58.507 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.507 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più basso | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2013-4483 | MED 4.9 | linux linux_kernel The ipc_rcu_putref function in ipc/util.c in the Linux kernel before 3.10 does not properly manage a reference count, which allows local users to cause a denial of service (memory consumption or system crash) via a crafted application. | 0,5% | — |
| CVE-2012-4467 | MED 6.6 | linux linux_kernel The (1) do_siocgstamp and (2) do_siocgstampns functions in net/socket.c in the Linux kernel before 3.5.4 use an incorrect argument order, which allows local users to obtain sensitive information from kernel memory or cause a denial of service (system crash) vi | 0,5% | — |
| CVE-2006-6058 | MED 4.0 | linux linux_kernel The minix filesystem code in Linux kernel 2.6.x before 2.6.24, including 2.6.18, allows local users to cause a denial of service (hang) via a malformed minix file stream that triggers an infinite loop in the minix_bmap function. NOTE: this issue might be due | 0,5% | — |
| CVE-2026-68852 | MED 5.5 | microsoft windows_10_1607 Use of uninitialized resource in Microsoft Account allows an authorized attacker to disclose information locally. | 0,5% | — |
| CVE-2026-59354 | CRIT 9.6 | vmware spring_security In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic Client Registration is explicitly enabled, the registration endpoint performs insufficient validation of certain client metadata fields supplied by the regist | 0,5% | — |
| CVE-2026-45843 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: slip: bound decode() reads against the compressed packet length slhc_uncompress() parses a VJ-compressed TCP header by advancing a pointer through the packet via decode() and pull16(). Neith | 0,5% | — |
| CVE-2026-23240 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tls: Fix race condition in tls_sw_cancel_work_tx() This issue was discovered during a code audit. After cancel_delayed_work_sync() is called from tls_sk_proto_close(), tx_work_handler() can | 0,5% | — |
| CVE-2026-20005 | MED 5.8 | cisco cyber_vision Multiple Cisco products are affected by a vulnerability in the Snort 3 Detection Engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspection. This vulnerabil | 0,5% | — |
| CVE-2025-53689 | HIGH 8.8 | apache jackrabbit Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an unsecured document build to load privileges. Users are recommended to upgrade to versions 2.20.17 (Java 8), 2.22.1 (Java 11) or 2.23.2 (Ja | 0,5% | — |
| CVE-2025-49751 | MED 6.8 | microsoft windows_10_1607 Missing synchronization in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network. | 0,5% | — |
| CVE-2025-49711 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0,5% | — |
| CVE-2025-48818 | MED 6.8 | microsoft windows_10_1507 Time-of-check time-of-use (toctou) race condition in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. | 0,5% | — |
| CVE-2025-36048 | HIGH 7.2 | ibm webmethods_integration IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15 could allow a privileged user to escalate their privileges when handling external entities due to execution with unnecessary privileges. | 0,5% | — |
| CVE-2023-52480 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix race condition between session lookup and expire Thread A + Thread B ksmbd_session_lookup | smb2_sess_setup sess = xa_load | 0,5% | — |
| CVE-2023-38733 | MED 4.3 | ibm robotic_process_automation IBM Robotic Process Automation 21.0.0 through 21.0.7.1 and 23.0.0 through 23.0.1 server could allow an authenticated user to view sensitive information from installation logs. IBM X-Force Id: 262293. | 0,5% | — |
| CVE-2023-32553 | MED 5.3 | trendmicro apex_one An Improper access control vulnerability in Trend Micro Apex One and Apex One as a Service could allow an unauthenticated user under certain circumstances to disclose sensitive information on agents. This is similar to, but not identical to CVE-2023-32552. | 0,5% | — |
| CVE-2022-38016 | HIGH 8.8 | microsoft windows_10 Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2022-37984 | HIGH 7.8 | microsoft windows_10 Windows WLAN Service Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2022-37983 | HIGH 7.8 | microsoft windows_10 Microsoft DWM Core Library Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2021-3049 | LOW 2.6 | paloaltonetworks cortex_xsoar An improper authorization vulnerability in the Palo Alto Networks Cortex XSOAR server enables an authenticated network-based attacker with investigation read permissions to download files from incident investigations of which they are aware but are not a part | 0,5% | — |
| CVE-2021-29888 | HIGH 8.8 | ibm infosphere_information_server IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 207123. | 0,5% | — |
| CVE-2018-5750 | MED 5.5 | canonical ubuntu_linux The acpi_smbus_hc_add function in drivers/acpi/sbshc.c in the Linux kernel through 4.14.15 allows local users to obtain sensitive address information by reading dmesg data from an SBS HC printk call. | 0,5% | — |
| CVE-2018-15431 | HIGH 7.3 | cisco webex_business_suite_32 A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software im | 0,5% | — |
| CVE-2018-0053 | MED 6.8 | juniper junos An authentication bypass vulnerability in the initial boot sequence of Juniper Networks Junos OS on vSRX Series may allow an attacker to gain full control of the system without authentication when the system is initially booted up. Affected releases are Junipe | 0,5% | — |
| CVE-2004-0394 | LOW 2.1 | linux linux_kernel A "potential" buffer overflow exists in the panic() function in Linux 2.4.x, although it may not be exploitable due to the functionality of panic. | 0,5% | — |