58.444 CVE seguite
792 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.444 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più basso | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2021-1584 | MED 6.0 | cisco nx-os A vulnerability in Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient restrictions during | 0,4% | — |
| CVE-2019-19054 | MED 4.7 | broadcom brocade_fabric_operating_system_firmware A memory leak in the cx23888_ir_probe() function in drivers/media/pci/cx23885/cx23888-ir.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering kfifo_alloc() failures, aka CID-a7b2df76b42b. | 0,4% | — |
| CVE-2019-1745 | HIGH 7.8 | cisco ios_xe A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with elevated privileges. The vulnerability is due to insufficient input validation of commands supplied by the user. An attack | 0,4% | — |
| CVE-2019-1646 | HIGH 7.8 | cisco sd-wan A vulnerability in the local CLI of the Cisco SD-WAN Solution could allow an authenticated, local attacker to escalate privileges and modify device configuration files. The vulnerability exists because user input is not properly sanitized for certain commands | 0,4% | — |
| CVE-2019-15316 | HIGH 7.0 | valvesoftware steam_client Valve Steam Client for Windows through 2019-08-20 has weak folder permissions, leading to privilege escalation (to NT AUTHORITY\SYSTEM) via crafted use of CreateMountPoint.exe and SetOpLock.exe to leverage a TOCTOU race condition. | 0,4% | — |
| CVE-2019-12378 | MED 5.5 | linux linux_kernel An issue was discovered in ip6_ra_control in net/ipv6/ipv6_sockglue.c in the Linux kernel through 5.1.5. There is an unchecked kmalloc of new_ra, which might allow an attacker to cause a denial of service (NULL pointer dereference and system crash). NOTE: This | 0,4% | — |
| CVE-2018-0146 | MED 5.4 | cisco data_center_analytics_framework A vulnerability in the Cisco Data Center Analytics Framework application could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to improper CSRF protection by the af | 0,4% | — |
| CVE-2016-9220 | MED 4.3 | cisco aironet_access_point_software A Denial of Service Vulnerability in 802.11 ingress packet processing of the Cisco Mobility Express 2800 and 3800 Access Points (APs) could allow an unauthenticated, adjacent attacker to cause the connection table to be full of invalid connections and be unabl | 0,4% | — |
| CVE-2016-7425 | HIGH 7.8 | canonical ubuntu_linux The arcmsr_iop_message_xfer function in drivers/scsi/arcmsr/arcmsr_hba.c in the Linux kernel through 4.8.2 does not restrict a certain length field, which allows local users to gain privileges or cause a denial of service (heap-based buffer overflow) via an AR | 0,4% | — |
| CVE-2016-5828 | HIGH 7.8 | canonical ubuntu_linux The start_thread function in arch/powerpc/kernel/process.c in the Linux kernel through 4.6.3 on powerpc platforms mishandles transactional state, which allows local users to cause a denial of service (invalid process state or TM Bad Thing exception, and system | 0,4% | — |
| CVE-2014-3532 | LOW 2.1 | debian debian_linux dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6, when running on Linux 2.6.37-rc4 or later, allows local users to cause a denial of service (system-bus disconnect of other services or applications) by sending a message containing a file descriptor, then exceed | 0,4% | — |
| CVE-2013-4515 | MED 4.9 | linux linux_kernel The bcm_char_ioctl function in drivers/staging/bcm/Bcmchar.c in the Linux kernel before 3.12 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel memory via an IOCTL_BCM_GET_DEVICE_DRIVER_INFO ioctl | 0,4% | — |
| CVE-2012-2764 | HIGH 7.2 | google chrome Untrusted search path vulnerability in Google Chrome before 20.0.1132.43 on Windows might allow local users to gain privileges via a Trojan horse Metro DLL in the current working directory. | 0,4% | — |
| CVE-2008-2137 | MED 4.4 | debian debian_linux The (1) sparc_mmap_check function in arch/sparc/kernel/sys_sparc.c and the (2) sparc64_mmap_check function in arch/sparc64/kernel/sys_sparc.c, in the Linux kernel 2.4 before 2.4.36.5 and 2.6 before 2.6.25.3, omit some virtual-address range (aka span) checks wh | 0,4% | — |
| CVE-2005-3276 | LOW 2.1 | linux linux_kernel The sys_get_thread_area function in process.c in Linux 2.6 before 2.6.12.4 and 2.6.13 does not clear a data structure before copying it to userspace, which might allow a user process to obtain sensitive information. | 0,4% | — |
| CVE-2005-2555 | MED 4.6 | debian debian_linux Linux kernel 2.6.x does not properly restrict socket policy access to users with the CAP_NET_ADMIN capability, which could allow local users to conduct unauthorized activities via (1) ipv4/ip_sockglue.c and (2) ipv6/ipv6_sockglue.c. | 0,4% | — |
| CVE-2005-0749 | HIGH 7.2 | linux linux_kernel The load_elf_library in the Linux kernel before 2.6.11.6 allows local users to cause a denial of service (kernel crash) via a crafted ELF library or executable, which causes a free of an invalid pointer. | 0,4% | — |
| CVE-2026-41081 | MED 6.5 | apache storm Improper Handling of TLS Client Authentication Failure Leading to Anonymous Principal Assignment in Apache Storm Versions Affected: up to 2.8.7 Description: When TLS transport is enabled in Apache Storm without requiring client certificate authentication (th | 0,4% | — |
| CVE-2026-34487 | HIGH 7.5 | apache tomcat Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernetes bearer token. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1 | 0,4% | — |
| CVE-2026-20935 | MED 6.2 | microsoft windows_11_23h2 Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an unauthorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-0309 | ND | A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS C | 0,4% | — |
| CVE-2025-53726 | HIGH 7.8 | microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-53724 | HIGH 7.8 | microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-53152 | HIGH 7.8 | microsoft windows_10_1507 Use after free in Desktop Windows Manager allows an authorized attacker to execute code locally. | 0,4% | — |
| CVE-2025-49707 | HIGH 7.9 | microsoft dcadsv5-series_azure_vm_firmware Improper access control in Azure Virtual Machines allows an authorized attacker to perform spoofing locally. | 0,4% | — |