EN
58.306 CVE seguite
790 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.306 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più basso In KEV dal, ordina dal più alto
CVE-2012-2669 LOW 2.1 linux linux_kernel The main function in tools/hv/hv_kvp_daemon.c in hypervkvpd, as distributed in the Linux kernel before 3.4.5, does not validate the origin of Netlink messages, which allows local users to spoof Netlink communication via a crafted connector message. 0,4% —
CVE-2012-1097 HIGH 7.8 linux linux_kernel The regset (aka register set) feature in the Linux kernel before 3.2.10 does not properly handle the absence of .get and .set methods, which allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact vi 0,4% —
CVE-2010-0530 LOW 2.1 apple quicktime Apple QuickTime before 7.6.9 on Windows sets weak permissions for the Apple Computer directory in the profile of a user account, which allows local users to obtain sensitive information by reading files in this directory. 0,4% —
CVE-2009-0024 HIGH 7.2 linux linux_kernel The sys_remap_file_pages function in mm/fremap.c in the Linux kernel before 2.6.24.1 allows local users to cause a denial of service or gain privileges via unspecified vectors, related to the vm_file structure member, and the mmap_region and do_munmap function 0,4% —
CVE-2008-3485 HIGH 7.2 citrix metaframe_presentation_server Untrusted search path vulnerability in Citrix MetaFrame Presentation Server allows local users to gain privileges via a malicious icabar.exe placed in the search path. 0,4% —
CVE-2007-6049 HIGH 7.2 ibm db2_universal_database Unspecified vulnerability in the SSL LOAD GSKIT action in IBM DB2 UDB 9.1 before Fixpak 4 has unknown impact and attack vectors, involving a call to dlopen when the effective uid is root. 0,4% —
CVE-2007-2480 MED 4.6 linux linux_kernel The _udp_lib_get_port function in net/ipv4/udp.c in Linux kernel 2.6.21 and earlier does not prevent a bind to a port with a local address when there is already a bind to that port with a wildcard local address, which might allow local users to intercept local 0,4% —
CVE-2026-68804 HIGH 7.8 microsoft 365_apps Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0,4% —
CVE-2026-68794 HIGH 7.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0,4% —
CVE-2026-66807 HIGH 7.8 microsoft 365_apps Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. 0,4% —
CVE-2026-65664 HIGH 7.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. 0,4% —
CVE-2026-63519 HIGH 7.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. 0,4% —
CVE-2026-63518 HIGH 7.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0,4% —
CVE-2026-63515 HIGH 7.8 microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally. 0,4% —
CVE-2026-63513 HIGH 7.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. 0,4% —
CVE-2026-50520 HIGH 8.4 microsoft visual_studio_code Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to execute code locally. 0,4% —
CVE-2026-48589 MED 5.4 apache shiro Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login. In affected versions, insufficient validation of this client-controlled value could allow an attacker to influence the redirect target in appli 0,4% —
CVE-2026-43514 LOW 3.7 apache tomcat Observable Timing Discrepancy vulnerability when comparing AJP secret in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 thr 0,4% —
CVE-2026-43112 HIGH 8.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath When cifs_sanitize_prepath is called with an empty string or a string containing only delimiters (e.g., "/"), the current logic 0,4% —
CVE-2026-41856 HIGH 7.5 vmware spring_for_graphql The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on methods within type hierarchies. This can be an issue if such annotations are used for authorization decisions. When all conditions are met 0,4% —
CVE-2026-40690 MED 4.3 apache airflow The asset dependency graph did not restrict nodes by the viewer's DAG read permissions: a user with read access to at least one DAG could browse the asset graph for any other asset in the deployment and learn the existence and names of DAGs and assets outside 0,4% —
CVE-2026-38743 MED 4.3 apache airflow The authenticated /ui/dags endpoint did not enforce per-DAG access control on embedded Human-in-the-Loop (HITL) and TaskInstance records: a logged-in Airflow user with read access to at least one DAG could retrieve HITL prompts (including their request paramet 0,4% —
CVE-2026-1642 MED 5.9 f5 nginx_gateway_fabric A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport Layer Security (TLS) servers. An attacker with a man-in-the-middle (MITM) position on the upstream server side—along with conditions beyond the attacker's control 0,4% —
CVE-2026-11024 HIGH 8.8 google chrome Stack buffer overflow in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page. (Chromium security severity: Medium) 0,4% —
CVE-2025-23329 HIGH 7.5 nvidia triton_inference_server NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause memory corruption by identifying and accessing the shared memory region used by the Python backend. A successful exploit of this vulnerability might lea 0,4% —