EN
58.254 CVE seguite
789 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.254 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più basso In KEV dal, ordina dal più alto
CVE-2026-68845 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally. 0,3% —
CVE-2026-62697 HIGH 7.8 microsoft windows_10_21h2 Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally. 0,3% —
CVE-2026-56177 HIGH 7.8 microsoft windows_10_1607 Use after free in Windows Server allows an authorized attacker to elevate privileges locally. 0,3% —
CVE-2026-56172 HIGH 7.8 microsoft windows_10_1809 Use after free in Windows VHD miniport driver allows an authorized attacker to elevate privileges locally. 0,3% —
CVE-2026-44814 MED 5.5 microsoft windows_11_26h1 Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. 0,3% —
CVE-2026-20853 HIGH 7.4 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows WalletService allows an unauthorized attacker to elevate privileges locally. 0,3% —
CVE-2026-14384 MED 6.5 google chrome Out of bounds read in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) 0,3% —
CVE-2026-14059 MED 6.5 google chrome Insufficient policy enforcement in Related-Website-Sets in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low) 0,3% —
CVE-2026-13810 MED 6.5 google chrome Inappropriate implementation in Input in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High) 0,3% —
CVE-2026-0390 MED 6.7 microsoft windows_10_1607 Reliance on untrusted inputs in a security decision in Windows Boot Loader allows an authorized attacker to bypass a security feature locally. 0,3% —
CVE-2025-58692 HIGH 8.8 fortinet fortivoice An improper neutralization of special elements used in an SQL Command ("SQL Injection") vulnerability [CWE-89] vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7 allows an authenticated attacker to execute unauthorized cod 0,3% —
CVE-2025-53134 HIGH 7.0 microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0,3% —
CVE-2024-50124 HIGH 8.0 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: Fix UAF on iso_sock_timeout conn->sk maybe have been unlinked/freed while waiting for iso_conn_lock so this checks if the conn->sk is still valid by checking if it part of is 0,3% —
CVE-2024-26602 MED 5.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: sched/membarrier: reduce the ability to hammer on sys_membarrier On some systems, sys_membarrier can be very expensive, causing overall slowdowns for everything. So put a lock on the path i 0,3% —
CVE-2024-20294 MED 6.6 cisco firepower_extensible_operating_system A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is d 0,3% —
CVE-2023-50443 MED 4.6 primx cryhod Encrypted disks created by PRIMX CRYHOD for Windows before Q.2020.4 (ANSSI qualification submission) or CRYHOD for Windows before 2023.5 can be modified by an unauthenticated attacker to include a UNC reference so that it could trigger outbound network traffic 0,3% —
CVE-2023-47063 HIGH 7.8 adobe illustrator Adobe Illustrator versions 28.0 (and earlier) and 27.9 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in 0,3% —
CVE-2023-47046 MED 5.5 adobe audition Adobe Audition version 24.0 (and earlier) and 23.6.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in th 0,3% —
CVE-2023-30431 HIGH 8.4 ibm db2 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 db2set is vulnerable to a buffer overflow, caused by improper bounds checking. An attacker could overflow the buffer and execute arbitrary code. IBM X-Force ID: 252184. 0,3% —
CVE-2022-49526 MED 5.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: md/bitmap: don't set sb values if can't pass sanity check If bitmap area contains invalid data, kernel will crash then mdadm triggers "Segmentation fault". This is cluster-md speical bug. In 0,3% —
CVE-2022-48805 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: usb: ax88179_178a: Fix out-of-bounds accesses in RX fixup ax88179_rx_fixup() contains several out-of-bounds accesses that can be triggered by a malicious (or defective) USB device, in p 0,3% —
CVE-2021-29266 HIGH 7.8 linux linux_kernel An issue was discovered in the Linux kernel before 5.11.9. drivers/vhost/vdpa.c has a use-after-free because v->config_ctx has an invalid value upon re-opening a character device, aka CID-f6bbf0010ba0. 0,3% —
CVE-2021-1593 HIGH 7.3 cisco packet_tracer A vulnerability in Cisco Packet Tracer for Windows could allow an authenticated, local attacker to perform a DLL injection attack on an affected device. To exploit this vulnerability, the attacker must have valid credentials on the Windows system. This vulnera 0,3% —
CVE-2020-9295 MED 4.7 fortinet antivirus_engine FortiOS 6.2 running AV engine version 6.00142 and below, FortiOS 6.4 running AV engine version 6.00144 and below and FortiClient 6.2 running AV engine version 6.00137 and below may not immediately detect certain types of malformed or non-standard RAR archives, 0,3% —
CVE-2020-1688 MED 6.5 juniper junos On Juniper Networks SRX Series and NFX Series, a local authenticated user with access to the shell may obtain the Web API service private key that is used to provide encrypted communication between the Juniper device and the authenticator services. Exploitatio 0,3% —