58.135 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.135 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più basso | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2016-8820 | MED 6.1 | nvidia gpu_driver All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where a check on a function return value is missing, potentially allowing an uninitialized value to be used as the source | 0,3% | — |
| CVE-2015-0603 | MED 4.6 | cisco unified_ip_phones_9900_series_firmware Cisco Unified IP 9900 phones with firmware 9.4(.1) and earlier use weak permissions for unspecified files, which allows local users to cause a denial of service (persistent hang or reboot) by writing to a phone's filesystem, aka Bug ID CSCup90474. | 0,3% | — |
| CVE-2015-0601 | MED 4.6 | cisco unified_ip_phones_9951_firmware Cisco Unified IP 9900 phones with firmware 9.4(.1) and earlier allow local users to cause a denial of service (device reload) via crafted commands, aka Bug ID CSCup92790. | 0,3% | — |
| CVE-2008-0163 | MED 4.4 | linux linux_kernel Linux kernel 2.6, when using vservers, allows local users to access resources of other vservers via a symlink attack in /proc. | 0,3% | — |
| CVE-2007-1089 | HIGH 7.2 | ibm db2_universal_database IBM DB2 Universal Database (UDB) 9.1 GA through 9.1 FP1 allows local users with table SELECT privileges to perform unauthorized UPDATE and DELETE SQL commands via unknown vectors. | 0,3% | — |
| CVE-2007-1056 | HIGH 7.2 | vmware workstation VMware Workstation 5.5.3 build 34685 does not provide per-user restrictions on certain privileged actions, which allows local users to perform restricted operations such as changing system time, accessing hardware components, and stopping the "VMware tools ser | 0,3% | — |
| CVE-2026-69895 | MED 4.7 | microsoft windows_10_1607 Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information locally. | 0,3% | — |
| CVE-2026-69853 | MED 4.7 | microsoft windows_10_1607 Use of uninitialized resource in Windows Win32K allows an authorized attacker to disclose information locally. | 0,3% | — |
| CVE-2026-69483 | MED 4.7 | microsoft windows_10_1607 Out-of-bounds read in Windows Image Acquisition allows an authorized attacker to disclose information locally. | 0,3% | — |
| CVE-2026-69316 | MED 4.7 | microsoft windows_10_1607 Buffer over-read in Windows Overlay Filter allows an authorized attacker to disclose information locally. | 0,3% | — |
| CVE-2026-68833 | MED 6.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack. | 0,3% | — |
| CVE-2026-54127 | HIGH 7.4 | microsoft windows_11_24h2 Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-50749 | MED 6.5 | apache answer Improper Authorization vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Any authenticated user can reject arbitrary pending edit-revisions without review permission due to a missing authorization check on the reject operation. | 0,3% | — |
| CVE-2026-48912 | MED 6.5 | apache answer Improper Input Validation vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing ownership check in the avatar-cleanup logic allows any authenticated user to delete other users' uploaded files by supplying their file URLs | 0,3% | — |
| CVE-2026-40419 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-3061 | CRIT 9.1 | google chrome Out of bounds read in Media in Google Chrome prior to 145.0.7632.116 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High) | 0,3% | — |
| CVE-2026-27316 | LOW 2.7 | fortinet fortisandbox A insufficiently protected credentials vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4 all versions, FortiSandbox PaaS 5.0.1 through 5.0.5 may allow an authenticathed administrator to read LDAP server credentials via client-side in | 0,3% | — |
| CVE-2026-20831 | HIGH 7.8 | microsoft windows_10_1607 Time-of-check time-of-use (toctou) race condition in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-20826 | HIGH 7.8 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-10917 | HIGH 8.3 | google chrome Insufficient validation of untrusted input in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 0,3% | — |
| CVE-2026-10911 | HIGH 8.3 | google chrome Insufficient validation of untrusted input in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 0,3% | — |
| CVE-2025-66495 | HIGH 7.8 | foxit pdf_editor A use-after-free vulnerability exists in the annotation handling of Foxit PDF Reader before 2025.2.1, 14.0.1, and 13.2.1 on Windows and MacOS. When opening a PDF containing specially crafted JavaScript, a pointer to memory that has already been freed may be ac | 0,3% | — |
| CVE-2025-66494 | HIGH 7.8 | foxit pdf_editor A use-after-free vulnerability exists in the PDF file parsing of Foxit PDF Reader before 2025.2.1, 14.0.1, and 13.2.1 on Windows. A PDF object managed by multiple parent objects could be freed while still being referenced, potentially allowing a remote attacke | 0,3% | — |
| CVE-2025-66493 | HIGH 7.8 | foxit pdf_editor A use-after-free vulnerability exists in the AcroForm handling of Foxit PDF Reader and Foxit PDF Editor before 2025.2.1,14.0.1 and 13.2.1 on Windows . When opening a PDF containing specially crafted JavaScript, a pointer to memory that has already been free | 0,3% | — |
| CVE-2025-59187 | HIGH 7.8 | microsoft windows_10_1507 Improper input validation in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0,3% | — |