58.650 CVE seguite
799 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.650 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2024-38209 | HIGH 7.8 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 0,7% | — |
| CVE-2024-27254 | MED 5.3 | ibm db2 IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 federated server is vulnerable to denial of service with a specially crafted query under certain conditions. IBM X-Force ID: 283813. | 0,7% | — |
| CVE-2023-4273 | MED 6.0 | debian debian_linux A flaw was found in the exFAT driver of the Linux kernel. The vulnerability exists in the implementation of the file name reconstruction function, which is responsible for reading file name entries from a directory index and merging file name parts belonging t | 0,7% | — |
| CVE-2023-36860 | HIGH 7.1 | intel unison_software Improper input validation for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via network access. | 0,7% | — |
| CVE-2022-48829 | CRIT 9.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix NFSv3 SETATTR/CREATE's handling of large file sizes iattr::ia_size is a loff_t, so these NFSv3 procedures must be careful to deal with incoming client size values that are larger t | 0,7% | — |
| CVE-2022-41083 | HIGH 7.8 | microsoft jupyter Visual Studio Code Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2022-37999 | HIGH 7.8 | microsoft windows_10 Windows Group Policy Preference Client Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2022-37994 | HIGH 7.8 | microsoft windows_10 Windows Group Policy Preference Client Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2022-37993 | HIGH 7.8 | microsoft windows_10 Windows Group Policy Preference Client Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2022-30305 | LOW 3.7 | fortinet fortideceptor An insufficient logging [CWE-778] vulnerability in FortiSandbox versions 4.0.0 to 4.0.2, 3.2.0 to 3.2.3 and 3.1.0 to 3.1.5 and FortiDeceptor versions 4.2.0, 4.1.0 through 4.1.1, 4.0.0 through 4.0.2, 3.3.0 through 3.3.3, 3.2.0 through 3.2.2,3.1.0 through 3.1.1 | 0,7% | — |
| CVE-2022-24484 | MED 5.5 | microsoft windows_server_2012 Windows Cluster Shared Volume (CSV) Denial of Service Vulnerability | 0,7% | — |
| CVE-2022-23268 | MED 6.5 | microsoft windows_11 Windows Hyper-V Denial of Service Vulnerability | 0,7% | — |
| CVE-2021-38896 | MED 6.1 | ibm qradar_advisor IBM QRadar Advisor 2.5 through 2.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted | 0,7% | — |
| CVE-2021-29712 | MED 6.1 | ibm infosphere_information_server IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trust | 0,7% | — |
| CVE-2020-3953 | MED 4.8 | vmware vrealize_log_insight Cross Site Scripting (XSS) vulnerability exists in VMware vRealize Log Insight prior to 8.1.0 due to improper Input validation. | 0,7% | — |
| CVE-2019-6593 | MED 5.9 | f5 big-ip_access_policy_manager On BIG-IP 11.5.1-11.5.4, 11.6.1, and 12.1.0, a virtual server configured with a Client SSL profile may be vulnerable to a chosen ciphertext attack against CBC ciphers. When exploited, this may result in plaintext recovery of encrypted messages through a man-in | 0,7% | — |
| CVE-2018-15801 | HIGH 7.4 | vmware spring_framework Spring Security versions 5.1.x prior to 5.1.2 contain an authorization bypass vulnerability during JWT issuer validation. In order to be impacted, the same private key for an honest issuer and a malicious user must be used when signing JWTs. In that case, a ma | 0,7% | — |
| CVE-2014-1438 | MED 4.7 | linux linux_kernel The restore_fpu_checking function in arch/x86/include/asm/fpu-internal.h in the Linux kernel before 3.12.8 on the AMD K7 and K8 platforms does not clear pending exceptions before proceeding to an EMMS instruction, which allows local users to cause a denial of | 0,7% | — |
| CVE-2011-1353 | MED 6.9 | adobe acrobat_reader Unspecified vulnerability in Adobe Reader 10.x before 10.1.1 on Windows allows local users to gain privileges via unknown vectors. | 0,7% | — |
| CVE-2026-82435 | CRIT 9.8 | Description The worker's Netty message decoder is installed ahead of the SASL authentication handlers in the pipeline and acts on frames before any authentication has taken place. It allocated buffers sized from a length field carried in the frame, so a singl | 0,7% | — |
| CVE-2026-69474 | MED 4.8 | microsoft windows_10_1607 Use after free in Windows Overlay Filter allows an authorized attacker to disclose information over a network. | 0,7% | — |
| CVE-2026-65432 | HIGH 7.5 | apache cxf Apache CXF reads a top-level WSDL through its hardened StaxUtils path, which disables XML DTDs and external entities. However, any <wsdl:import> or <xsd:import> referenced from that top-level WSDL is handed off to WSDL4J, which does not disable DOCTYPE declara | 0,7% | — |
| CVE-2026-64061 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfs: Fix early put of sink folio in netfs_read_gaps() Fix netfs_read_gaps() to release the sink page it uses after waiting for the request to complete. The way the sink page is used is th | 0,7% | — |
| CVE-2026-53404 | HIGH 7.3 | apache tomcat Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat's rewrite valve meant that if the first condition in an OR chain matched, subsequent non-OR conditions were skipped. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, | 0,7% | — |
| CVE-2026-43379 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in smb_lazy_parent_lease_break_close() opinfo pointer obtained via rcu_dereference(fp->f_opinfo) is being accessed after rcu_read_unlock() has been called. This cre | 0,7% | — |