58.507 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.507 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più basso | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2014-9892 | MED 5.5 | google android The snd_compr_tstamp function in sound/core/compress_offload.c in the Linux kernel through 4.7, as used in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices, does not properly initialize a timestamp data structure, which allows attackers to obtain sens | 0,5% | — |
| CVE-2014-3183 | MED 6.9 | linux linux_kernel Heap-based buffer overflow in the logi_dj_ll_raw_request function in drivers/hid/hid-logitech-dj.c in the Linux kernel before 3.16.2 allows physically proximate attackers to cause a denial of service (system crash) or possibly execute arbitrary code via a craf | 0,5% | — |
| CVE-2012-0028 | HIGH 7.2 | linux linux_kernel The robust futex implementation in the Linux kernel before 2.6.28 does not properly handle processes that make exec system calls, which allows local users to cause a denial of service or possibly gain privileges by writing to a memory location in a child proce | 0,5% | — |
| CVE-2009-0322 | MED 4.9 | canonical ubuntu_linux drivers/firmware/dell_rbu.c in the Linux kernel before 2.6.27.13, and 2.6.28.x before 2.6.28.2, allows local users to cause a denial of service (system crash) via a read system call that specifies zero bytes from the (1) image_type or (2) packet_size file in / | 0,5% | — |
| CVE-2005-3181 | LOW 2.1 | canonical ubuntu_linux The audit system in Linux kernel 2.6.6, and other versions before 2.6.13.4, when CONFIG_AUDITSYSCALL is enabled, uses an incorrect function to free names_cache memory, which prevents the memory from being tracked by AUDITSYSCALL code and leads to a memory leak | 0,5% | — |
| CVE-2005-0001 | MED 6.9 | linux linux_kernel Race condition in the page fault handler (fault.c) for Linux kernel 2.2.x to 2.2.7, 2.4 to 2.4.29, and 2.6 to 2.6.10, when running on multiprocessor machines, allows local users to execute arbitrary code via concurrent threads that share the same virtual memor | 0,5% | — |
| CVE-2026-64102 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Reject MPA FPDU length underflow before signed receive math A malicious connected siw peer can send an iWARP FPDU whose MPA length field (c_hdr->mpa_len, 16 bit big-endian, peer-co | 0,5% | — |
| CVE-2026-25199 | CRIT 9.1 | apache cloudstack Instances deployed via the Proxmox extension allow unauthorized access to instances belonging to other tenants. This issue affects Apache CloudStack: from 4.21.0.0 through 4.22.0.0. The Proxmox extension for CloudStack improperly uses a user-editable i | 0,5% | — |
| CVE-2026-20920 | HIGH 7.8 | microsoft windows_11_23h2 Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. | 0,5% | — |
| CVE-2026-20810 | HIGH 7.8 | microsoft windows_10_1809 Free of memory not on the heap in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0,5% | — |
| CVE-2025-59510 | MED 5.5 | microsoft windows_10_1607 Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to deny service locally. | 0,5% | — |
| CVE-2025-54912 | HIGH 7.8 | microsoft windows_10_1507 Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally. | 0,5% | — |
| CVE-2025-53784 | HIGH 8.4 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0,5% | — |
| CVE-2025-53736 | MED 6.8 | microsoft 365_apps Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | 0,5% | — |
| CVE-2025-20221 | MED 5.3 | cisco ios_xe A vulnerability in the packet filtering features of Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to bypass Layer 3 and Layer 4 traffic filters. This vulnerability is due to improper traffic filtering conditions on an affecte | 0,5% | — |
| CVE-2024-20373 | MED 5.3 | cisco ios_xe_sd-wan A vulnerability in the implementation of the Simple Network Management Protocol (SNMP) IPv4 access control list (ACL) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform SNMP polling of an affected | 0,5% | — |
| CVE-2023-38119 | HIGH 7.8 | foxit pdf_editor Foxit PDF Reader AcroForm signature Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnera | 0,5% | — |
| CVE-2023-38118 | HIGH 7.8 | foxit pdf_editor Foxit PDF Reader AcroForm Doc Object Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulne | 0,5% | — |
| CVE-2023-35347 | HIGH 7.1 | microsoft windows_10_21h2 Microsoft Install Service Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2023-26207 | LOW 3.3 | fortinet fortios An insertion of sensitive information into log file vulnerability in Fortinet FortiOS 7.2.0 through 7.2.4 and FortiProxy 7.0.0 through 7.0.10. 7.2.0 through 7.2.1 allows an attacker to read certain passwords in plain text. | 0,5% | — |
| CVE-2023-20096 | MED 5.4 | cisco unified_contact_center_express A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to perform a stored cross-site scripting (XSS) attack. This vulnerability is due to insufficient input val | 0,5% | — |
| CVE-2022-48673 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/smc: Fix possible access to freed memory in link clear After modifying the QP to the Error state, all RX WR would be completed with WC in IB_WC_WR_FLUSH_ERR status. Current implementatio | 0,5% | — |
| CVE-2020-5913 | HIGH 7.4 | f5 big-ip_access_policy_manager In versions 15.0.0-15.1.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.2, the BIG-IP Client or Server SSL profile ignores revoked certificates, even when a valid CRL is present. This impacts SSL/TLS connections and may result in a ma | 0,5% | — |
| CVE-2020-3261 | MED 6.5 | cisco 6300_series_access_points_firmware A vulnerability in the web-based management interface of Cisco Mobility Express Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF | 0,5% | — |
| CVE-2020-3148 | HIGH 7.1 | cisco prime_network_registrar A vulnerability in the web-based interface of Cisco Prime Network Registrar (CPNR) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protec | 0,5% | — |