EN
57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

57.971 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più basso In KEV dal, ordina dal più alto
CVE-2018-0449 MED 4.2 cisco jabber A vulnerability in the Cisco Jabber Client Framework (JCF) software, installed as part of the Cisco Jabber for Mac client, could allow an authenticated, local attacker to corrupt arbitrary files on an affected device that has elevated privileges. The vulnerabi 0,3%
CVE-2014-9710 MED 6.9 linux linux_kernel The Btrfs implementation in the Linux kernel before 3.19 does not ensure that the visible xattr state is consistent with a requested replacement, which allows local users to bypass intended ACL settings and gain privileges via standard filesystem operations (1 0,3%
CVE-2009-1142 MED 6.7 vmware open_vm_tools An issue was discovered in open-vm-tools 2009.03.18-154848. Local users can gain privileges via a symlink attack on /tmp files if vmware-user-suid-wrapper is setuid root and the ChmodChownDirectory function is enabled. 0,3%
CVE-2007-0833 LOW 1.2 vmware workstation VMware Workstation 5.5.3 34685, when the "Enable copy and paste to and from this virtual machine" option is enabled, preserves clipboard data on the guest operating system after it was deleted on the host operating system, which might allow local users to read 0,3%
CVE-2007-0832 LOW 1.2 vmware workstation VMware Workstation 5.5.3 34685 does not immediately change the availability of a shared clipboard when the "Enable copy and paste to and from this virtual machine" checkbox is changed, which allows local users to obtain sensitive information or conduct certain 0,3%
CVE-2026-84000 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to execute code locally. 0,3%
CVE-2026-83990 HIGH 7.8 microsoft windows_11_23h2 Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-61367 HIGH 7.8 microsoft windows_10_1607 Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-61365 HIGH 7.8 microsoft windows_10_1607 Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-61364 HIGH 7.8 microsoft windows_10_1607 Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-61356 HIGH 7.8 microsoft windows_10_1809 Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-21240 HIGH 7.8 microsoft windows_10_1809 Time-of-check time-of-use (toctou) race condition in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-13931 MED 6.5 google chrome Inappropriate implementation in Media in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) 0,3%
CVE-2026-11037 CRIT 9.6 google chrome Out of bounds write in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: Medium) 0,3%
CVE-2026-11030 HIGH 8.8 google chrome Use after free in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: Medium) 0,3%
CVE-2025-49742 HIGH 7.8 microsoft windows_10_1507 Integer overflow or wraparound in Microsoft Graphics Component allows an authorized attacker to execute code locally. 0,3%
CVE-2025-49732 HIGH 7.8 microsoft windows_10_1507 Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2025-49725 HIGH 7.8 microsoft windows_10_1607 Use after free in Windows Notification allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2025-30680 HIGH 7.1 trendmicro apex_central A Server-side Request Forgery (SSRF) vulnerability in Trend Micro Apex Central (SaaS) could allow an attacker to manipulate certain parameters leading to information disclosure on affected installations. Please note: this vulnerability only affects the Sa 0,3%
CVE-2024-56677 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: powerpc/fadump: Move fadump_cma_init to setup_arch() after initmem_init() During early init CMA_MIN_ALIGNMENT_BYTES can be PAGE_SIZE, since pageblock_order is still zero and it gets initiali 0,3%
CVE-2024-52998 MED 5.5 adobe substance_3d_stager Substance3D - Stager versions 3.0.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue 0,3%
CVE-2024-49883 HIGH 7.8 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: ext4: aovid use-after-free in ext4_ext_insert_extent() As Ojaswin mentioned in Link, in ext4_ext_insert_extent(), if the path is reallocated in ext4_ext_create_new_leaf(), we'll use the stal 0,3%
CVE-2024-46674 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: st: fix probed platform device ref count on probe error path The probe function never performs any paltform device allocation, thus error path "undo_platform_dev_alloc" is entirel 0,3%
CVE-2024-41057 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: cachefiles: fix slab-use-after-free in cachefiles_withdraw_cookie() We got the following issue in our fault injection stress test: ========================================================== 0,3%
CVE-2024-40993 MED 5.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: Fix suspicious rcu_dereference_protected() When destroying all sets, we are either in pernet exit phase or are executing a "destroy all sets command" from userspace. The la 0,3%