58.306 CVE seguite
790 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.306 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più basso | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-47631 | HIGH 8.1 | microsoft exchange_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | 0,4% | — |
| CVE-2026-45658 | HIGH 7.8 | microsoft windows_10_1607 Improper access control in Windows BitLocker allows an authorized attacker to bypass a security feature locally. | 0,4% | — |
| CVE-2026-43345 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: ipa: fix event ring index not programmed for IPA v5.0+ For IPA v5.0+, the event ring index field moved from CH_C_CNTXT_0 to CH_C_CNTXT_1. The v5.0 register definition intended to define | 0,4% | — |
| CVE-2026-41705 | HIGH 8.6 | vmware spring_ai Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injection via unsanitized document IDs. Spring AI 1.0.x: affected from 1.0.0 through latest 1.0.x; upgrade to 1.0.7 or greater. Spring AI 1.1.x: affected from 1.1.0 | 0,4% | — |
| CVE-2026-33803 | MED 6.5 | juniper junos_os_evolved An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause a limited information disclosure and availability impact to the device. Due t | 0,4% | — |
| CVE-2026-32084 | MED 5.5 | microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-26134 | HIGH 7.8 | microsoft 365_copilot Integer overflow or wraparound in Microsoft Office allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2026-24253 | HIGH 8.2 | nvidia dynamo NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to denial of service and data tampering. | 0,4% | — |
| CVE-2026-23672 | HIGH 7.8 | microsoft windows_10_1607 Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | 0,4% | — |
| CVE-2026-22742 | HIGH 8.6 | vmware spring_ai Spring AI's spring-ai-bedrock-converse contains a Server-Side Request Forgery (SSRF) vulnerability in BedrockProxyChatModel when processing multimodal messages that include user-supplied media URLs. Insufficient validation of those URLs allows an attacker to i | 0,4% | — |
| CVE-2026-21242 | HIGH 7.0 | microsoft windows_10_21h2 Use after free in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2026-14108 | HIGH 8.8 | google chrome Use after free in PDFium in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low) | 0,4% | — |
| CVE-2025-55697 | HIGH 7.8 | microsoft windows_server_2022_23h2 Heap-based buffer overflow in Azure Local allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-38523 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: cifs: Fix the smbd_response slab to allow usercopy The handling of received data in the smbdirect client code involves using copy_to_iter() to copy data from the smbd_reponse struct's packet | 0,4% | — |
| CVE-2025-37959 | CRIT 9.4 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: bpf: Scrub packet on bpf_redirect_peer When bpf_redirect_peer is used to redirect packets to a device in another network namespace, the skb isn't scrubbed. That can lead skb information from | 0,4% | — |
| CVE-2025-37777 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in __smb2_lease_break_noti() Move tcp_transport free to ksmbd_conn_free. If ksmbd connection is referenced when ksmbd server thread terminates, It will not be freed | 0,4% | — |
| CVE-2025-27174 | HIGH 7.8 | adobe acrobat Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction i | 0,4% | — |
| CVE-2025-27160 | HIGH 7.8 | adobe acrobat Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction i | 0,4% | — |
| CVE-2025-27159 | HIGH 7.8 | adobe acrobat Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction i | 0,4% | — |
| CVE-2025-20335 | MED 5.3 | cisco desk_phone_9841_firmware A vulnerability in the directory permissions of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 could allow an unauthenticated, remote attacker to write arbitrary files on an affected device. This vulnerability | 0,4% | — |
| CVE-2024-50264 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: Initialization of the dangling pointer occurring in vsk->trans During loopback communication, a dangling pointer can be created in vsk->trans, potentially leading to a Use-Afte | 0,4% | — |
| CVE-2024-35811 | HIGH 8.8 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: Fix use-after-free bug in brcmf_cfg80211_detach This is the candidate patch of CVE-2023-47233 : https://nvd.nist.gov/vuln/detail/CVE-2023-47233 In brcm80211 driver,it starts | 0,4% | — |
| CVE-2024-34098 | HIGH 7.8 | adobe acrobat Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in | 0,4% | — |
| CVE-2024-20531 | MED 5.5 | cisco identity_services_engine A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system of an affected device and conduct a server-side request forgery (SSRF) attack through an affected device. To exploi | 0,4% | — |
| CVE-2024-20476 | MED 4.3 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to bypass the authorization mechanisms for specific file management functions. This vulnerability is due to lack of server-side validation of Ad | 0,4% | — |