EN
57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

57.971 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più basso In KEV dal, ordina dal più alto
CVE-2022-49060 MED 5.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/smc: Fix NULL pointer dereference in smc_pnet_find_ib() dev_name() was called with dev.parent as argument but without to NULL-check it before. Solve this by checking the pointer before t 0,3%
CVE-2022-49050 MED 5.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: memory: renesas-rpc-if: fix platform-device leak in error path Make sure to free the flash platform device in the event that registration fails during probe. 0,3%
CVE-2022-49014 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: tun: Fix use-after-free in tun_detach() syzbot reported use-after-free in tun_detach() [1]. This causes call trace like below: ======================================================== 0,3%
CVE-2022-41294 MED 6.5 ibm robotic_process_automation IBM Robotic Process Automation 21.0.0, 21.0.1, 21.0.2, 21.0.3, and 21.0.4 is vulnerable to cross origin resource sharing using the bot api. IBM X-Force ID: 236807. 0,3%
CVE-2022-22516 HIGH 7.8 codesys control_rte_sl The SysDrv3S driver in the CODESYS Control runtime system on Microsoft Windows allows any system user to read and write within restricted memory space. 0,3%
CVE-2022-20762 HIGH 7.8 cisco ultra_cloud_core_-_subscriber_microservices_infrastructure A vulnerability in the Common Execution Environment (CEE) ConfD CLI of Cisco Ultra Cloud Core - Subscriber Microservices Infrastructure (SMI) software could allow an authenticated, local attacker to escalate privileges on an affected device. This vulnerability 0,3%
CVE-2022-20729 MED 4.4 cisco secure_firewall_threat_defense A vulnerability in CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to inject XML into the command parser. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability 0,3%
CVE-2021-47588 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: sit: do not call ipip6_dev_free() from sit_init_net() ipip6_dev_free is sit dev->priv_destructor, already called by register_netdevice() if something goes wrong. Alternative would be to mak 0,3%
CVE-2021-47352 HIGH 8.4 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: virtio-net: Add validation for used length This adds validation for used length (might come from an untrusted device) to avoid data corruption or loss. 0,3%
CVE-2021-33063 HIGH 7.8 intel realsense_d400_series_universal_windows_platform_driver Uncontrolled search path in the Intel(R) RealSense(TM) D400 Series UWP driver for Windows 10 before version 6.1.160.22 may allow an authenticated user to potentially enable escalation of privilege via local access. 0,3%
CVE-2020-10742 MED 6.0 linux linux_kernel A flaw was found in the Linux kernel. An index buffer overflow during Direct IO write leading to the NFS client to crash. In some cases, a reach out of the index after one memory allocation by kmalloc will cause a kernel panic. The highest threat from this vul 0,3%
CVE-2019-5804 MED 5.5 google chrome Incorrect command line processing in Chrome in Google Chrome prior to 73.0.3683.75 allowed a local attacker to perform domain spoofing via a crafted domain name. 0,3%
CVE-2019-1810 MED 6.7 cisco nx-os A vulnerability in the Image Signature Verification feature used in an NX-OS CLI command in Cisco Nexus 3000 Series and 9000 Series Switches could allow an authenticated, local attacker with administrator-level credentials to install a malicious software image 0,3%
CVE-2017-6874 HIGH 7.0 linux linux_kernel Race condition in kernel/ucount.c in the Linux kernel through 4.10.2 allows local users to cause a denial of service (use-after-free and system crash) or possibly have unspecified other impact via crafted system calls that leverage certain decrement behavior t 0,3%
CVE-2009-4895 MED 4.7 canonical ubuntu_linux Race condition in the tty_fasync function in drivers/char/tty_io.c in the Linux kernel before 2.6.32.6 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via unknown vectors, re 0,3%
CVE-2026-9262 MED 6.5 canon eos_network_setting_tool Use of a non-secure protocol as the default FTP configuration in Canon EOS Network Setting Tool Version 1.5.0 or earlier 0,3%
CVE-2026-69267 MED 6.5 microsoft windows_10_1809 Insufficient granularity of access control in Windows Connected User Experiences and Telemetry allows an authorized attacker to disclose information locally. 0,3%
CVE-2026-58637 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-58629 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-58619 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-58544 HIGH 7.0 microsoft windows_11_24h2 Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-56183 HIGH 7.0 microsoft windows_11_24h2 Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-56173 HIGH 7.0 microsoft windows_10_1809 Use after free in Windows WebView allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-50449 HIGH 7.0 microsoft windows_10_1809 Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-50410 HIGH 7.0 microsoft windows_10_1809 Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. 0,3%