58.335 CVE seguite
790 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.335 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più basso | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-53049 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: gfs2: add some missing log locking Function gfs2_logd() calls the log flushing functions gfs2_ail1_start(), gfs2_ail1_wait(), and gfs2_ail1_empty() without holding sdp->sd_log_flush_lock, bu | 0,4% | — |
| CVE-2026-48566 | MED 5.5 | microsoft windows_11_24h2 Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2026-45491 | MED 6.2 | microsoft .net Improper link resolution before file access ('link following') in .NET allows an unauthorized attacker to perform tampering locally. | 0,4% | — |
| CVE-2026-42969 | MED 5.5 | microsoft windows_10_1607 Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-42968 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Telephony Service allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-31533 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption The -EBUSY handling in tls_do_encryption(), introduced by commit 859054147318 ("net: tls: handle backlogging of crypto r | 0,4% | — |
| CVE-2026-22922 | MED 6.5 | apache airflow Apache Airflow versions 3.1.0 through 3.1.6 contain an authorization flaw that can allow an authenticated user with custom permissions limited to task access to view task logs without having task log access. Users are recommended to upgrade to Apache Airflow | 0,4% | — |
| CVE-2026-20081 | MED 6.5 | cisco unity_connection Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker to download arbitrary files from an affected system. To exploit these vulnerabilities, the attacker must have valid administrative credentials. These | 0,4% | — |
| CVE-2026-20078 | MED 6.5 | cisco unity_connection Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker to download arbitrary files from an affected system. To exploit these vulnerabilities, the attacker must have valid administrative credentials. These | 0,4% | — |
| CVE-2025-58474 | MED 5.3 | f5 big-ip_advanced_web_application_firewall When BIG-IP Advanced WAF is configured on a virtual server with Server-Side Request Forgery (SSRF) protection or when an NGINX server is configured with App Protect Bot Defense, undisclosed requests can disrupt new client requests. Note: Software versions whi | 0,4% | — |
| CVE-2025-53137 | HIGH 7.0 | microsoft windows_10_1507 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-20327 | HIGH 7.7 | cisco ios A vulnerability in the web UI of Cisco IOS Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper input validation. An attacker cou | 0,4% | — |
| CVE-2025-20312 | HIGH 7.7 | cisco ios_xe A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper error | 0,4% | — |
| CVE-2024-33507 | HIGH 7.4 | fortinet fortiisolator An insufficient session expiration vulnerability [CWE-613] and an incorrect authorization vulnerability [CWE-863] in FortiIsolator 2.4.0 through 2.4.4, 2.3 all versions, 2.2.0, 2.1 all versions, 2.0 all versions authentication mechanism may allow remote unauth | 0,4% | — |
| CVE-2023-4594 | MED 6.1 | seattlelab slmail Stored XSS vulnerability. This vulnerability could allow an attacker to store a malicious JavaScript payload via GET and POST methods on multiple parameters in the MailAdmin_dll.htm file. | 0,4% | — |
| CVE-2023-26276 | MED 5.9 | ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.5.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 248147. | 0,4% | — |
| CVE-2021-47476 | MED 4.6 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: comedi: ni_usb6501: fix NULL-deref in command paths The driver uses endpoint-sized USB transfer buffers but had no sanity checks on the sizes. This can lead to zero-size-pointer dereferences | 0,4% | — |
| CVE-2021-38933 | MED 5.9 | ibm sterling_connect\ IBM Sterling Connect:Direct for UNIX 1.5 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 210574. | 0,4% | — |
| CVE-2021-1053 | MED 5.5 | nvidia gpu_driver NVIDIA GPU Display Driver for Windows and Linux, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape or IOCTL in which improper validation of a user pointer may lead to denial of service. | 0,4% | — |
| CVE-2020-3961 | HIGH 7.8 | vmware horizon_client VMware Horizon Client for Windows (prior to 5.4.3) contains a privilege escalation vulnerability due to folder permission configuration and unsafe loading of libraries. A local user on the system where the software is installed may exploit this issue to run co | 0,4% | — |
| CVE-2019-0157 | MED 5.5 | intel software_guard_extensions Insufficient input validation in the Intel(R) SGX driver for Linux may allow an authenticated user to potentially enable a denial of service via local access. | 0,4% | — |
| CVE-2017-18255 | HIGH 7.8 | linux linux_kernel The perf_cpu_time_max_percent_handler function in kernel/events/core.c in the Linux kernel before 4.11 allows local users to cause a denial of service (integer overflow) or possibly have unspecified other impact via a large value, as demonstrated by an incorre | 0,4% | — |
| CVE-2017-17854 | HIGH 7.8 | debian debian_linux kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (integer overflow and memory corruption) or possibly have unspecified other impact by leveraging unrestricted integer values for pointer arithmetic. | 0,4% | — |
| CVE-2017-17853 | HIGH 7.8 | debian debian_linux kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging incorrect BPF_RSH signed bounds calculations. | 0,4% | — |
| CVE-2016-7916 | MED 5.5 | linux linux_kernel Race condition in the environ_read function in fs/proc/base.c in the Linux kernel before 4.5.4 allows local users to obtain sensitive information from kernel memory by reading a /proc/*/environ file during a process-setup time interval in which environment-var | 0,4% | — |