58.507 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.507 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più basso | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2025-57870 | CRIT 10.0 | esri arcgis_server A SQL Injection vulnerability exists in Esri ArcGIS Server versions 11.3, 11.4 and 11.5 on Windows, Linux and Kubernetes. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary SQL commands via a specific ArcGIS Feature Service opera | 0,5% | — |
| CVE-2024-49023 | MED 5.9 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 0,5% | — |
| CVE-2024-43646 | MED 6.7 | microsoft windows_10_1607 Windows Secure Kernel Mode Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2024-43645 | MED 6.7 | microsoft windows_10_1507 Windows Defender Application Control (WDAC) Security Feature Bypass Vulnerability | 0,5% | — |
| CVE-2024-43631 | MED 6.7 | microsoft windows_10_21h2 Windows Secure Kernel Mode Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2023-53006 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: cifs: Fix oops due to uncleared server->smbd_conn in reconnect In smbd_destroy(), clear the server->smbd_conn pointer after freeing the smbd_connection struct that it points to so that recon | 0,5% | — |
| CVE-2023-0008 | MED 4.4 | paloaltonetworks pan-os A file disclosure vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write administrator with access to the web interface to export local files from the firewall through a race condition. | 0,5% | — |
| CVE-2022-37426 | MED 4.3 | opennebula opennebula Unrestricted Upload of File with Dangerous Type vulnerability in OpenNebula OpenNebula core on Linux allows File Content Injection. | 0,5% | — |
| CVE-2021-42322 | HIGH 7.8 | microsoft visual_studio_code Visual Studio Code Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2021-38571 | HIGH 7.8 | foxitsoftware foxit_reader An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows DLL hijacking, aka CNVD-C-2021-68000 and CNVD-C-2021-68502. | 0,5% | — |
| CVE-2021-3031 | MED 4.3 | paloaltonetworks pan-os Padding bytes in Ethernet packets on PA-200, PA-220, PA-500, PA-800, PA-2000 Series, PA-3000 Series, PA-3200 Series, PA-5200 Series, and PA-7000 Series firewalls are not cleared before the data frame is created. This leaks a small amount of random information | 0,5% | — |
| CVE-2019-17055 | LOW 3.3 | canonical ubuntu_linux base_sock_create in drivers/isdn/mISDN/socket.c in the AF_ISDN network module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means that unprivileged users can create a raw socket, aka CID-b91ee4aa2a21. | 0,5% | — |
| CVE-2018-16597 | MED 5.5 | linux linux_kernel An issue was discovered in the Linux kernel before 4.8. Incorrect access checking in overlayfs mounts could be used by local attackers to modify or truncate files in the underlying filesystem. | 0,5% | — |
| CVE-2018-10940 | MED 5.5 | debian debian_linux The cdrom_ioctl_media_changed function in drivers/cdrom/cdrom.c in the Linux kernel before 4.16.6 allows local attackers to use a incorrect bounds check in the CDROM driver CDROM_MEDIA_CHANGED ioctl to read out kernel memory. | 0,5% | — |
| CVE-2017-18550 | MED 5.5 | linux linux_kernel An issue was discovered in drivers/scsi/aacraid/commctrl.c in the Linux kernel before 4.13. There is potential exposure of kernel stack memory because aac_get_hba_info does not initialize the hbainfo structure. | 0,5% | — |
| CVE-2016-7461 | HIGH 8.8 | vmware fusion The drag-and-drop (aka DnD) function in VMware Workstation Pro 12.x before 12.5.2 and VMware Workstation Player 12.x before 12.5.2 and VMware Fusion and Fusion Pro 8.x before 8.5.2 allows guest OS users to execute arbitrary code on the host OS or cause a denia | 0,5% | — |
| CVE-2011-1776 | MED 6.1 | linux linux_kernel The is_gpt_valid function in fs/partitions/efi.c in the Linux kernel before 2.6.39 does not check the size of an Extensible Firmware Interface (EFI) GUID Partition Table (GPT) entry, which allows physically proximate attackers to cause a denial of service (hea | 0,5% | — |
| CVE-2004-1234 | LOW 2.1 | linux linux_kernel load_elf_binary in Linux before 2.4.26 allows local users to cause a denial of service (system crash) via an ELF binary in which the interpreter is NULL. | 0,5% | — |
| CVE-2026-53399 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nfsd: release layout stid on setlease failure nfs4_alloc_stid() publishes the new stid into cl->cl_stateids via idr_alloc_cyclic() under cl_lock before returning to nfsd4_alloc_layout_statei | 0,5% | — |
| CVE-2026-53398 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix SECINFO_NO_NAME decode error cleanup nfsd4_decode_secinfo_no_name() currently initializes sin_exp after decoding sin_style. If the XDR stream is truncated, the decoder returns nfse | 0,5% | — |
| CVE-2026-50623 | MED 4.8 | apache cxf An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF. Due to a missing 'throw' keyword in the security context check, the introspection endpoint (/services/oauth2/introspect) can be accessed by any unauthenticated | 0,5% | — |
| CVE-2025-47953 | HIGH 8.4 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 0,5% | — |
| CVE-2025-36128 | HIGH 7.5 | ibm mq IBM MQ 9.1, 9.2, 9.3, 9.4 LTS and 9.3, 9.4 CD is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read operations. By conducting slowloris-type attacks, a remote attacker could exploit this vulnerability to cause a | 0,5% | — |
| CVE-2024-53178 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: Don't leak cfid when reconnect races with open_cached_dir open_cached_dir() may either race with the tcon reconnection even before compound_send_recv() or directly trigger a reconnectio | 0,5% | — |
| CVE-2024-46665 | LOW 3.7 | fortinet fortios An insertion of sensitive information into sent data vulnerability [CWE-201] in FortiOS 7.6.0, 7.4.0 through 7.4.4 may allow an attacker in a man-in-the-middle position to retrieve the RADIUS accounting server shared secret via intercepting accounting-requests | 0,5% | — |