58.254 CVE seguite
789 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.254 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più basso | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-69784 | HIGH 8.8 | microsoft windows_10_21h2 Use after free in Windows Hello allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-69740 | HIGH 8.8 | microsoft windows_11_23h2 Use after free in Windows Hello allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-69725 | HIGH 7.8 | microsoft windows_10_21h2 Double free in Windows Hello allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-69603 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally. | 0,3% | — |
| CVE-2026-65662 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows GDI allows an authorized attacker to disclose information locally. | 0,3% | — |
| CVE-2026-62798 | MED 5.5 | microsoft windows_11_23h2 Untrusted pointer dereference in Windows Win32K allows an authorized attacker to disclose information locally. | 0,3% | — |
| CVE-2026-62796 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. | 0,3% | — |
| CVE-2026-62793 | MED 5.5 | microsoft windows_10_1607 Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally. | 0,3% | — |
| CVE-2026-62786 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally. | 0,3% | — |
| CVE-2026-49326 | MED 6.5 | apache hbase Missing Authorization vulnerability in Apache HBase thrift and rest delegation service. A scan operation in thrift/rest service has 3 steps, open, fetch(possible multiple times), close. The open step will return an id which will be passed back to server for i | 0,3% | — |
| CVE-2026-46303 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: isofs: validate Rock Ridge CE continuation extent against volume size rock_continue() reads rs->cont_extent verbatim from the Rock Ridge CE record and passes it to sb_bread() without checkin | 0,3% | — |
| CVE-2026-42357 | MED 6.5 | apache dolphinscheduler Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access. This issue affects Apache DolphinScheduler versions prior to 3.4.2. Users are recommended to upgrade to v | 0,3% | — |
| CVE-2026-40975 | MED 4.8 | vmware spring_boot Values produced by ${random.value} are not suitable for use as secrets. ${random.uuid} is not affected. ${random.int} and ${random.long} should never be used for secrets as they are numeric values with a predictable range. Affected: Spring Boot 4.0.0–4.0.5 (f | 0,3% | — |
| CVE-2026-33519 | CRIT 9.8 | esri portal_for_arcgis An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to developer credentials. | 0,3% | — |
| CVE-2026-11076 | HIGH 8.8 | google chrome Type Confusion in CSS in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) | 0,3% | — |
| CVE-2025-64658 | HIGH 7.5 | microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2025-38728 | CRIT 9.1 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: smb3: fix for slab out of bounds on mount to ksmbd With KASAN enabled, it is possible to get a slab out of bounds during mount to ksmbd due to missing check in parse_server_interfaces() (see | 0,3% | — |
| CVE-2024-49514 | HIGH 7.8 | adobe photoshop Photoshop Desktop versions 24.7.3, 25.11 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction | 0,3% | — |
| CVE-2024-42083 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ionic: fix kernel panic due to multi-buffer handling Currently, the ionic_run_xdp() doesn't handle multi-buffer packets properly for XDP_TX and XDP_REDIRECT. When a jumbo frame is received, | 0,3% | — |
| CVE-2024-27024 | HIGH 7.8 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: net/rds: fix WARNING in rds_conn_connect_if_down If connection isn't established yet, get_mr() will fail, trigger connection after get_mr(). | 0,3% | — |
| CVE-2024-26773 | HIGH 7.8 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: ext4: avoid allocating blocks from corrupted group in ext4_mb_try_best_found() Determine if the group block bitmap is corrupted before using ac_b_ex in ext4_mb_try_best_found() to avoid allo | 0,3% | — |
| CVE-2024-20369 | MED 4.7 | cisco network_services_orchestrator A vulnerability in the web-based management interface of Cisco Crosswork Network Services Orchestrator (NSO) could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation | 0,3% | — |
| CVE-2023-6679 | MED 5.5 | fedoraproject fedora A null pointer dereference vulnerability was found in dpll_pin_parent_pin_set() in drivers/dpll/dpll_netlink.c in the Digital Phase Locked Loop (DPLL) subsystem in the Linux kernel. This issue could be exploited to trigger a denial of service. | 0,3% | — |
| CVE-2023-4208 | HIGH 7.8 | debian debian_linux A use-after-free vulnerability in the Linux kernel's net/sched: cls_u32 component can be exploited to achieve local privilege escalation. When u32_change() is called on an existing filter, the whole tcf_result struct is always copied into the new instance of | 0,3% | — |
| CVE-2023-23454 | MED 5.5 | debian debian_linux cbq_classify in net/sched/sch_cbq.c in the Linux kernel through 6.1.4 allows attackers to cause a denial of service (slab-out-of-bounds read) because of type confusion (non-negative numbers can sometimes indicate a TC_ACT_SHOT condition rather than valid class | 0,3% | — |