58.135 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.135 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più basso | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2016-1360 | HIGH 7.1 | cisco prime_lan_management_solution Cisco Prime LAN Management Solution (LMS) through 4.2.5 uses the same database decryption key across different customers' installations, which allows local users to obtain cleartext data by leveraging console connectivity, aka Bug ID CSCuw85390. | 0,3% | — |
| CVE-2016-0823 | MED 4.0 | google android The pagemap_open function in fs/proc/task_mmu.c in the Linux kernel before 3.19.3, as used in Android 6.0.1 before 2016-03-01, allows local users to obtain sensitive physical-address information by reading a pagemap file, aka Android internal bug 25739721. | 0,3% | — |
| CVE-2012-4081 | MED 4.6 | cisco unified_computing_system MCServer in the Cisco Management Controller in Cisco Unified Computing System (UCS) allows local users to cause a denial of service (application crash) via invalid MCTools parameters, aka Bug ID CSCtg20734. | 0,3% | — |
| CVE-2026-77488 | MED 5.5 | microsoft sql_server_2017 Integer underflow (wrap or wraparound) in SQL Server allows an authorized attacker to disclose information locally. | 0,3% | — |
| CVE-2026-7345 | HIGH 8.3 | google chrome Insufficient validation of untrusted input in Feedback in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Hig | 0,3% | — |
| CVE-2026-69900 | HIGH 7.8 | microsoft windows_10_21h2 Untrusted pointer dereference in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-69731 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in HID class driver allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-69369 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows DNS allows an authorized attacker to disclose information locally. | 0,3% | — |
| CVE-2026-69288 | MED 5.5 | microsoft windows_10_1607 Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally. | 0,3% | — |
| CVE-2026-65105 | HIGH 8.1 | nvidia nemoclaw NVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup, where a remote attacker may access the inference service without authentication. A successful exploit of this vulnerability may lead to information disclosure and denial of servi | 0,3% | — |
| CVE-2026-41728 | HIGH 7.5 | vmware spring_data_rest Spring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-access filter to intermediate path segments when resolving a multi-segment JSON Pointer. Affected versions: Spring Data REST 3.7.0 through 3.7.19; 4.3.0 throug | 0,3% | — |
| CVE-2026-30793 | CRIT 9.8 | rustdesk rustdesk Cross-Site Request Forgery (CSRF) vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Flutter URI scheme handler, FFI bridge modules) allows Privilege Escalation. This vulnerability is associated with progra | 0,3% | — |
| CVE-2026-14525 | CRIT 9.4 | ibm websphere_application_server IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnerable to an authentication bypass when the rtcomm-1.0 or rtcommGateway-1.0 feature is enabled. | 0,3% | — |
| CVE-2026-14113 | CRIT 9.6 | google chrome Use after free in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low) | 0,3% | — |
| CVE-2026-13861 | CRIT 9.6 | google chrome Use after free in Core in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) | 0,3% | — |
| CVE-2026-13859 | CRIT 9.6 | google chrome Inappropriate implementation in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) | 0,3% | — |
| CVE-2026-13854 | CRIT 9.6 | google chrome Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 0,3% | — |
| CVE-2026-13853 | CRIT 9.6 | google chrome Use after free in Journeys in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 0,3% | — |
| CVE-2026-11117 | HIGH 8.8 | google chrome Use after free in Views in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Medium) | 0,3% | — |
| CVE-2025-55670 | MED 6.5 | f5 big-ip_next_cloud-native_network_functions On BIG-IP Next CNF, BIG-IP Next SPK, and BIG-IP Next for Kubernetes systems, repeated undisclosed API calls can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not eva | 0,3% | — |
| CVE-2025-54838 | MED 6.8 | fortinet fortiportal An Incorrect Authorization vulnerability [CWE-863] in FortiPortal 7.4.0 through 7.4.5 may allow an authenticated attacker to reboot a shared FortiGate device via crafted HTTP requests. | 0,3% | — |
| CVE-2025-54805 | MED 6.5 | f5 big-ip_next_cloud-native_network_functions When an iRule is configured on a virtual server via the declarative API, upon re-instantiation, the cleanup process can cause an increase in the Traffic Management Microkernel (TMM) memory resource utilization. Note: Software versions which have reached End o | 0,3% | — |
| CVE-2025-53608 | MED 4.8 | fortinet fortisandbox An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all ver | 0,3% | — |
| CVE-2025-47991 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2025-39929 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: client: fix smbdirect_recv_io leak in smbd_negotiate() error path During tests of another unrelated patch I was able to trigger this error: Objects remaining on __kmem_cache_shutdown() | 0,3% | — |