57.551 CVE seguite
782 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.551 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più basso | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2021-4439 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: isdn: cpai: check ctr->cnr to avoid array index out of bound The cmtp_add_connection() would add a cmtp session to a controller and run a kernel thread to process cmtp. __module_get(THIS_M | 0,2% | — |
| CVE-2020-36691 | MED 5.5 | linux linux_kernel An issue was discovered in the Linux kernel before 5.8. lib/nlattr.c allows attackers to cause a denial of service (unbounded recursion) via a nested Netlink policy with a back reference. | 0,2% | — |
| CVE-2026-50325 | HIGH 7.0 | microsoft windows_10_1607 Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-50297 | HIGH 7.0 | microsoft windows_10_1607 Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-49805 | HIGH 7.0 | microsoft windows_10_1607 Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-22741 | LOW 3.1 | vmware spring_framework Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources. More precisely, an application can be vulnerable when all the following are true: * the application is using Spring MVC or Spring WebFlux * the appl | 0,2% | — |
| CVE-2026-21274 | HIGH 7.8 | adobe dreamweaver Dreamweaver Desktop versions 21.6 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could leverage this vulnerability to bypass security measures a | 0,2% | — |
| CVE-2026-18636 | MED 6.8 | The Velociraptor gRPC API has a VFSGetBuffer endpoint which allows reading files from the datastore. To prevent users from reading sensitive files or accessing other orgs, the requested path is prefix checked against a list of denied prefixes. This prefix chec | 0,2% | — |
| CVE-2026-11303 | HIGH 8.8 | google chrome Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low) | 0,2% | — |
| CVE-2025-69271 | HIGH 7.5 | broadcom dx_netops_spectrum Insufficiently Protected Credentials vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Sniffing Attacks.This issue affects DX NetOps Spectrum: 24.3.13 and earlier. | 0,2% | — |
| CVE-2025-58725 | HIGH 7.0 | microsoft windows_10_1507 Heap-based buffer overflow in Windows COM allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2025-54279 | HIGH 7.8 | adobe animate Animate versions 23.0.13, 24.0.10 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a mal | 0,2% | — |
| CVE-2025-46777 | LOW 2.3 | fortinet fortiportal A insertion of sensitive information into log file in Fortinet FortiPortal versions 7.4.0, versions 7.2.0 through 7.2.5, and versions 7.0.0 through 7.0.9 may allow an authenticated attacker with at least read-only admin permissions to view encrypted secrets vi | 0,2% | — |
| CVE-2025-39848 | HIGH 8.8 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: ax25: properly unshare skbs in ax25_kiss_rcv() Bernard Pidoux reported a regression apparently caused by commit c353e8983e0d ("net: introduce per netns packet chains"). skb->dev becomes NUL | 0,2% | — |
| CVE-2025-21792 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ax25: Fix refcount leak caused by setting SO_BINDTODEVICE sockopt If an AX25 device is bound to a socket by setting the SO_BINDTODEVICE socket option, a refcount leak will occur in ax25_rele | 0,2% | — |
| CVE-2025-21664 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: dm thin: make get_first_thin use rcu-safe list first function The documentation in rculist.h explains the absence of list_empty_rcu() and cautions programmers against relying on a list_empty | 0,2% | — |
| CVE-2025-21602 | MED 6.5 | juniper junos An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker sending a specific BGP update packet to cause rpd to crash and resta | 0,2% | — |
| CVE-2025-21593 | MED 6.5 | juniper junos An Improper Control of a Resource Through its Lifetime vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker to cause a Denial-of-Service (DoS). On devices with SR | 0,2% | — |
| CVE-2025-20141 | HIGH 7.4 | cisco ios_xr A vulnerability in the handling of specific packets that are punted from a line card to a route processor in Cisco IOS XR Software Release 7.9.2 could allow an unauthenticated, adjacent attacker to cause control plane traffic to stop working on multiple Cisco | 0,2% | — |
| CVE-2024-57998 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: OPP: add index check to assert to avoid buffer overflow in _read_freq() Pass the freq index to the assert function to make sure we do not read a freq out of the opp->rates[] table when calle | 0,2% | — |
| CVE-2024-56581 | HIGH 7.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: btrfs: ref-verify: fix use-after-free after invalid ref action At btrfs_ref_tree_mod() after we successfully inserted the new ref entry (local variable 'ref') into the respective block entry | 0,2% | — |
| CVE-2024-54458 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: bsg: Set bsg_queue to NULL after removal Currently, this does not cause any issues, but I believe it is necessary to set bsg_queue to NULL after removing it to prevent potential u | 0,2% | — |
| CVE-2024-53878 | LOW 2.8 | nvidia cuda_toolkit NVIDIA CUDA toolkit for Linux and Windows contains a vulnerability in the cuobjdump binary, where a user could cause a crash by passing a malformed ELF file to cuobjdump. A successful exploit of this vulnerability might lead to a partial denial of service. | 0,2% | — |
| CVE-2024-53231 | MED 5.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: cpufreq: CPPC: Fix possible null-ptr-deref for cpufreq_cpu_get_raw() cpufreq_cpu_get_raw() may return NULL if the cpu is not in policy->cpus cpu mask and it will cause null pointer dereferen | 0,2% | — |
| CVE-2024-53230 | MED 5.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: cpufreq: CPPC: Fix possible null-ptr-deref for cppc_get_cpu_cost() cpufreq_cpu_get_raw() may return NULL if the cpu is not in policy->cpus cpu mask and it will cause null pointer dereference | 0,2% | — |