58.507 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.507 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più basso | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2021-38625 | HIGH 7.8 | microsoft windows_server_2008 Windows Kernel Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2021-36974 | HIGH 7.8 | microsoft windows_10 Windows SMB Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2021-36973 | HIGH 7.8 | microsoft windows_10 Windows Redirected Drive Buffering System Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2021-36966 | HIGH 7.8 | microsoft windows_10 Windows Subsystem for Linux Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2021-36964 | HIGH 7.8 | microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2021-36954 | HIGH 8.8 | microsoft windows_10 Windows Bind Filter Driver Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2020-5917 | MED 5.9 | f5 big-ip_access_policy_manager In BIG-IP versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.2 and BIG-IQ versions 5.2.0-7.0.0, the host OpenSSH servers utilize keys of less than 2048 bits which are no longer considered secure. | 0,5% | — |
| CVE-2020-5870 | HIGH 8.1 | f5 big-iq_centralized_management In BIG-IQ 5.2.0-7.0.0, high availability (HA) synchronization mechanisms do not use any form of authentication for connecting to the peer. | 0,5% | — |
| CVE-2019-4640 | CRIT 9.8 | ibm security_secret_server IBM Security Secret Server 10.7 processes patches, image backups and other updates without sufficiently verifying the origin and integrity of the code which could result in an attacker executing malicious code. IBM X-Force ID: 170046. | 0,5% | — |
| CVE-2018-10902 | HIGH 7.8 | canonical ubuntu_linux It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_input_params() and snd_rawmidi_output_status() which are part of snd_rawmidi_ioctl() handler in rawmidi.c file. | 0,5% | — |
| CVE-2017-8360 | MED 5.5 | conexant mictray64 Conexant Systems mictray64 task, as used on HP Elite, EliteBook, ProBook, and ZBook systems, leaks sensitive data (keystrokes) to any process. In mictray64.exe (mic tray icon) 1.0.0.46, a LowLevelKeyboardProc Windows hook is used to capture keystrokes. This da | 0,5% | — |
| CVE-2016-2543 | MED 6.2 | linux linux_kernel The snd_seq_ioctl_remove_events function in sound/core/seq/seq_clientmgr.c in the Linux kernel before 4.4.1 does not verify FIFO assignment before proceeding with FIFO clearing, which allows local users to cause a denial of service (NULL pointer dereference an | 0,5% | — |
| CVE-2014-9900 | MED 5.5 | google android The ethtool_get_wol function in net/core/ethtool.c in the Linux kernel through 4.7, as used in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices, does not initialize a certain data structure, which allows local users to obtain sensitive information via | 0,5% | — |
| CVE-2001-0020 | LOW 2.1 | cisco arrowpoint Directory traversal vulnerability in Arrowpoint (aka Cisco Content Services, or CSS) allows local unprivileged users to read arbitrary files via a .. (dot dot) attack. | 0,5% | — |
| CVE-2026-64319 | CRIT 9.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: validate reply message payload bounds against transfer length nvmet_auth_reply() accesses the variable-length rval[] array using attacker-controlled hl (hash length) and dhvlen ( | 0,5% | — |
| CVE-2026-58528 | MED 6.8 | microsoft windows_10_1809 Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack. | 0,5% | — |
| CVE-2026-31611 | HIGH 8.6 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: require 3 sub-authorities before reading sub_auth[2] parse_dacl() compares each ACE SID against sid_unix_NFS_mode and on match reads sid.sub_auth[2] as the file mode. If sid_unix_NFS | 0,5% | — |
| CVE-2025-62468 | MED 5.5 | microsoft windows_11_23h2 Out-of-bounds read in Windows Defender Firewall Service allows an authorized attacker to disclose information locally. | 0,5% | — |
| CVE-2025-62202 | HIGH 7.1 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | 0,5% | — |
| CVE-2024-25560 | HIGH 7.5 | f5 big-ip_access_policy_manager When BIG-IP AFM is licensed and provisioned, undisclosed DNS traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0,5% | — |
| CVE-2023-38114 | HIGH 7.8 | foxit pdf_editor Foxit PDF Reader AcroForm Doc Object Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerabil | 0,5% | — |
| CVE-2023-1217 | MED 6.5 | google chrome Stack buffer overflow in Crash reporting in Google Chrome on Windows prior to 111.0.5563.64 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium se | 0,5% | — |
| CVE-2022-30532 | MED 5.3 | octopus octopus_server In affected versions of Octopus Deploy, there is no logging of changes to artifacts within Octopus Deploy. | 0,5% | — |
| CVE-2021-31193 | HIGH 7.8 | microsoft windows_10 Windows SSDP Service Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2021-29683 | MED 6.5 | ibm security_identity_manager IBM Security Identity Manager 7.0.2 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 199998. | 0,5% | — |