58.306 CVE seguite
790 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.306 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più basso | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2021-34953 | HIGH 7.8 | foxit pdf_editor Foxit PDF Reader Annotation Use of Uninitialized Variable Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vuln | 0,3% | — |
| CVE-2021-34952 | HIGH 7.8 | foxit pdf_editor Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in th | 0,3% | — |
| CVE-2021-34950 | HIGH 7.8 | foxit pdf_editor Foxit PDF Reader Annotation Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability i | 0,3% | — |
| CVE-2021-34948 | HIGH 7.8 | foxit pdf_editor Foxit PDF Reader Square Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerabilit | 0,3% | — |
| CVE-2019-3621 | MED 6.8 | mcafee data_loss_prevention_endpoint Authentication protection bypass vulnerability in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.0 allows physical local user to bypass the Windows lock screen via DLPe processes being killed just prior to the screen being locked or when the | 0,3% | — |
| CVE-2019-15925 | HIGH 7.8 | canonical ubuntu_linux An issue was discovered in the Linux kernel before 5.2.3. An out of bounds access exists in the function hclge_tm_schd_mode_vnet_base_cfg in the file drivers/net/ethernet/hisilicon/hns3/hns3pf/hclge_tm.c. | 0,3% | — |
| CVE-2016-6276 | HIGH 7.8 | citrix linux_virtual_delivery_agent Citrix Linux Virtual Delivery Agent (aka VDA, formerly Linux Virtual Desktop) before 1.4.0 allows local users to gain root privileges via unspecified vectors. | 0,3% | — |
| CVE-2013-5522 | MED 6.8 | cisco catalyst_3750-x Cisco IOS on Catalyst 3750X switches has default Service Module credentials, which makes it easier for local users to gain privileges via a Service Module login, aka Bug ID CSCue92286. | 0,3% | — |
| CVE-2013-1215 | MED 6.8 | cisco 5500_series_adaptive_security_appliance The vpnclient program in the Easy VPN component on Cisco Adaptive Security Appliances (ASA) 5505 devices allows local users to gain privileges via unspecified vectors, aka Bug ID CSCuf85295. | 0,3% | — |
| CVE-2012-4542 | MED 4.6 | linux linux_kernel block/scsi_ioctl.c in the Linux kernel through 3.8 does not properly consider the SCSI device class during authorization of SCSI commands, which allows local users to bypass intended access restrictions via an SG_IO ioctl call that leverages overlapping opcode | 0,3% | — |
| CVE-2011-4080 | MED 4.0 | linux linux_kernel The sysrq_sysctl_handler function in kernel/sysctl.c in the Linux kernel before 2.6.39 does not require the CAP_SYS_ADMIN capability to modify the dmesg_restrict value, which allows local users to bypass intended access restrictions and read the kernel ring bu | 0,3% | — |
| CVE-2010-0633 | MED 4.6 | citrix xenserver Unspecified vulnerability in Citrix XenServer 5.0 Update 3 and earlier, and 5.5, allows local users to bypass authentication and execute unspecified Xen API (XAPI) calls via unknown vectors. | 0,3% | — |
| CVE-2009-1184 | MED 4.4 | linux linux_kernel The selinux_ip_postroute_iptables_compat function in security/selinux/hooks.c in the SELinux subsystem in the Linux kernel before 2.6.27.22, and 2.6.28.x before 2.6.28.10, when compat_net is enabled, omits calls to avc_has_perm for the (1) node and (2) port, w | 0,3% | — |
| CVE-2007-1589 | LOW 2.1 | truecrypt_foundation truecrypt TrueCrypt before 4.3, when set-euid mode is used on Linux, allows local users to cause a denial of service (filesystem unavailability) by dismounting a volume mounted by a different user. | 0,3% | — |
| CVE-2026-69267 | MED 6.5 | microsoft windows_10_1809 Insufficient granularity of access control in Windows Connected User Experiences and Telemetry allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-58545 | MED 5.5 | microsoft windows_10_1607 Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally. | 0,4% | — |
| CVE-2026-50312 | MED 4.7 | microsoft windows_10_1607 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2026-49167 | MED 4.7 | microsoft windows_10_1809 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2026-48569 | HIGH 7.1 | microsoft visual_studio_code Improper input validation in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | 0,4% | — |
| CVE-2026-45169 | HIGH 8.6 | paloaltonetworks idira_privileged_access_manager_vault Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a validation vulnerability. Under specific circumstances and configuration scenarios, processing unexpected input could potentially lead to an | 0,4% | — |
| CVE-2026-41017 | MED 5.9 | apache airflow Apache Airflow's `JWTRefreshMiddleware` set the JWT auth cookie without the `Secure` flag, so deployments running the Airflow API server behind an HTTPS-terminating reverse proxy (e.g. nginx / Envoy / a managed load balancer that terminates TLS and forwards pl | 0,4% | — |
| CVE-2026-3542 | HIGH 8.8 | google chrome Inappropriate implementation in WebAssembly in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) | 0,4% | — |
| CVE-2026-13445 | HIGH 8.1 | langflow langflow IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile component to read and modify another user's uploaded files by specifying absolute paths pointing to victim storage locations. In append mode, the attacker's wor | 0,4% | — |
| CVE-2025-58738 | HIGH 7.0 | microsoft windows_10_1507 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2025-58736 | HIGH 7.0 | microsoft windows_10_1507 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. | 0,4% | — |