EN
58.444 CVE seguite
792 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.444 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più basso In KEV dal, ordina dal più alto
CVE-2021-1584 MED 6.0 cisco nx-os A vulnerability in Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient restrictions during 0,4% —
CVE-2019-19054 MED 4.7 broadcom brocade_fabric_operating_system_firmware A memory leak in the cx23888_ir_probe() function in drivers/media/pci/cx23885/cx23888-ir.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering kfifo_alloc() failures, aka CID-a7b2df76b42b. 0,4% —
CVE-2019-1745 HIGH 7.8 cisco ios_xe A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with elevated privileges. The vulnerability is due to insufficient input validation of commands supplied by the user. An attack 0,4% —
CVE-2019-1646 HIGH 7.8 cisco sd-wan A vulnerability in the local CLI of the Cisco SD-WAN Solution could allow an authenticated, local attacker to escalate privileges and modify device configuration files. The vulnerability exists because user input is not properly sanitized for certain commands 0,4% —
CVE-2019-15316 HIGH 7.0 valvesoftware steam_client Valve Steam Client for Windows through 2019-08-20 has weak folder permissions, leading to privilege escalation (to NT AUTHORITY\SYSTEM) via crafted use of CreateMountPoint.exe and SetOpLock.exe to leverage a TOCTOU race condition. 0,4% —
CVE-2019-12378 MED 5.5 linux linux_kernel An issue was discovered in ip6_ra_control in net/ipv6/ipv6_sockglue.c in the Linux kernel through 5.1.5. There is an unchecked kmalloc of new_ra, which might allow an attacker to cause a denial of service (NULL pointer dereference and system crash). NOTE: This 0,4% —
CVE-2018-0146 MED 5.4 cisco data_center_analytics_framework A vulnerability in the Cisco Data Center Analytics Framework application could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to improper CSRF protection by the af 0,4% —
CVE-2016-9220 MED 4.3 cisco aironet_access_point_software A Denial of Service Vulnerability in 802.11 ingress packet processing of the Cisco Mobility Express 2800 and 3800 Access Points (APs) could allow an unauthenticated, adjacent attacker to cause the connection table to be full of invalid connections and be unabl 0,4% —
CVE-2016-7425 HIGH 7.8 canonical ubuntu_linux The arcmsr_iop_message_xfer function in drivers/scsi/arcmsr/arcmsr_hba.c in the Linux kernel through 4.8.2 does not restrict a certain length field, which allows local users to gain privileges or cause a denial of service (heap-based buffer overflow) via an AR 0,4% —
CVE-2016-5828 HIGH 7.8 canonical ubuntu_linux The start_thread function in arch/powerpc/kernel/process.c in the Linux kernel through 4.6.3 on powerpc platforms mishandles transactional state, which allows local users to cause a denial of service (invalid process state or TM Bad Thing exception, and system 0,4% —
CVE-2014-3532 LOW 2.1 debian debian_linux dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6, when running on Linux 2.6.37-rc4 or later, allows local users to cause a denial of service (system-bus disconnect of other services or applications) by sending a message containing a file descriptor, then exceed 0,4% —
CVE-2013-4515 MED 4.9 linux linux_kernel The bcm_char_ioctl function in drivers/staging/bcm/Bcmchar.c in the Linux kernel before 3.12 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel memory via an IOCTL_BCM_GET_DEVICE_DRIVER_INFO ioctl 0,4% —
CVE-2012-2764 HIGH 7.2 google chrome Untrusted search path vulnerability in Google Chrome before 20.0.1132.43 on Windows might allow local users to gain privileges via a Trojan horse Metro DLL in the current working directory. 0,4% —
CVE-2008-2137 MED 4.4 debian debian_linux The (1) sparc_mmap_check function in arch/sparc/kernel/sys_sparc.c and the (2) sparc64_mmap_check function in arch/sparc64/kernel/sys_sparc.c, in the Linux kernel 2.4 before 2.4.36.5 and 2.6 before 2.6.25.3, omit some virtual-address range (aka span) checks wh 0,4% —
CVE-2005-3276 LOW 2.1 linux linux_kernel The sys_get_thread_area function in process.c in Linux 2.6 before 2.6.12.4 and 2.6.13 does not clear a data structure before copying it to userspace, which might allow a user process to obtain sensitive information. 0,4% —
CVE-2005-2555 MED 4.6 debian debian_linux Linux kernel 2.6.x does not properly restrict socket policy access to users with the CAP_NET_ADMIN capability, which could allow local users to conduct unauthorized activities via (1) ipv4/ip_sockglue.c and (2) ipv6/ipv6_sockglue.c. 0,4% —
CVE-2005-0749 HIGH 7.2 linux linux_kernel The load_elf_library in the Linux kernel before 2.6.11.6 allows local users to cause a denial of service (kernel crash) via a crafted ELF library or executable, which causes a free of an invalid pointer. 0,4% —
CVE-2026-41081 MED 6.5 apache storm Improper Handling of TLS Client Authentication Failure Leading to Anonymous Principal Assignment in Apache Storm Versions Affected: up to 2.8.7 Description: When TLS transport is enabled in Apache Storm without requiring client certificate authentication (th 0,4% —
CVE-2026-34487 HIGH 7.5 apache tomcat Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernetes bearer token. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1 0,4% —
CVE-2026-20935 MED 6.2 microsoft windows_11_23h2 Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an unauthorized attacker to disclose information locally. 0,4% —
CVE-2026-0309 ND A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS C 0,4% —
CVE-2025-53726 HIGH 7.8 microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. 0,4% —
CVE-2025-53724 HIGH 7.8 microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. 0,4% —
CVE-2025-53152 HIGH 7.8 microsoft windows_10_1507 Use after free in Desktop Windows Manager allows an authorized attacker to execute code locally. 0,4% —
CVE-2025-49707 HIGH 7.9 microsoft dcadsv5-series_azure_vm_firmware Improper access control in Azure Virtual Machines allows an authorized attacker to perform spoofing locally. 0,4% —