58.507 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.507 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più basso | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2018-0429 | HIGH 7.8 | cisco thor_video_codec Stack-based buffer overflow in the Cisco Thor decoder before commit 18de8f9f0762c3a542b1122589edb8af859d9813 allows local users to cause a denial of service (segmentation fault) and execute arbitrary code via a crafted non-conformant Thor bitstream. | 0,5% | — |
| CVE-2017-4946 | HIGH 7.8 | vmware vrealize_operations_for_horizon The VMware V4H and V4PA desktop agents (6.x before 6.5.1) contain a privilege escalation vulnerability. Successful exploitation of this issue could result in a low privileged windows user escalating their privileges to SYSTEM. | 0,5% | — |
| CVE-2016-3699 | HIGH 7.4 | linux linux_kernel The Linux kernel, as used in Red Hat Enterprise Linux 7.2 and Red Hat Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended Secure Boot restrictions and execute untrusted code by appending ACPI tables to the init | 0,5% | — |
| CVE-2014-8989 | MED 4.6 | linux linux_kernel The Linux kernel through 3.17.4 does not properly restrict dropping of supplemental group memberships in certain namespace scenarios, which allows local users to bypass intended file permissions by leveraging a POSIX ACL containing an entry for the group categ | 0,5% | — |
| CVE-2014-4654 | MED 4.6 | canonical ubuntu_linux The snd_ctl_elem_add function in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 does not check authorization for SNDRV_CTL_IOCTL_ELEM_REPLACE commands, which allows local users to remove kernel controls and cause a de | 0,5% | — |
| CVE-2014-4653 | MED 4.6 | canonical ubuntu_linux sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 does not ensure possession of a read/write lock, which allows local users to cause a denial of service (use-after-free) and obtain sensitive information from kernel memor | 0,5% | — |
| CVE-2009-2406 | MED 6.9 | linux kernel Stack-based buffer overflow in the parse_tag_11_packet function in fs/ecryptfs/keystore.c in the eCryptfs subsystem in the Linux kernel before 2.6.30.4 allows local users to cause a denial of service (system crash) or possibly gain privileges via vectors invol | 0,5% | — |
| CVE-2026-80354 | HIGH 8.1 | apache camel Authorization bypass through User-Controlled key vulnerability in Apache Camel K. An authorization vulnerability in custom resource resolution allows a tenant to reference secrets by name in the operator namespace, potentially exposing secrets belonging to | 0,5% | — |
| CVE-2026-20957 | HIGH 7.8 | microsoft 365_apps Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0,5% | — |
| CVE-2026-20146 | MED 5.5 | cisco identity_services_engine A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system to either read or delete arbitrary fil | 0,5% | — |
| CVE-2026-20136 | MED 6.0 | cisco identity_services_engine A vulnerability in the CLI of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, local attacker with administrative privileges to perform a command injection attack on the underlying opera | 0,5% | — |
| CVE-2025-64899 | HIGH 7.8 | adobe acrobat Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure | 0,5% | — |
| CVE-2025-59208 | HIGH 7.1 | microsoft windows_10_1507 Out-of-bounds read in Windows MapUrlToZone allows an unauthorized attacker to disclose information over a network. | 0,5% | — |
| CVE-2025-54104 | MED 6.7 | microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally. | 0,5% | — |
| CVE-2025-50173 | HIGH 7.8 | microsoft windows_10_1507 Weak authentication in Windows Installer allows an authorized attacker to elevate privileges locally. | 0,5% | — |
| CVE-2024-53880 | MED 4.9 | nvidia triton_inference_server NVIDIA Triton Inference Server contains a vulnerability in the model loading API, where a user could cause an integer overflow or wraparound error by loading a model with an extra-large file size that overflows an internal variable. A successful exploit of thi | 0,5% | — |
| CVE-2024-43553 | HIGH 7.4 | microsoft windows_10_1507 NT OS Kernel Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2024-23607 | MED 5.5 | f5 f5os-a A directory traversal vulnerability exists in the F5OS QKView utility that allows an authenticated attacker to read files outside the QKView directory. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0,5% | — |
| CVE-2024-22268 | HIGH 7.1 | vmware fusion VMware Workstation and Fusion contain a heap buffer-overflow vulnerability in the Shader functionality. A malicious actor with non-administrative access to a virtual machine with 3D graphics enabled may be able to exploit this vulnerability to create a denial | 0,5% | — |
| CVE-2024-21586 | HIGH 7.5 | juniper junos An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX Series and NFX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). If an a | 0,5% | — |
| CVE-2024-20357 | MED 5.9 | cisco ip_phone_6821_with_multiplatform_firmware A vulnerability in the XML service of Cisco IP Phone firmware could allow an unauthenticated, remote attacker to initiate phone calls on an affected device. This vulnerability exists because bounds-checking does not occur while parsing XML requests. An at | 0,5% | — |
| CVE-2023-42098 | LOW 3.3 | foxit pdf_editor Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerabil | 0,5% | — |
| CVE-2023-41742 | HIGH 7.5 | acronis agent Excessive attack surface due to binding to an unrestricted IP address. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 30430, Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 35979. | 0,5% | — |
| CVE-2019-1972 | MED 6.7 | cisco enterprise_nfv_infrastructure_software A vulnerability the Cisco Enterprise NFV Infrastructure Software (NFVIS) restricted CLI could allow an authenticated, local attacker with valid administrator-level credentials to elevate privileges and execute arbitrary commands on the underlying operating sys | 0,5% | — |
| CVE-2019-11191 | LOW 2.5 | linux linux_kernel The Linux kernel through 5.0.7, when CONFIG_IA32_AOUT is enabled and ia32_aout is loaded, allows local users to bypass ASLR on setuid a.out programs (if any exist) because install_exec_creds() is called too late in load_aout_binary() in fs/binfmt_aout.c, and t | 0,5% | — |