58.254 CVE seguite
789 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.254 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più basso | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2022-47521 | HIGH 7.8 | debian debian_linux An issue was discovered in the Linux kernel before 6.0.11. Missing validation of IEEE80211_P2P_ATTR_CHANNEL_LIST in drivers/net/wireless/microchip/wilc1000/cfg80211.c in the WILC1000 wireless driver can trigger a heap-based buffer overflow when parsing the ope | 0,3% | — |
| CVE-2022-34696 | HIGH 7.8 | microsoft windows_10 Windows Hyper-V Remote Code Execution Vulnerability | 0,3% | — |
| CVE-2022-23763 | HIGH 7.8 | douzone neors Origin validation error vulnerability in NeoRS’s ActiveX moudle allows attackers to download and execute arbitrary files. Remote attackers can use this vulerability to encourage users to access crafted web pages, causing damage such as malicious code infection | 0,3% | — |
| CVE-2022-0516 | HIGH 7.8 | debian debian_linux A vulnerability was found in kvm_s390_guest_sida_op in the arch/s390/kvm/kvm-s390.c function in KVM for s390 in the Linux kernel. This flaw allows a local attacker with a normal user privilege to obtain unauthorized memory write access. This flaw affects Linux | 0,3% | — |
| CVE-2021-26087 | MED 4.3 | fortinet fortiwlc An improper neutralization of input during web page generation in FortiWLC version 8.6.0, version 8.5.3 and below, version 8.4.8 and below, version 8.3.3 web interface may allow both authenticated remote attackers and non-authenticated attackers in the same ne | 0,3% | — |
| CVE-2020-4411 | HIGH 7.1 | ibm spectrum_scale The Spectrum Scale 4.2.0.0 through 4.2.3.21 and 5.0.0.0 through 5.0.4.3 file system component is affected by a denial of service vulnerability in its kernel module that could allow an attacker to cause a denial of service condition on the affected system. To e | 0,3% | — |
| CVE-2020-36311 | MED 5.5 | debian debian_linux An issue was discovered in the Linux kernel before 5.9. arch/x86/kvm/svm/sev.c allows attackers to cause a denial of service (soft lockup) by triggering destruction of a large SEV VM (which requires unregistering many encrypted regions), aka CID-7be74942f184. | 0,3% | — |
| CVE-2019-17437 | HIGH 7.8 | paloaltonetworks pan-os An improper authentication check in Palo Alto Networks PAN-OS may allow an authenticated low privileged non-superuser custom role user to elevate privileges and become superuser. This issue affects PAN-OS 7.1 versions prior to 7.1.25; 8.0 versions prior to 8.0 | 0,3% | — |
| CVE-2017-7836 | HIGH 7.8 | mozilla firefox The "pingsender" executable used by the Firefox Health Report dynamically loads a system copy of libcurl, which an attacker could replace. This allows for privilege escalation as the replaced libcurl code will run with Firefox's privileges. Note: This attack r | 0,3% | — |
| CVE-2017-18261 | MED 5.5 | linux linux_kernel The arch_timer_reg_read_stable macro in arch/arm64/include/asm/arch_timer.h in the Linux kernel before 4.13 allows local users to cause a denial of service (infinite recursion) by writing to a file under /sys/kernel/debug in certain circumstances, as demonstra | 0,3% | — |
| CVE-2016-9794 | HIGH 7.8 | linux linux_kernel Race condition in the snd_pcm_period_elapsed function in sound/core/pcm_lib.c in the ALSA subsystem in the Linux kernel before 4.7 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted SNDRV_PC | 0,3% | — |
| CVE-2016-5109 | MED 4.3 | citrix worx_home Citrix Worx Home for iOS before 10.3.6 and XenMobile MDX Toolkit for iOS before 10.3.6 might allow physically proximate attackers to bypass in-application Apple Touch ID authentication via unspecified vectors, related to an application requiring re-authenticat | 0,3% | — |
| CVE-2014-4652 | LOW 1.9 | canonical ubuntu_linux Race condition in the tlv handler functionality in the snd_ctl_elem_user_tlv function in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 allows local users to obtain sensitive information from kernel memory by leveragi | 0,3% | — |
| CVE-2013-3408 | MED 6.8 | cisco virtualization_experience_client_6000 The firmware on Cisco Virtualization Experience Client 6000 devices sets incorrect operating-system permissions, which allows local users to gain privileges via an unspecified sequence of commands, aka Bug ID CSCuc31764. | 0,3% | — |
| CVE-2008-7256 | LOW 1.2 | linux linux_kernel mm/shmem.c in the Linux kernel before 2.6.28-rc8, when strict overcommit is enabled and CONFIG_SECURITY is disabled, does not properly handle the export of shmemfs objects by knfsd, which allows attackers to cause a denial of service (NULL pointer dereference | 0,3% | — |
| CVE-2005-2617 | LOW 3.6 | linux linux_kernel The syscall32_setup_pages function in syscall32.c for Linux kernel 2.6.12 and later, on the 64-bit x86 platform, does not check the return value of the insert_vm_struct function, which allows local users to trigger a memory leak via a 32-bit application with c | 0,3% | — |
| CVE-2000-0090 | LOW 3.6 | vmware workstation VMWare 1.1.2 allows local users to cause a denial of service via a symlink attack. | 0,3% | — |
| CVE-2026-69713 | MED 4.4 | microsoft windows_10_1607 Dependency on vulnerable third-party component in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | 0,3% | — |
| CVE-2026-6306 | HIGH 8.8 | google chrome Heap buffer overflow in PDFium in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High) | 0,3% | — |
| CVE-2026-6305 | HIGH 8.8 | google chrome Heap buffer overflow in PDFium in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High) | 0,3% | — |
| CVE-2026-62897 | HIGH 7.0 | microsoft .net Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally. | 0,3% | — |
| CVE-2026-61397 | HIGH 7.5 | apache cloudstack Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAuth2 authentication plugin and Google OAuth integration. This issue affects Apache CloudStack: from 4.19.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. | 0,3% | — |
| CVE-2026-59780 | HIGH 7.5 | apache cloudstack Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's LDAP authentication plugin while listing LDAP providers. LDAP configurations can be listed by any authenticated user with access to the listLdapConfigura | 0,3% | — |
| CVE-2026-59655 | HIGH 7.5 | apache cloudstack Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAuth authentication plugin while listing OAuth providers. This issue affects Apache CloudStack: from 4.19.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. | 0,3% | — |
| CVE-2026-50622 | HIGH 8.8 | apache atlas Description: Missing Authorization in Apache Atlas. A missing authorization vulnerability in Apache Atlas's admin endpoints allows any authenticated user, regardless of their assigned role, to perform administrative operations. Affect Version: This issue a | 0,3% | — |