EN
58.306 CVE seguite
790 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.306 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più basso In KEV dal, ordina dal più alto
CVE-2021-34953 HIGH 7.8 foxit pdf_editor Foxit PDF Reader Annotation Use of Uninitialized Variable Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vuln 0,3% —
CVE-2021-34952 HIGH 7.8 foxit pdf_editor Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in th 0,3% —
CVE-2021-34950 HIGH 7.8 foxit pdf_editor Foxit PDF Reader Annotation Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability i 0,3% —
CVE-2021-34948 HIGH 7.8 foxit pdf_editor Foxit PDF Reader Square Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerabilit 0,3% —
CVE-2019-3621 MED 6.8 mcafee data_loss_prevention_endpoint Authentication protection bypass vulnerability in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.0 allows physical local user to bypass the Windows lock screen via DLPe processes being killed just prior to the screen being locked or when the 0,3% —
CVE-2019-15925 HIGH 7.8 canonical ubuntu_linux An issue was discovered in the Linux kernel before 5.2.3. An out of bounds access exists in the function hclge_tm_schd_mode_vnet_base_cfg in the file drivers/net/ethernet/hisilicon/hns3/hns3pf/hclge_tm.c. 0,3% —
CVE-2016-6276 HIGH 7.8 citrix linux_virtual_delivery_agent Citrix Linux Virtual Delivery Agent (aka VDA, formerly Linux Virtual Desktop) before 1.4.0 allows local users to gain root privileges via unspecified vectors. 0,3% —
CVE-2013-5522 MED 6.8 cisco catalyst_3750-x Cisco IOS on Catalyst 3750X switches has default Service Module credentials, which makes it easier for local users to gain privileges via a Service Module login, aka Bug ID CSCue92286. 0,3% —
CVE-2013-1215 MED 6.8 cisco 5500_series_adaptive_security_appliance The vpnclient program in the Easy VPN component on Cisco Adaptive Security Appliances (ASA) 5505 devices allows local users to gain privileges via unspecified vectors, aka Bug ID CSCuf85295. 0,3% —
CVE-2012-4542 MED 4.6 linux linux_kernel block/scsi_ioctl.c in the Linux kernel through 3.8 does not properly consider the SCSI device class during authorization of SCSI commands, which allows local users to bypass intended access restrictions via an SG_IO ioctl call that leverages overlapping opcode 0,3% —
CVE-2011-4080 MED 4.0 linux linux_kernel The sysrq_sysctl_handler function in kernel/sysctl.c in the Linux kernel before 2.6.39 does not require the CAP_SYS_ADMIN capability to modify the dmesg_restrict value, which allows local users to bypass intended access restrictions and read the kernel ring bu 0,3% —
CVE-2010-0633 MED 4.6 citrix xenserver Unspecified vulnerability in Citrix XenServer 5.0 Update 3 and earlier, and 5.5, allows local users to bypass authentication and execute unspecified Xen API (XAPI) calls via unknown vectors. 0,3% —
CVE-2009-1184 MED 4.4 linux linux_kernel The selinux_ip_postroute_iptables_compat function in security/selinux/hooks.c in the SELinux subsystem in the Linux kernel before 2.6.27.22, and 2.6.28.x before 2.6.28.10, when compat_net is enabled, omits calls to avc_has_perm for the (1) node and (2) port, w 0,3% —
CVE-2007-1589 LOW 2.1 truecrypt_foundation truecrypt TrueCrypt before 4.3, when set-euid mode is used on Linux, allows local users to cause a denial of service (filesystem unavailability) by dismounting a volume mounted by a different user. 0,3% —
CVE-2026-69267 MED 6.5 microsoft windows_10_1809 Insufficient granularity of access control in Windows Connected User Experiences and Telemetry allows an authorized attacker to disclose information locally. 0,4% —
CVE-2026-58545 MED 5.5 microsoft windows_10_1607 Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally. 0,4% —
CVE-2026-50312 MED 4.7 microsoft windows_10_1607 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0,4% —
CVE-2026-49167 MED 4.7 microsoft windows_10_1809 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. 0,4% —
CVE-2026-48569 HIGH 7.1 microsoft visual_studio_code Improper input validation in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. 0,4% —
CVE-2026-45169 HIGH 8.6 paloaltonetworks idira_privileged_access_manager_vault Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a validation vulnerability. Under specific circumstances and configuration scenarios, processing unexpected input could potentially lead to an 0,4% —
CVE-2026-41017 MED 5.9 apache airflow Apache Airflow's `JWTRefreshMiddleware` set the JWT auth cookie without the `Secure` flag, so deployments running the Airflow API server behind an HTTPS-terminating reverse proxy (e.g. nginx / Envoy / a managed load balancer that terminates TLS and forwards pl 0,4% —
CVE-2026-3542 HIGH 8.8 google chrome Inappropriate implementation in WebAssembly in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) 0,4% —
CVE-2026-13445 HIGH 8.1 langflow langflow IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile component to read and modify another user's uploaded files by specifying absolute paths pointing to victim storage locations. In append mode, the attacker's wor 0,4% —
CVE-2025-58738 HIGH 7.0 microsoft windows_10_1507 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. 0,4% —
CVE-2025-58736 HIGH 7.0 microsoft windows_10_1507 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. 0,4% —