57.962 CVE seguite
784 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.962 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più basso | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2021-47654 | MED 5.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: samples/landlock: Fix path_list memory leak Clang static analysis reports this error sandboxer.c:134:8: warning: Potential leak of memory pointed to by 'path_list' ret = 0; | 0,3% | — |
| CVE-2021-47640 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: powerpc/kasan: Fix early region not updated correctly The shadow's page table is not updated when PTE_RPN_SHIFT is 24 and PAGE_SHIFT is 12. It not only causes false positives but also false | 0,3% | — |
| CVE-2021-47576 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: scsi: scsi_debug: Sanity check block descriptor length in resp_mode_select() In resp_mode_select() sanity check the block descriptor len to avoid UAF. BUG: KASAN: use-after-free in resp_mod | 0,3% | — |
| CVE-2021-47322 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: NFSv4: Fix an Oops in pnfs_mark_request_commit() when doing O_DIRECT Fix an Oopsable condition in pnfs_mark_request_commit() when we're putting a set of writes on the commit list to reschedu | 0,3% | — |
| CVE-2021-47035 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Remove WO permissions on second-level paging entries When the first level page table is used for IOVA translation, it only supports Read-Only and Read-Write permissions. The Writ | 0,3% | — |
| CVE-2021-46984 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: kyber: fix out of bounds access when preempted __blk_mq_sched_bio_merge() gets the ctx and hctx for the current CPU and passes the hctx to ->bio_merge(). kyber_bio_merge() then gets the ctx | 0,3% | — |
| CVE-2021-46904 | MED 5.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: hso: fix null-ptr-deref during tty device unregistration Multiple ttys try to claim the same the minor number causing a double unregistration of the same device. The first unregistratio | 0,3% | — |
| CVE-2021-1219 | HIGH 7.8 | cisco smart_software_manager_on-prem A vulnerability in Cisco Smart Software Manager Satellite could allow an authenticated, local attacker to access sensitive information on an affected system. The vulnerability is due to insufficient protection of static credentials in the affected software. An | 0,3% | — |
| CVE-2019-15962 | MED 4.4 | cisco telepresence_collaboration_endpoint A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, local attacker to write files to the /root directory of an affected device. The vulnerability is due to improper permission assignment. An attac | 0,3% | — |
| CVE-2012-2373 | MED 4.0 | linux linux_kernel The Linux kernel before 3.4.5 on the x86 platform, when Physical Address Extension (PAE) is enabled, does not properly use the Page Middle Directory (PMD), which allows local users to cause a denial of service (panic) via a crafted application that triggers a | 0,3% | — |
| CVE-2026-8547 | HIGH 7.5 | google chrome Insufficient policy enforcement in Passwords in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: High) | 0,3% | — |
| CVE-2026-65774 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-65672 | HIGH 7.8 | microsoft windows_11_23h2 Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-65671 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-62799 | HIGH 7.8 | microsoft windows_11_26h1 Heap-based buffer overflow in Windows SMB Client allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-60093 | MED 5.5 | apache camel Relative path traversal vulnerability in Apache Camel Azure-Storage Datalake component This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The camel-azure-storage-datalake component can downloa | 0,3% | — |
| CVE-2026-59276 | MED 5.9 | vmware spring_security Several components in Spring Security compare security-sensitive values using standard string equality (String.equals()) rather than a constant-time comparison. Because String.equals() returns as soon as it finds a differing character, the time taken to reject | 0,3% | — |
| CVE-2026-50512 | HIGH 7.8 | microsoft pc_manager Missing authentication for critical function in Microsoft PC Manager allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-39459 | HIGH 7.2 | f5 big-ip_access_policy_manager A vulnerability exists in iControl REST and the TMOS Shell (tmsh) where a highly privileged, authenticated attacker with at least the Manager role can create configuration objects that allow running arbitrary commands. Note: Software versions which have reac | 0,3% | — |
| CVE-2026-32074 | HIGH 7.8 | microsoft windows_10_1809 Double free in Windows Projected File System allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-32069 | HIGH 7.8 | microsoft windows_10_1809 Double free in Windows Projected File System allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-10890 | HIGH 8.8 | google chrome Use after free in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: Critical) | 0,3% | — |
| CVE-2025-52947 | MED 6.5 | juniper junos An Improper Handling of Exceptional Conditions vulnerability in route processing of Juniper Networks Junos OS on specific end-of-life (EOL) ACX Series platforms allows an attacker to crash the Forwarding Engine Board (FEB) by flapping an interface, leading to | 0,3% | — |
| CVE-2025-33138 | MED 5.4 | ibm aspera_faspex IBM Aspera Faspex 5.0.0 through 5.0.12 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. | 0,3% | — |
| CVE-2025-24789 | HIGH 7.8 | snowflake snowflake_jdbc Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connect to Snowflake. Snowflake discovered and remediated a vulnerability in the Snowflake JDBC Driver. When the EXTERNALBROWSER authentication method is us | 0,3% | — |