EN
58.532 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.532 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più basso In KEV dal, ordina dal più alto
CVE-2013-0913 HIGH 7.2 linux linux_kernel Integer overflow in drivers/gpu/drm/i915/i915_gem_execbuffer.c in the i915 driver in the Direct Rendering Manager (DRM) subsystem in the Linux kernel through 3.8.3, as used in Google Chrome OS before 25.0.1364.173 and other products, allows local users to caus 0,6% —
CVE-2012-2313 LOW 1.2 linux linux_kernel The rio_ioctl function in drivers/net/ethernet/dlink/dl2k.c in the Linux kernel before 3.3.7 does not restrict access to the SIOCSMIIREG command, which allows local users to write data to an Ethernet adapter via an ioctl call. 0,6% —
CVE-2007-6151 HIGH 7.2 linux linux_kernel The isdn_ioctl function in isdn_common.c in Linux kernel 2.6.23 allows local users to cause a denial of service via a crafted ioctl struct in which iocts is not null terminated, which triggers a buffer overflow. 0,6% —
CVE-2026-69512 HIGH 8.0 microsoft windows_10_1607 Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to elevate privileges over a network. 0,6% —
CVE-2026-63337 ND The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, com.rabbitmq.tools.jsonrpc.ProcedureDescription receives a javaReturnType value in an untrusted system.describe response an 0,6% —
CVE-2026-53086 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: fix racing timeout handler The bcmgenet_timeout handler tries to take down all tx queues when a single queue times out. This is over zealous and causes many race conditions wi 0,6% —
CVE-2026-32990 MED 5.3 apache tomcat Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614. This issue affects Apache Tomcat: from 11.0.15 through 11.0.19, from 10.1.50 through 10.1.52, from 9.0.113 through 9.0.115. Users are recommended to upgrade 0,6% —
CVE-2026-20282 MED 4.9 A vulnerability in Cisco ISE could allow an authenticated, remote attacker to obtain write access on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploi 0,6% —
CVE-2025-53192 HIGH 8.8 apache commons_ognl ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Expression/Command Delimiters vulnerability in Apache Commons OGNL. This issue affects Apache Commons OGNL: all versions. When using the API Ognl.getValue​, the OGNL engine parses and evaluates the 0,6% —
CVE-2025-49812 HIGH 7.4 apache http_server In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows a man-in-the-middle attacker to hijack an HTTP session via a TLS upgrade. Only configurations using "SSLEngine optional" to enable TLS upg 0,6% —
CVE-2024-6222 HIGH 7.0 docker desktop In Docker Desktop before v4.29.0, an attacker who has gained access to the Docker Desktop VM through a container breakout can further escape to the host by passing extensions and dashboard related IPC messages. Docker Desktop v4.29.0 https://docs.docker.com/ 0,6% —
CVE-2023-52885 HIGH 8.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Fix UAF in svc_tcp_listen_data_ready() After the listener svc_sock is freed, and before invoking svc_tcp_accept() for the established child sock, there is a window that the newsock r 0,6% —
CVE-2023-3864 HIGH 7.2 snowsoftware snow_license_manager Blind SQL injection in a service running in Snow Software license manager from version 8.0.0 up to and including 9.30.1 on Windows allows a logged in user with high privileges to inject SQL commands via the web portal. 0,6% —
CVE-2023-29333 LOW 3.3 microsoft 365_apps Microsoft Access Denial of Service Vulnerability 0,6% —
CVE-2023-26078 HIGH 7.8 atera atera Privilege escalation vulnerability was discovered in Atera Agent 1.8.4.4 and prior on Windows due to mishandling of privileged APIs. 0,6% —
CVE-2023-24594 MED 5.3 f5 big-ip_access_policy_manager When an SSL profile is configured on a Virtual Server, undisclosed traffic can cause an increase in CPU or SSL accelerator resource utilization.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. 0,6% —
CVE-2022-38436 HIGH 7.8 adobe illustrator Adobe Illustrator versions 26.4 (and earlier) and 25.4.7 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this 0,6% —
CVE-2022-36077 HIGH 7.2 electronjs electron The Electron framework enables writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions prior to 21.0.0-beta.1, 20.0.1, 19.0.11, and 18.3.7, Electron is vulnerable to Exposure of Sensitive Information. When following a redirect, 0,6% —
CVE-2022-35820 HIGH 7.8 microsoft windows_10 Windows Bluetooth Driver Elevation of Privilege Vulnerability 0,6% —
CVE-2021-43240 HIGH 7.8 microsoft windows_10 NTFS Set Short Name Elevation of Privilege Vulnerability 0,6% —
CVE-2021-43230 HIGH 7.8 microsoft windows_10 Windows NTFS Elevation of Privilege Vulnerability 0,6% —
CVE-2021-34456 HIGH 7.8 microsoft windows_10 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability 0,6% —
CVE-2021-20446 MED 5.4 ibm maximo_for_civil_infrastructure IBM Maximo for Civil Infrastructure 7.6.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a tr 0,6% —
CVE-2020-5904 HIGH 8.8 f5 big-ip_access_policy_manager In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, a cross-site request forgery (CSRF) vulnerability in the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, exists in an undisclosed pa 0,6% —
CVE-2020-4933 MED 5.4 ibm jazz_reporting_service IBM Jazz Reporting Service 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclo 0,6% —