58.306 CVE seguite
790 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.306 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più basso | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-55012 | HIGH 7.8 | microsoft malware_protection_engine Integer overflow or wraparound in Microsoft Defender allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2026-55011 | HIGH 7.8 | microsoft malware_protection_engine Integer underflow (wrap or wraparound) in Microsoft Defender allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2026-35419 | MED 5.5 | microsoft windows_11_24h2 Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-10946 | HIGH 7.5 | google chrome Heap buffer overflow in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | 0,4% | — |
| CVE-2025-64680 | HIGH 7.8 | microsoft windows_10_1507 Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-54093 | HIGH 7.0 | microsoft windows_10_1507 Time-of-check time-of-use (toctou) race condition in Windows TCP/IP allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-49679 | HIGH 7.8 | microsoft windows_10_1507 Numeric truncation error in Windows Shell allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-47982 | HIGH 7.8 | microsoft windows_10_1607 Improper input validation in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-47159 | HIGH 7.8 | microsoft windows_10_1507 Protection mechanism failure in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-46265 | HIGH 8.8 | f5 f5os-a On F5OS, an improper authorization vulnerability exists where remotely authenticated users (LDAP, RADIUS, TACACS+) may be authorized with higher privilege F5OS roles. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0,4% | — |
| CVE-2025-21947 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix type confusion via race condition when using ipc_msg_send_request req->handle is allocated using ksmbd_acquire_id(&ipc_ida), based on ida_alloc. req->handle from ksmbd_ipc_login_r | 0,4% | — |
| CVE-2025-21890 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: idpf: fix checksums set in idpf_rx_rsc() idpf_rx_rsc() uses skb_transport_offset(skb) while the transport header is not set yet. This triggers the following warning for CONFIG_DEBUG_NET=y b | 0,4% | — |
| CVE-2025-21163 | HIGH 7.8 | adobe illustrator Illustrator versions 29.1, 28.7.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim mu | 0,4% | — |
| CVE-2023-53358 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix racy issue under cocurrent smb2 tree disconnect There is UAF issue under cocurrent smb2 tree disconnect. This patch introduce TREE_CONN_EXPIRE flags for tcon to avoid cocurrent ac | 0,4% | — |
| CVE-2023-38544 | MED 5.5 | ivanti secure_access_client A logged in user can modify specific files that may lead to unauthorized changes in system-wide configuration settings. This vulnerability could be exploited to compromise the integrity and security of the network on the affected system. | 0,4% | — |
| CVE-2022-50335 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: 9p: set req refcount to zero to avoid uninitialized usage When a new request is allocated, the refcount will be zero if it is reused, but if the request is newly allocated from slab, it is n | 0,4% | — |
| CVE-2022-28226 | HIGH 7.8 | yandex yandex_browser Local privilege vulnerability in Yandex Browser for Windows prior to 22.3.3.801 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating temporary files in directory with insecure permissions during Yand | 0,4% | — |
| CVE-2021-3501 | HIGH 7.1 | fedoraproject fedora A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to an array index, which can be updated by a user process at anytime which could lead to an out-of-bounds write. The highest threat from this v | 0,4% | — |
| CVE-2021-0287 | MED 6.5 | juniper junos In a Segment Routing ISIS (SR-ISIS)/MPLS environment, on Juniper Networks Junos OS and Junos OS Evolved devices, configured with ISIS Flexible Algorithm for Segment Routing and sensor-based statistics, a flap of a ISIS link in the network, can lead to a routin | 0,4% | — |
| CVE-2017-6353 | MED 5.5 | linux linux_kernel net/sctp/socket.c in the Linux kernel through 4.10.1 does not properly restrict association peel-off operations during certain wait states, which allows local users to cause a denial of service (invalid unlock and double free) via a multithreaded application. | 0,4% | — |
| CVE-2017-1000111 | HIGH 7.8 | debian debian_linux Linux kernel: heap out-of-bounds in AF_PACKET sockets. This new issue is analogous to previously disclosed CVE-2016-8655. In both cases, a socket option that changes socket state may race with safety checks in packet_set_ring. Previously with PACKET_VERSION. T | 0,4% | — |
| CVE-2016-5400 | MED 4.3 | linux linux_kernel Memory leak in the airspy_probe function in drivers/media/usb/airspy/airspy.c in the airspy USB driver in the Linux kernel before 4.7 allows local users to cause a denial of service (memory consumption) via a crafted USB device that emulates many VFL_TYPE_SDR | 0,4% | — |
| CVE-2016-2383 | MED 5.5 | canonical ubuntu_linux The adjust_branches function in kernel/bpf/verifier.c in the Linux kernel before 4.5 does not consider the delta in the backward-jump case, which allows local users to obtain sensitive information from kernel memory by creating a packet filter and then loading | 0,4% | — |
| CVE-2015-7362 | HIGH 7.8 | fortinet forticlient Fortinet FortiClient Linux SSLVPN before build 2313, when installed on Linux in a home directory that is world readable and executable, allows local users to gain privileges via the helper/subroc setuid program. | 0,4% | — |
| CVE-2014-8086 | MED 4.7 | linux linux_kernel Race condition in the ext4_file_write_iter function in fs/ext4/file.c in the Linux kernel through 3.17 allows local users to cause a denial of service (file unavailability) via a combination of a write action and an F_SETFL fcntl operation for the O_DIRECT fla | 0,4% | — |