58.306 CVE seguite
790 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.306 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più basso | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-7356 | HIGH 8.8 | google chrome Use after free in Navigation in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) | 0,4% | — |
| CVE-2026-7335 | HIGH 8.8 | google chrome Use after free in media in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | 0,4% | — |
| CVE-2026-57030 | MED 5.9 | juniper junos A Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of- | 0,4% | — |
| CVE-2026-35194 | HIGH 8.1 | apache flink Code injection in SQL code generation in Apache Flink 1.15.0 through 1.20.x and 2.0.0 through 2.x allows authenticated users with query submission privileges to execute arbitrary code on TaskManagers via maliciously crafted SQL queries. The vulnerability affec | 0,4% | — |
| CVE-2026-33930 | MED 5.9 | apache traffic_server Apache Traffic Server copies the client Host header into a fixed-size stack buffer without a bound during redirect handling, so an over-long Host header overflows the stack when redirect following is enabled. This issue affects Apache Traffic Server: from 8.0 | 0,4% | — |
| CVE-2026-20073 | MED 5.8 | cisco adaptive_security_appliance_software A vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to send traffic that should be denied through an affected device. Thi | 0,4% | — |
| CVE-2026-20009 | MED 5.3 | cisco adaptive_security_appliance_software A vulnerability in the implementation of the proprietary SSH stack with SSH key-based authentication in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to log in to a Cisco Secure Firewall ASA de | 0,4% | — |
| CVE-2026-13446 | CRIT 9.8 | langflow langflow IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. | 0,4% | — |
| CVE-2026-10955 | HIGH 8.8 | google chrome Type Confusion in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) | 0,4% | — |
| CVE-2025-59238 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2025-59226 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2025-59225 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2025-59224 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2025-59223 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2025-43892 | MED 4.3 | fortinet fortios A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow an authenticated remote attacker to return a portion of device memory | 0,4% | — |
| CVE-2025-26649 | HIGH 7.0 | microsoft windows_11_22h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Secure Channel allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-21988 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: fs/netfs/read_collect: add to next->prev_donated If multiple subrequests donate data to the same "next" request (depending on the subrequest completion order), each of them would overwrite t | 0,4% | — |
| CVE-2025-21805 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs: Add missing deinit() call A warning is triggered when repeatedly connecting and disconnecting the rnbd: list_add corruption. prev->next should be next (ffff88800b13e480), but was | 0,4% | — |
| CVE-2024-49338 | MED 4.4 | ibm app_connect_enterprise IBM App Connect Enterprise 12.0.1.0 through 12.0.7.0and 13.0.1.0 under certain configurations could allow a privileged user to obtain JMS credentials. | 0,4% | — |
| CVE-2023-26077 | HIGH 7.8 | atera atera Atera Agent through 1.8.3.6 on Windows Creates a Temporary File in a Directory with Insecure Permissions. | 0,4% | — |
| CVE-2022-30701 | HIGH 7.8 | trendmicro apex_one An uncontrolled search path element vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to craft a special configuration file to load an untrusted library with escalated privileges on affected installations. Please note | 0,4% | — |
| CVE-2022-27950 | MED 5.5 | linux linux_kernel In drivers/hid/hid-elo.c in the Linux kernel before 5.16.11, a memory leak exists for a certain hid_parse error condition. | 0,4% | — |
| CVE-2021-34734 | MED 6.5 | cisco video_surveillance_7000_ip_camera_firmware A vulnerability in the Link Layer Discovery Protocol (LLDP) implementation for the Cisco Video Surveillance 7000 Series IP Cameras firmware could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. This vulnerability is du | 0,4% | — |
| CVE-2021-27893 | HIGH 7.0 | ssh tectia_client SSH Tectia Client and Server before 6.4.19 on Windows allow local privilege escalation in nonstandard conditions. ConnectSecure on Windows is affected. | 0,4% | — |
| CVE-2021-26111 | MED 6.5 | fortinet fortiswitch A missing release of memory after effective lifetime vulnerability in FortiSwitch 6.4.0 to 6.4.6, 6.2.0 to 6.2.6, 6.0.0 to 6.0.6, 3.6.11 and below may allow an attacker on an adjacent network to exhaust available memory by sending specifically crafted LLDP/CDP | 0,4% | — |