58.306 CVE seguite
790 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.306 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più basso | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2016-1712 | HIGH 7.8 | paloaltonetworks pan-os Palo Alto Networks PAN-OS before 5.0.19, 5.1.x before 5.1.12, 6.0.x before 6.0.14, 6.1.x before 6.1.12, and 7.0.x before 7.0.8 might allow local users to gain privileges by leveraging improper sanitization of the root_reboot local invocation. | 0,4% | — |
| CVE-2015-6318 | MED 6.9 | cisco telepresence_video_communication_server_software Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.1 and X8.5.2 allows local users to write to arbitrary files via an unspecified symlink attack, aka Bug ID CSCuv11969. | 0,4% | — |
| CVE-2015-4176 | MED 5.5 | linux linux_kernel fs/namespace.c in the Linux kernel before 4.0.2 does not properly support mount connectivity, which allows local users to read arbitrary files by leveraging user-namespace root access for deletion of a file or directory. | 0,4% | — |
| CVE-2013-4343 | MED 6.9 | canonical ubuntu_linux Use-after-free vulnerability in drivers/net/tun.c in the Linux kernel through 3.11.1 allows local users to gain privileges by leveraging the CAP_NET_ADMIN capability and providing an invalid tuntap interface name in a TUNSETIFF ioctl call. | 0,4% | — |
| CVE-2009-1146 | MED 4.9 | vmware ace Unspecified vulnerability in an ioctl in hcmon.sys in VMware Workstation 6.5.1 and earlier, VMware Player 2.5.1 and earlier, VMware ACE 2.5.1 and earlier, and VMware Server 1.0.x before 1.0.9 build 156507 and 2.0.x before 2.0.1 build 156745 allows local users | 0,4% | — |
| CVE-2007-5548 | MED 6.9 | cisco ios Multiple stack-based buffer overflows in Command EXEC in Cisco IOS allow local users to gain privileges via unspecified vectors, aka (1) PSIRT-0474975756 and (2) PSIRT-0388256465. NOTE: as of 20071016, the only disclosure is a vague pre-advisory with no actio | 0,4% | — |
| CVE-2026-85921 | HIGH 8.2 | Double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2026-79175 | HIGH 8.3 | google chrome Type confusion in Accessibility in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | 0,4% | — |
| CVE-2026-75099 | MED 5.3 | apache allura Unauthenticated REST disclosure of certain content items in Apache Allura. This issue affects Apache Allura: through 1.19.1. Users are recommended to upgrade to version 1.20.0, which fixes the issue. | 0,4% | — |
| CVE-2026-69449 | MED 6.7 | microsoft windows_10_1607 Heap-based buffer overflow in Windows BitLocker allows an authorized attacker to execute code locally. | 0,4% | — |
| CVE-2026-69373 | MED 6.7 | microsoft windows_10_1607 Integer overflow or wraparound in Windows Overlay Filter allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2026-69350 | MED 6.7 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2026-65656 | HIGH 7.8 | microsoft 365_apps Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2026-62829 | MED 4.6 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 0,4% | — |
| CVE-2026-52989 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers Currently, when nvmet_tcp_build_pdu_iovec() detects an out-of-bounds PDU length or offset, it triggers nvmet_tcp_fatal_ | 0,4% | — |
| CVE-2026-44805 | MED 5.5 | microsoft windows_server_2019 Use after free in Windows Network Controller (NC) Host Agent allows an authorized attacker to deny service locally. | 0,4% | — |
| CVE-2026-42809 | CRIT 9.9 | apache polaris Apache Polaris can issue broad temporary ("vended") storage credentials during staged table creation before the effective table location has been validated or durably reserved. Those temporary credentials are meant to limit the scope of accessible table data | 0,4% | — |
| CVE-2026-31718 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in __ksmbd_close_fd() via durable scavenger When a durable file handle survives session disconnect (TCP close without SMB2_LOGOFF), session_fd_check() sets fp->conn | 0,4% | — |
| CVE-2026-27220 | HIGH 7.8 | adobe acrobat Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction i | 0,4% | — |
| CVE-2026-15771 | MED 5.3 | google chrome Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. | 0,4% | — |
| CVE-2025-47410 | HIGH 8.8 | apache geode Apache Geode is vulnerable to CSRF attacks through GET requests to the Management and Monitoring REST API that could allow an attacker who has tricked a user into giving up their Geode session credentials to submit malicious commands on the target system on be | 0,4% | — |
| CVE-2024-27416 | HIGH 8.8 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: Fix handling of HCI_EV_IO_CAPA_REQUEST If we received HCI_EV_IO_CAPA_REQUEST while HCI_OP_READ_REMOTE_EXT_FEATURES is yet to be responded assume the remote does support | 0,4% | — |
| CVE-2024-20463 | MED 5.4 | cisco ata_191_firmware A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remote attacker to modify the configuration or reboot an affected device. This vulnerability is due to the HTTP s | 0,4% | — |
| CVE-2024-20420 | MED 5.4 | cisco ata_191_firmware A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an authenticated, remote attacker with low privileges to run commands as an Admin user. This vulnerability is due to incorrect autho | 0,4% | — |
| CVE-2024-20364 | MED 4.8 | cisco secure_firewall_management_center A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. | 0,4% | — |