58.515 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.515 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più basso | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2021-3489 | HIGH 7.8 | canonical ubuntu_linux The eBPF RINGBUF bpf_ringbuf_reserve() function in the Linux kernel did not check that the allocated size was smaller than the ringbuf size, allowing an attacker to perform out-of-bounds writes within the kernel and therefore, arbitrary code execution. This is | 0,5% | — |
| CVE-2021-31973 | HIGH 7.8 | microsoft windows_10 Windows GPSVC Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2021-31953 | HIGH 7.8 | microsoft windows_10 Windows Filter Manager Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2021-31190 | HIGH 7.8 | microsoft windows_10 Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2021-28436 | HIGH 7.8 | microsoft windows_10 Windows Speech Runtime Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2021-28351 | HIGH 7.8 | microsoft windows_10 Windows Speech Runtime Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2021-28347 | HIGH 7.8 | microsoft windows_10 Windows Speech Runtime Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2021-28320 | HIGH 7.8 | microsoft windows_10 Windows Resource Manager PSM Service Extension Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2021-1137 | HIGH 7.8 | cisco catalyst_sd-wan_manager Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or allow an authenticated, local attacker to gain escalated privileges on an affected system. For more information about these v | 0,5% | — |
| CVE-2020-3963 | MED 5.5 | vmware cloud_foundation VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.2), and Fusion (11.x before 11.5.2) contain a use-after-free vulnerability in PVNVRAM. A malicious actor with | 0,5% | — |
| CVE-2020-29012 | MED 5.6 | fortinet fortisandbox An insufficient session expiration vulnerability in FortiSandbox versions 3.2.1 and below may allow an attacker to reuse the unexpired admin user session IDs to gain information about other users configured on the device, should the attacker be able to obtain | 0,5% | — |
| CVE-2019-1632 | MED 4.6 | cisco integrated_management_controller A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The v | 0,5% | — |
| CVE-2013-1130 | MED 6.8 | cisco anyconnect_secure_mobility_client Cisco AnyConnect Secure Mobility Client on Mac OS X uses weak permissions for a library directory, which allows local users to gain privileges via a crafted library file, aka Bug ID CSCue33619. | 0,5% | — |
| CVE-2005-2553 | LOW 2.1 | linux linux_kernel The find_target function in ptrace32.c in the Linux kernel 2.4.x before 2.4.29 does not properly handle a NULL return value from another function, which allows local users to cause a denial of service (kernel crash/oops) by running a 32-bit ltrace program with | 0,5% | — |
| CVE-2026-31631 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix buffer overread in rxgk_do_verify_authenticator() Fix rxgk_do_verify_authenticator() to check the buffer size before checking the nonce. | 0,6% | — |
| CVE-2026-23663 | HIGH 7.5 | microsoft global_secure_access Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network. | 0,6% | — |
| CVE-2026-20819 | MED 5.5 | microsoft windows_11_23h2 Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally. | 0,6% | — |
| CVE-2024-46865 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: fou: fix initialization of grc The grc must be initialize first. There can be a condition where if fou is NULL, goto out will be executed and grc would be used uninitialized. | 0,6% | — |
| CVE-2024-21339 | MED 6.4 | microsoft windows_10_1809 Windows USB Generic Parent Driver Remote Code Execution Vulnerability | 0,6% | — |
| CVE-2024-20492 | MED 6.0 | cisco telepresence_video_communication_server A vulnerability in the restricted shell of Cisco Expressway Series could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, the attacker | 0,6% | — |
| CVE-2021-43975 | MED 6.7 | debian debian_linux In the Linux kernel through 5.15.2, hw_atl_utils_fw_rpc_wait in drivers/net/ethernet/aquantia/atlantic/hw_atl/hw_atl_utils.c allows an attacker (who can introduce a crafted device) to trigger an out-of-bounds write via a crafted length value. | 0,6% | — |
| CVE-2020-8607 | MED 6.7 | trendmicro antivirus_toolkit An input validation vulnerability found in multiple Trend Micro products utilizing a particular version of a specific rootkit protection driver could allow an attacker in user-mode with administrator permissions to abuse the driver to modify a kernel address t | 0,6% | — |
| CVE-2019-19807 | HIGH 7.8 | canonical ubuntu_linux In the Linux kernel before 5.3.11, sound/core/timer.c has a use-after-free caused by erroneous code refactoring, aka CID-e7af6307a8a5. This is related to snd_timer_open and snd_timer_close_locked. The timeri variable was originally intended to be for a newly c | 0,6% | — |
| CVE-2018-15594 | MED 5.5 | canonical ubuntu_linux arch/x86/kernel/paravirt.c in the Linux kernel before 4.18.1 mishandles certain indirect calls, which makes it easier for attackers to conduct Spectre-v2 attacks against paravirtual guests. | 0,6% | — |
| CVE-2013-6381 | MED 6.9 | linux linux_kernel Buffer overflow in the qeth_snmp_command function in drivers/s390/net/qeth_core_main.c in the Linux kernel through 3.12.1 allows local users to cause a denial of service or possibly have unspecified other impact via an SNMP ioctl call with a length value that | 0,6% | — |