EN
58.507 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.507 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più basso In KEV dal, ordina dal più alto
CVE-2017-7335 MED 5.4 fortinet fortiwlc A Cross-Site Scripting (XSS) vulnerability in Fortinet FortiWLC 6.1-x (6.1-2, 6.1-4 and 6.1-5); 7.0-x (7.0-7, 7.0-8, 7.0-9, 7.0-10); and 8.x (8.0, 8.1, 8.2 and 8.3.0-8.3.2) allows an authenticated user to inject arbitrary web script or HTML via non-sanitized p 0,5% —
CVE-2014-0203 MED 5.5 linux linux_kernel The __do_follow_link function in fs/namei.c in the Linux kernel before 2.6.33 does not properly handle the last pathname component during use of certain filesystems, which allows local users to cause a denial of service (incorrect free operations and system cr 0,5% —
CVE-2014-0181 LOW 2.1 linux linux_kernel The Netlink implementation in the Linux kernel through 3.14.1 does not provide a mechanism for authorizing socket operations based on the opener of a socket, which allows local users to bypass intended access restrictions and modify network configurations by u 0,5% —
CVE-2010-1148 MED 4.7 linux linux_kernel The cifs_create function in fs/cifs/dir.c in the Linux kernel 2.6.33.2 and earlier allows local users to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via a NULL nameidata (aka nd) field in a POSIX file 0,5% —
CVE-2026-50222 HIGH 7.5 apache cloudstack Missing Authorization, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's Userdata reference APIs. Several userdata-related APIs in Apache CloudStack, including deleteUserData, linkUserDataToTemplate, resetUserData 0,5% —
CVE-2026-41280 MED 4.9 apache dolphinscheduler Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects This issue affects Apache DolphinScheduler versions prior to 3.4.2. Users are recommended to upgrade to version 3.4.2, which 0,5% —
CVE-2024-50284 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: Fix the missing xa_store error check xa_store() can fail, it return xa_err(-EINVAL) if the entry cannot be stored in an XArray, or xa_err(-ENOMEM) if memory allocation failed, so chec 0,5% —
CVE-2024-30395 HIGH 7.5 juniper junos An Improper Validation of Specified Type of Input vulnerability in Routing Protocol Daemon (RPD) of Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause Denial of Service (DoS). If a BGP update is received over an establish 0,5% —
CVE-2023-53338 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: lwt: Fix return values of BPF xmit ops BPF encap ops can return different types of positive values, such like NET_RX_DROP, NET_XMIT_CN, NETDEV_TX_BUSY, and so on, from function skb_do_redire 0,5% —
CVE-2022-0027 MED 4.3 paloaltonetworks cortex_xsoar An improper authorization vulnerability in Palo Alto Network Cortex XSOAR software enables authenticated users in non-Read-Only groups to generate an email report that contains summary information about all incidents in the Cortex XSOAR instance, including inc 0,5% —
CVE-2018-1922 HIGH 8.4 ibm db2 IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is affected by buffer overflow vulnerability that can potentially result in arbitrary code execution. IBM X-Force ID: 152858. 0,5% —
CVE-2006-6056 MED 4.9 linux linux_kernel Linux kernel 2.6.x up to 2.6.18 and possibly other versions, when SELinux hooks are enabled, allows local users to cause a denial of service (crash) via a malformed file stream that triggers a NULL pointer dereference in the superblock_doinit function, as demo 0,5% —
CVE-2026-68791 HIGH 8.6 microsoft azure_machine_learning Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over a network. 0,5% —
CVE-2026-42526 MED 5.3 apache apache-airflow-providers-amazon In the AWS Secrets Manager and SSM Parameter Store secrets backends of `apache-airflow-providers-amazon` prior to 9.28.0, the team-scoping logic could resolve a `conn_id` containing a `/` (e.g. `"my_team/conn"`) to the same path as another team's team-scoped s 0,5% —
CVE-2026-34476 HIGH 7.1 apache skywalking_mcp Server-Side Request Forgery via SW-URL Header vulnerability in Apache SkyWalking MCP. This issue affects Apache SkyWalking MCP: 0.1.0. Users are recommended to upgrade to version 0.2.0, which fixes this issue. 0,5% —
CVE-2026-33826 HIGH 8.0 microsoft windows_server_2012 Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network. 0,5% —
CVE-2026-20833 MED 5.5 microsoft windows_server_2008 Use of a broken or risky cryptographic algorithm in Windows Kerberos allows an authorized attacker to disclose information locally. 0,5% —
CVE-2026-20825 MED 4.4 microsoft windows_10_1809 Improper access control in Windows Hyper-V allows an authorized attacker to disclose information locally. 0,5% —
CVE-2025-38052 HIGH 8.8 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: net/tipc: fix slab-use-after-free Read in tipc_aead_encrypt_done Syzbot reported a slab-use-after-free with the following call trace: ===================================================== 0,5% —
CVE-2025-21271 HIGH 7.8 microsoft windows_10_1809 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability 0,5% —
CVE-2024-56688 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: sunrpc: clear XPRT_SOCK_UPD_TIMEOUT when reset transport Since transport->sock has been set to NULL during reset transport, XPRT_SOCK_UPD_TIMEOUT also needs to be cleared. Otherwise, the xs_ 0,5% —
CVE-2024-46855 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_socket: fix sk refcount leaks We must put 'sk' reference before returning. 0,5% —
CVE-2024-21336 LOW 2.5 microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability 0,5% —
CVE-2023-35898 MED 4.3 ibm infosphere_information_server IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information due to an insecure security configuration in InfoSphere Data Flow Designer. IBM X-Force ID: 259352. 0,5% —
CVE-2022-31676 HIGH 7.8 debian debian_linux VMware Tools (12.0.0, 11.x.y and 10.x.y) contains a local privilege escalation vulnerability. A malicious actor with local non-administrative access to the Guest OS can escalate privileges as a root user in the virtual machine. 0,5% —