57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.971 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più basso | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2022-49060 | MED 5.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/smc: Fix NULL pointer dereference in smc_pnet_find_ib() dev_name() was called with dev.parent as argument but without to NULL-check it before. Solve this by checking the pointer before t | 0,3% | — |
| CVE-2022-49050 | MED 5.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: memory: renesas-rpc-if: fix platform-device leak in error path Make sure to free the flash platform device in the event that registration fails during probe. | 0,3% | — |
| CVE-2022-49014 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: tun: Fix use-after-free in tun_detach() syzbot reported use-after-free in tun_detach() [1]. This causes call trace like below: ======================================================== | 0,3% | — |
| CVE-2022-41294 | MED 6.5 | ibm robotic_process_automation IBM Robotic Process Automation 21.0.0, 21.0.1, 21.0.2, 21.0.3, and 21.0.4 is vulnerable to cross origin resource sharing using the bot api. IBM X-Force ID: 236807. | 0,3% | — |
| CVE-2022-22516 | HIGH 7.8 | codesys control_rte_sl The SysDrv3S driver in the CODESYS Control runtime system on Microsoft Windows allows any system user to read and write within restricted memory space. | 0,3% | — |
| CVE-2022-20762 | HIGH 7.8 | cisco ultra_cloud_core_-_subscriber_microservices_infrastructure A vulnerability in the Common Execution Environment (CEE) ConfD CLI of Cisco Ultra Cloud Core - Subscriber Microservices Infrastructure (SMI) software could allow an authenticated, local attacker to escalate privileges on an affected device. This vulnerability | 0,3% | — |
| CVE-2022-20729 | MED 4.4 | cisco secure_firewall_threat_defense A vulnerability in CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to inject XML into the command parser. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability | 0,3% | — |
| CVE-2021-47588 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: sit: do not call ipip6_dev_free() from sit_init_net() ipip6_dev_free is sit dev->priv_destructor, already called by register_netdevice() if something goes wrong. Alternative would be to mak | 0,3% | — |
| CVE-2021-47352 | HIGH 8.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: virtio-net: Add validation for used length This adds validation for used length (might come from an untrusted device) to avoid data corruption or loss. | 0,3% | — |
| CVE-2021-33063 | HIGH 7.8 | intel realsense_d400_series_universal_windows_platform_driver Uncontrolled search path in the Intel(R) RealSense(TM) D400 Series UWP driver for Windows 10 before version 6.1.160.22 may allow an authenticated user to potentially enable escalation of privilege via local access. | 0,3% | — |
| CVE-2020-10742 | MED 6.0 | linux linux_kernel A flaw was found in the Linux kernel. An index buffer overflow during Direct IO write leading to the NFS client to crash. In some cases, a reach out of the index after one memory allocation by kmalloc will cause a kernel panic. The highest threat from this vul | 0,3% | — |
| CVE-2019-5804 | MED 5.5 | google chrome Incorrect command line processing in Chrome in Google Chrome prior to 73.0.3683.75 allowed a local attacker to perform domain spoofing via a crafted domain name. | 0,3% | — |
| CVE-2019-1810 | MED 6.7 | cisco nx-os A vulnerability in the Image Signature Verification feature used in an NX-OS CLI command in Cisco Nexus 3000 Series and 9000 Series Switches could allow an authenticated, local attacker with administrator-level credentials to install a malicious software image | 0,3% | — |
| CVE-2017-6874 | HIGH 7.0 | linux linux_kernel Race condition in kernel/ucount.c in the Linux kernel through 4.10.2 allows local users to cause a denial of service (use-after-free and system crash) or possibly have unspecified other impact via crafted system calls that leverage certain decrement behavior t | 0,3% | — |
| CVE-2009-4895 | MED 4.7 | canonical ubuntu_linux Race condition in the tty_fasync function in drivers/char/tty_io.c in the Linux kernel before 2.6.32.6 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via unknown vectors, re | 0,3% | — |
| CVE-2026-9262 | MED 6.5 | canon eos_network_setting_tool Use of a non-secure protocol as the default FTP configuration in Canon EOS Network Setting Tool Version 1.5.0 or earlier | 0,3% | — |
| CVE-2026-69267 | MED 6.5 | microsoft windows_10_1809 Insufficient granularity of access control in Windows Connected User Experiences and Telemetry allows an authorized attacker to disclose information locally. | 0,3% | — |
| CVE-2026-58637 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-58629 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-58619 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-58544 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-56183 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-56173 | HIGH 7.0 | microsoft windows_10_1809 Use after free in Windows WebView allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-50449 | HIGH 7.0 | microsoft windows_10_1809 Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-50410 | HIGH 7.0 | microsoft windows_10_1809 Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. | 0,3% | — |