58.518 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.518 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più basso | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2018-10323 | MED 5.5 | canonical ubuntu_linux The xfs_bmap_extents_to_btree function in fs/xfs/libxfs/xfs_bmap.c in the Linux kernel through 4.16.3 allows local users to cause a denial of service (xfs_bmapi_write NULL pointer dereference) via a crafted xfs image. | 0,6% | — |
| CVE-2016-4581 | MED 5.5 | canonical ubuntu_linux fs/pnode.c in the Linux kernel before 4.5.4 does not properly traverse a mount propagation tree in a certain case involving a slave mount, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a crafted series of mount s | 0,6% | — |
| CVE-2016-4482 | MED 6.2 | canonical ubuntu_linux The proc_connectinfo function in drivers/usb/core/devio.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted USBDEVFS_CONNECTINFO ioctl c | 0,6% | — |
| CVE-2016-3156 | MED 5.5 | canonical ubuntu_linux The IPv4 implementation in the Linux kernel before 4.5.2 mishandles destruction of device objects, which allows guest OS users to cause a denial of service (host OS networking outage) by arranging for a large number of IP addresses. | 0,6% | — |
| CVE-2013-7393 | LOW 2.4 | apache subversion The daemonize.py module in Subversion 1.8.0 before 1.8.2 allows local users to gain privileges via a symlink attack on the pid file created for (1) svnwcsub.py or (2) irkerbridge.py when the --pidfile option is used. NOTE: this issue was SPLIT from CVE-2013-4 | 0,6% | — |
| CVE-2026-68831 | MED 5.5 | microsoft windows_10_1607 Files or directories accessible to external parties in Windows Defender Firewall Service allows an authorized attacker to disclose information locally. | 0,6% | — |
| CVE-2026-33782 | MED 6.5 | juniper junos A Missing Release of Memory after Effective Lifetime vulnerability in the DHCP daemon (jdhcpd) of Juniper Networks Junos OS on MX Series, allows an adjacent, unauthenticated attacker to cause a memory leak, that will eventually cause a complete Denial-of-Servi | 0,6% | — |
| CVE-2025-54910 | HIGH 8.4 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | 0,6% | — |
| CVE-2025-30001 | HIGH 7.3 | apache streampark Incorrect Execution-Assigned Permissions vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are recommended to upgrade to version 2.1.6, which fixes the issue. | 0,6% | — |
| CVE-2023-25606 | MED 6.5 | fortinet fortianalyzer An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-23] in FortiAnalyzer and FortiManager management interface 7.2.0 through 7.2.1, 7.0.0 through 7.0.5, 6.4 all versions may allow a remote and authenticated att | 0,6% | — |
| CVE-2022-30992 | MED 6.1 | acronis cyber_protect Open redirect via user-controlled query parameter. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 29240 | 0,6% | — |
| CVE-2021-24017 | MED 5.4 | fortinet fortimanager An improper authentication in Fortinet FortiManager version 6.4.3 and below, 6.2.6 and below allows attacker to assign arbitrary Policy and Object modules via crafted requests to the request handler. | 0,6% | — |
| CVE-2018-15326 | HIGH 7.5 | f5 big-ip_access_policy_manager In some situations on BIG-IP APM 14.0.0-14.0.0.2, 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, or 11.6.0-11.6.3.2, the CRLDP Auth access policy agent may treat revoked certificates as valid when the BIG-IP APM system fails to download a new Certificate Revocation List. | 0,6% | — |
| CVE-2026-32223 | MED 6.8 | microsoft windows_11_24h2 Heap-based buffer overflow in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack. | 0,6% | — |
| CVE-2025-47989 | HIGH 7.0 | microsoft azure_connected_machine_agent Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally. | 0,6% | — |
| CVE-2025-26639 | HIGH 7.8 | microsoft windows_10_21h2 Integer overflow or wraparound in Windows USB Print Driver allows an authorized attacker to elevate privileges locally. | 0,6% | — |
| CVE-2024-46958 | CRIT 9.1 | nextcloud desktop In Nextcloud Desktop Client 3.13.1 through 3.13.3 on Linux, synchronized files (between the server and client) may become world writable or world readable. This is fixed in 3.13.4. | 0,6% | — |
| CVE-2024-21606 | HIGH 7.5 | juniper junos A Double Free vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX Series allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). In a remote access VPN scenario, if a "tcp-encap-profile" is con | 0,6% | — |
| CVE-2023-6793 | LOW 2.7 | paloaltonetworks pan-os An improper privilege management vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-only administrator to revoke active XML API keys from the firewall and disrupt XML API usage. | 0,6% | — |
| CVE-2023-28263 | MED 5.5 | microsoft visual_studio_2019 Visual Studio Information Disclosure Vulnerability | 0,6% | — |
| CVE-2023-28253 | MED 5.5 | microsoft windows_10_1507 Windows Kernel Information Disclosure Vulnerability | 0,6% | — |
| CVE-2023-24945 | MED 5.5 | microsoft windows_10_1507 Windows iSCSI Target Service Information Disclosure Vulnerability | 0,6% | — |
| CVE-2021-22981 | MED 4.8 | f5 big-ip_access_policy_manager On all versions of BIG-IP 12.1.x and 11.6.x, the original TLS protocol includes a weakness in the master secret negotiation that is mitigated by the Extended Master Secret (EMS) extension defined in RFC 7627. TLS connections that do not use EMS are vulnerable | 0,6% | — |
| CVE-2019-5665 | HIGH 7.8 | nvidia gpu_driver NVIDIA Windows GPU Display driver contains a vulnerability in the 3D vision component in which the stereo service software, when opening a file, does not check for hard links. This behavior may lead to code execution, denial of service or escalation of privile | 0,6% | — |
| CVE-2019-15031 | MED 4.4 | canonical ubuntu_linux In the Linux kernel through 5.2.14 on the powerpc platform, a local user can read vector registers of other users' processes via an interrupt. To exploit the venerability, a local user starts a transaction (via the hardware transactional memory instruction tbe | 0,6% | — |