58.089 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.089 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più basso | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-41101 | HIGH 7.1 | microsoft word Improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing locally. | 0,3% | — |
| CVE-2026-34339 | MED 5.5 | microsoft windows_10_1607 Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to deny service locally. | 0,3% | — |
| CVE-2026-32682 | MED 6.5 | f5 nginx_gateway_fabric When NGINX Gateway Fabric is configured using GRPCRoutes, an authenticated, remote attacker with permission to create or modify GRPCRoute resources can cause the NGINX Gateway Fabric control plane to terminate by sending undisclosed GRPCRoute configurations co | 0,3% | — |
| CVE-2026-32221 | HIGH 8.4 | microsoft windows_11_24h2 Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code locally. | 0,3% | — |
| CVE-2026-32198 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0,3% | — |
| CVE-2026-26141 | HIGH 7.8 | microsoft azure_automation_hybrid_worker_windows_extension Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-20280 | HIGH 8.8 | cisco ios_xr As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple | 0,3% | — |
| CVE-2026-20049 | HIGH 7.7 | cisco adaptive_security_appliance_software A vulnerability in the processing of Galois/Counter Mode (GCM)-encrypted Internet Key Exchange version 2 (IKEv2) IPsec traffic of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could all | 0,3% | — |
| CVE-2025-59980 | MED 6.5 | juniper junos An Authentication Bypass by Primary Weakness in the FTP server of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to get limited read-write access to files on the device. When the FTP server is enabled and a user named "ftp" or "an | 0,3% | — |
| CVE-2025-55678 | HIGH 7.0 | microsoft windows_10_1507 Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2025-55223 | HIGH 7.0 | microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2025-54913 | HIGH 7.8 | microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows UI XAML Maps MapControlSettings allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2025-5180 | HIGH 7.0 | wondershare filmora A vulnerability, which was classified as critical, has been found in Wondershare Filmora 14.5.16. Affected by this issue is some unknown functionality in the library CRYPTBASE.dll of the file NFWCHK.exe of the component Installer. The manipulation leads to unc | 0,3% | — |
| CVE-2025-38264 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: sanitize request list handling Validate the request in nvme_tcp_handle_r2t() to ensure it's not part of any list, otherwise a malicious R2T PDU might inject a loop in request list | 0,3% | — |
| CVE-2025-27185 | MED 5.5 | adobe after_effects After Effects versions 25.1, 24.6.4 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-servic | 0,3% | — |
| CVE-2025-14806 | MED 5.7 | ibm planning_analytics_local IBM Planning Analytics Local 2.1.0 through 2.1.17 could allow an attacker to trick the caching mechanism into storing and serving sensitive, user-specific responses as publicly cacheable resources. | 0,3% | — |
| CVE-2024-46743 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: of/irq: Prevent device address out-of-bounds read in interrupt map walk When of_irq_parse_raw() is invoked with a device address smaller than the interrupt parent node (from #address-cells p | 0,3% | — |
| CVE-2024-41041 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: udp: Set SOCK_RCU_FREE earlier in udp_lib_get_port(). syzkaller triggered the warning [0] in udp_v4_early_demux(). In udp_v[46]_early_demux() and sk_lookup(), we do not touch the refcount o | 0,3% | — |
| CVE-2024-40963 | MED 5.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mips: bmips: BCM6358: make sure CBR is correctly set It was discovered that some device have CBR address set to 0 causing kernel panic when arch_sync_dma_for_cpu_all is called. This was not | 0,3% | — |
| CVE-2024-40927 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: xhci: Handle TD clearing for multiple streams case When multiple streams are in use, multiple TDs might be in flight when an endpoint is stopped. We need to issue a Set TR Dequeue Pointer fo | 0,3% | — |
| CVE-2024-39384 | HIGH 7.8 | adobe premiere_pro Premiere Pro versions 24.5, 23.6.8 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must ope | 0,3% | — |
| CVE-2024-27073 | HIGH 7.8 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: media: ttpci: fix two memleaks in budget_av_attach When saa7146_register_device and saa7146_vv_init fails, budget_av_attach should free the resources it allocates, like the error-handling of | 0,3% | — |
| CVE-2024-27038 | MED 5.5 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: clk: Fix clk_core_get NULL dereference It is possible for clk_core_get to dereference a NULL in the following sequence: clk_core_get() of_clk_get_hw_from_clkspec() __of_clk_get_ | 0,3% | — |
| CVE-2024-20782 | HIGH 7.8 | adobe indesign InDesign Desktop versions ID19.3, ID18.5.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim | 0,3% | — |
| CVE-2024-20403 | MED 4.8 | cisco firepower_management_center A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This v | 0,3% | — |