9.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out of bounds in init_smb2_rsp_hdr() If client send smb2 negotiate request and then send smb1 negotiate request, init_smb2_rsp_hdr is called for smb1 negotiate request since need_ | 0,7% | — |
| CVE-2023-36760 | HIGH 7.8 | microsoft 3d_viewer 3D Viewer Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2023-36740 | HIGH 7.8 | microsoft 3d_viewer 3D Viewer Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2023-36739 | HIGH 7.8 | microsoft 3d_viewer 3D Viewer Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2022-47984 | MED 6.3 | ibm infosphere_information_server IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 243163. | 0,7% | — |
| CVE-2022-45434 | MED 5.9 | dahuasecurity dhi-dss4004-s2_firmware Some Dahua software products have a vulnerability of unauthenticated un-throttled ICMP requests on remote DSS Server. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could exploi | 0,7% | — |
| CVE-2022-38022 | LOW 3.3 | microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2022-37997 | HIGH 7.8 | microsoft windows_10 Windows Graphics Component Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2021-43207 | HIGH 7.8 | microsoft windows_10 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2020-5018 | HIGH 7.5 | ibm spectrum_protect_plus IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may include sensitive information in its URLs increasing the risk of such information being caputured by an attacker. IBM X-Force ID: 193654. | 0,7% | — |
| CVE-2019-19332 | MED 6.1 | linux linux_kernel An out-of-bounds memory write issue was found in the Linux Kernel, version 3.13 through 5.4, in the way the Linux kernel's KVM hypervisor handled the 'KVM_GET_EMULATED_CPUID' ioctl(2) request to get CPUID features emulated by the KVM hypervisor. A user or proc | 0,7% | — |
| CVE-2016-2067 | HIGH 7.8 | google android drivers/gpu/msm/kgsl.c in the MSM graphics driver (aka GPU driver) for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, mishandles the KGSL_MEMFLAGS_GPUREADONLY flag, which allows atta | 0,7% | — |
| CVE-2014-1210 | MED 5.8 | vmware vsphere_client VMware vSphere Client 5.0 before Update 3 and 5.1 before Update 2 does not properly validate X.509 certificates, which allows man-in-the-middle attackers to spoof SSL servers via a crafted certificate. | 0,7% | — |
| CVE-2026-43187 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: xfs: delete attr leaf freemap entries when empty Back in commit 2a2b5932db6758 ("xfs: fix attr leaf header freemap.size underflow"), Brian Foster observed that it's possible for a small free | 0,7% | — |
| CVE-2026-43112 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath When cifs_sanitize_prepath is called with an empty string or a string containing only delimiters (e.g., "/"), the current logic | 0,7% | — |
| CVE-2023-28222 | HIGH 7.1 | microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2023-20081 | MED 6.8 | cisco adaptive_security_appliance_software A vulnerability in the IPv6 DHCP (DHCPv6) client module of Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense (FTD) Software, Cisco IOS Software, and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a | 0,7% | — |
| CVE-2023-20057 | NONE 0.0 | cisco asyncos A vulnerability in the URL filtering mechanism of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected device. This vulnerability is due to improp | 0,7% | — |
| CVE-2022-21912 | HIGH 7.8 | microsoft windows_10 DirectX Graphics Kernel Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2022-21875 | HIGH 7.0 | microsoft windows_10 Windows Storage Elevation of Privilege Vulnerability | 0,7% | — |