EN
58.306 CVE seguite
790 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.306 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più basso In KEV dal, ordina dal più alto
CVE-2014-7843 MED 4.9 linux linux_kernel The __clear_user function in arch/arm64/lib/clear_user.S in the Linux kernel before 3.17.4 on the ARM64 platform allows local users to cause a denial of service (system crash) by reading one byte beyond a /dev/zero page boundary. 0,4% —
CVE-2014-7842 MED 4.9 linux linux_kernel Race condition in arch/x86/kvm/x86.c in the Linux kernel before 3.17.4 allows guest OS users to cause a denial of service (guest OS crash) via a crafted application that performs an MMIO transaction or a PIO transaction to trigger a guest userspace emulation e 0,4% —
CVE-2007-5549 LOW 2.1 cisco ios Unspecified vulnerability in Command EXEC in Cisco IOS allows local users to bypass command restrictions and obtain sensitive information via an unspecified "variation of an IOS command" involving "two different methods", aka CSCsk16129. NOTE: as of 20071016, 0,4% —
CVE-2026-70325 MED 5.5 microsoft 365_apps Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. 0,4% —
CVE-2026-70323 MED 5.5 microsoft 365_apps Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally. 0,4% —
CVE-2026-70322 MED 5.5 microsoft 365_apps Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. 0,4% —
CVE-2026-70320 MED 5.5 microsoft 365_apps Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. 0,4% —
CVE-2026-70319 MED 5.5 microsoft 365_apps Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information locally. 0,4% —
CVE-2026-70316 MED 5.5 microsoft 365_apps Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. 0,4% —
CVE-2026-70315 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. 0,4% —
CVE-2026-59317 MED 6.5 vmware spring_for_apache_kafka DeadLetterPublishingRecovererFactory reads the retry_topic-original-timestamp header from an inbound ConsumerRecord and passes its raw bytes directly to new BigInteger(header.value()) with no length or format validation. Spring for Apache Kafka 4.1.0 Spring fo 0,4% —
CVE-2026-50475 MED 5.5 microsoft windows_10_1607 Buffer over-read in Windows Kernel allows an authorized attacker to disclose information locally. 0,4% —
CVE-2026-45500 MED 6.1 microsoft exchange_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. 0,4% —
CVE-2026-43139 HIGH 8.6 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: xfrm6: fix uninitialized saddr in xfrm6_get_saddr() xfrm6_get_saddr() does not check the return value of ipv6_dev_get_saddr(). When ipv6_dev_get_saddr() fails to find a suitable source addre 0,4% —
CVE-2026-33267 CRIT 10.0 apache traffic_server Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue. 0,4% —
CVE-2026-19300 HIGH 7.5 langflow langflow IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to incomplete scrubbing of sensitive credential fields. 0,4% —
CVE-2025-59511 HIGH 7.8 microsoft windows_10_1809 External control of file name or path in Windows WLAN Service allows an authorized attacker to elevate privileges locally. 0,4% —
CVE-2025-54112 HIGH 7.0 microsoft windows_10_1507 Use after free in Microsoft Virtual Hard Drive allows an authorized attacker to elevate privileges locally. 0,4% —
CVE-2025-54111 HIGH 7.8 microsoft windows_10_1507 Use after free in Windows UI XAML Phone DatePickerFlyout allows an authorized attacker to elevate privileges locally. 0,4% —
CVE-2025-54099 HIGH 7.0 microsoft windows_10_1507 Stack-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0,4% —
CVE-2025-53802 HIGH 7.0 microsoft windows_10_21h2 Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. 0,4% —
CVE-2025-49694 HIGH 7.8 microsoft windows_11_24h2 Null pointer dereference in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. 0,4% —
CVE-2025-49693 HIGH 7.8 microsoft windows_11_22h2 Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. 0,4% —
CVE-2025-49659 HIGH 7.8 microsoft windows_10_1507 Buffer over-read in Windows TDX.sys allows an authorized attacker to elevate privileges locally. 0,4% —
CVE-2025-29838 HIGH 7.4 microsoft windows_11_24h2 Null pointer dereference in Windows Drivers allows an unauthorized attacker to elevate privileges locally. 0,4% —