EN
58.650 CVE seguite
799 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.650 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più alto In KEV dal, ordina dal più alto
CVE-2025-58136 HIGH 7.5 apache traffic_server A bug in POST request handling causes a crash under a certain condition. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.1, from 9.0.0 through 9.2.12. Users are recommended to upgrade to version 10.1.2 or 9.2.13, which fix the issue. A wo 0,7% —
CVE-2024-38047 HIGH 7.8 microsoft windows_10_1607 PowerShell Elevation of Privilege Vulnerability 0,7% —
CVE-2023-36551 MED 4.3 fortinet fortisiem A exposure of sensitive information to an unauthorized actor in Fortinet FortiSIEM version 6.7.0 through 6.7.5 allows attacker to information disclosure via a crafted http request. 0,7% —
CVE-2023-33171 HIGH 8.2 microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability 0,7% —
CVE-2023-28314 MED 6.1 microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability 0,7% —
CVE-2023-21753 MED 5.5 microsoft windows_10 Event Tracing for Windows Information Disclosure Vulnerability 0,7% —
CVE-2022-48658 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mm: slub: fix flush_cpu_slab()/__free_slab() invocations in task context. Commit 5a836bf6b09f ("mm: slub: move flush_cpu_slab() invocations __free_slab() invocations out of IRQ context") mov 0,7% —
CVE-2022-31663 MED 6.1 vmware access_connector VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a reflected cross-site scripting (XSS) vulnerability. Due to improper user input sanitization, a malicious actor with some user interaction may be able to inject javascript code in t 0,7% —
CVE-2022-21867 HIGH 7.0 microsoft windows_10 Windows Push Notifications Apps Elevation of Privilege Vulnerability 0,7% —
CVE-2022-21863 HIGH 7.0 microsoft windows_10 Windows StateRepository API Server file Elevation of Privilege Vulnerability 0,7% —
CVE-2020-16983 MED 5.7 microsoft azure_sphere Azure Sphere Tampering Vulnerability 0,7% —
CVE-2014-7970 MED 5.5 canonical ubuntu_linux The pivot_root implementation in fs/namespace.c in the Linux kernel through 3.17 does not properly interact with certain locations of a chroot directory, which allows local users to cause a denial of service (mount-tree loop) via . (dot) values in both argumen 0,7% —
CVE-2011-0562 MED 6.9 adobe acrobat Untrusted search path vulnerability in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows allows local users to gain privileges via a Trojan horse DLL in the current working directory, a different vulnerability than 0,7% —
CVE-2009-1914 MED 4.9 linux linux_kernel The pci_register_iommu_region function in arch/sparc/kernel/pci_common.c in the Linux kernel before 2.6.29 on the sparc64 platform allows local users to cause a denial of service (system crash) by reading the /proc/iomem file, related to uninitialized pointers 0,7% —
CVE-2026-64398 HIGH 8.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: add a permission check for FSCTL_SET_ZERO_DATA FSCTL_SET_ZERO_DATA in smb2_ioctl() destroys file data via ksmbd_vfs_zero_data() -> vfs_fallocate(PUNCH_HOLE/ZERO_RANGE) after checking 0,7% —
CVE-2026-47629 HIGH 7.5 nvidia triton_inference_server NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause improper input validation. A successful exploit might lead to denial of service. 0,7% —
CVE-2026-47628 HIGH 7.5 nvidia triton_inference_server NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an allocation of resources without limits. A successful exploit might lead to denial of service. 0,7% —
CVE-2026-13473 HIGH 8.1 ibm storage_protect IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 through 8.2.1.0 IBM Storage Protect is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote attacker could overflow a buffer and execute arbitrary co 0,7% —
CVE-2025-62220 HIGH 8.8 microsoft windows_subsystem_for_linux Heap-based buffer overflow in Windows Subsystem for Linux GUI allows an unauthorized attacker to execute code over a network. 0,7% —
CVE-2025-53156 MED 5.5 microsoft windows_11_24h2 Exposure of sensitive information to an unauthorized actor in Storage Port Driver allows an authorized attacker to disclose information locally. 0,7% —
CVE-2025-21346 HIGH 7.1 microsoft 365_apps Microsoft Office Security Feature Bypass Vulnerability 0,7% —
CVE-2024-43625 HIGH 8.1 microsoft windows_11_22h2 Microsoft Windows VMSwitch Elevation of Privilege Vulnerability 0,7% —
CVE-2024-41073 CRIT 9.8 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: nvme: avoid double free special payload If a discard request needs to be retried, and that retry may fail before a new special payload is added, a double free will result. Clear the RQF_SPEC 0,7% —
CVE-2024-1552 HIGH 7.5 debian debian_linux Incorrect code generation could have led to unexpected numeric conversions and potential undefined behavior.*Note:* This issue only affects 32-bit ARM devices. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8. 0,7% —
CVE-2024-0136 HIGH 7.6 nvidia nvidia_container_toolkit NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to untrusted code obtaining read and write access to host devices. This vulnerability is present only when the NVIDIA Container Toolkit i 0,7% —