58.532 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.532 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più basso | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2013-0913 | HIGH 7.2 | linux linux_kernel Integer overflow in drivers/gpu/drm/i915/i915_gem_execbuffer.c in the i915 driver in the Direct Rendering Manager (DRM) subsystem in the Linux kernel through 3.8.3, as used in Google Chrome OS before 25.0.1364.173 and other products, allows local users to caus | 0,6% | — |
| CVE-2012-2313 | LOW 1.2 | linux linux_kernel The rio_ioctl function in drivers/net/ethernet/dlink/dl2k.c in the Linux kernel before 3.3.7 does not restrict access to the SIOCSMIIREG command, which allows local users to write data to an Ethernet adapter via an ioctl call. | 0,6% | — |
| CVE-2007-6151 | HIGH 7.2 | linux linux_kernel The isdn_ioctl function in isdn_common.c in Linux kernel 2.6.23 allows local users to cause a denial of service via a crafted ioctl struct in which iocts is not null terminated, which triggers a buffer overflow. | 0,6% | — |
| CVE-2026-69512 | HIGH 8.0 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to elevate privileges over a network. | 0,6% | — |
| CVE-2026-63337 | ND | The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, com.rabbitmq.tools.jsonrpc.ProcedureDescription receives a javaReturnType value in an untrusted system.describe response an | 0,6% | — |
| CVE-2026-53086 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: fix racing timeout handler The bcmgenet_timeout handler tries to take down all tx queues when a single queue times out. This is over zealous and causes many race conditions wi | 0,6% | — |
| CVE-2026-32990 | MED 5.3 | apache tomcat Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614. This issue affects Apache Tomcat: from 11.0.15 through 11.0.19, from 10.1.50 through 10.1.52, from 9.0.113 through 9.0.115. Users are recommended to upgrade | 0,6% | — |
| CVE-2026-20282 | MED 4.9 | A vulnerability in Cisco ISE could allow an authenticated, remote attacker to obtain write access on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploi | 0,6% | — |
| CVE-2025-53192 | HIGH 8.8 | apache commons_ognl ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Expression/Command Delimiters vulnerability in Apache Commons OGNL. This issue affects Apache Commons OGNL: all versions. When using the API Ognl.getValue, the OGNL engine parses and evaluates the | 0,6% | — |
| CVE-2025-49812 | HIGH 7.4 | apache http_server In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows a man-in-the-middle attacker to hijack an HTTP session via a TLS upgrade. Only configurations using "SSLEngine optional" to enable TLS upg | 0,6% | — |
| CVE-2024-6222 | HIGH 7.0 | docker desktop In Docker Desktop before v4.29.0, an attacker who has gained access to the Docker Desktop VM through a container breakout can further escape to the host by passing extensions and dashboard related IPC messages. Docker Desktop v4.29.0 https://docs.docker.com/ | 0,6% | — |
| CVE-2023-52885 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Fix UAF in svc_tcp_listen_data_ready() After the listener svc_sock is freed, and before invoking svc_tcp_accept() for the established child sock, there is a window that the newsock r | 0,6% | — |
| CVE-2023-3864 | HIGH 7.2 | snowsoftware snow_license_manager Blind SQL injection in a service running in Snow Software license manager from version 8.0.0 up to and including 9.30.1 on Windows allows a logged in user with high privileges to inject SQL commands via the web portal. | 0,6% | — |
| CVE-2023-29333 | LOW 3.3 | microsoft 365_apps Microsoft Access Denial of Service Vulnerability | 0,6% | — |
| CVE-2023-26078 | HIGH 7.8 | atera atera Privilege escalation vulnerability was discovered in Atera Agent 1.8.4.4 and prior on Windows due to mishandling of privileged APIs. | 0,6% | — |
| CVE-2023-24594 | MED 5.3 | f5 big-ip_access_policy_manager When an SSL profile is configured on a Virtual Server, undisclosed traffic can cause an increase in CPU or SSL accelerator resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0,6% | — |
| CVE-2022-38436 | HIGH 7.8 | adobe illustrator Adobe Illustrator versions 26.4 (and earlier) and 25.4.7 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this | 0,6% | — |
| CVE-2022-36077 | HIGH 7.2 | electronjs electron The Electron framework enables writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions prior to 21.0.0-beta.1, 20.0.1, 19.0.11, and 18.3.7, Electron is vulnerable to Exposure of Sensitive Information. When following a redirect, | 0,6% | — |
| CVE-2022-35820 | HIGH 7.8 | microsoft windows_10 Windows Bluetooth Driver Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2021-43240 | HIGH 7.8 | microsoft windows_10 NTFS Set Short Name Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2021-43230 | HIGH 7.8 | microsoft windows_10 Windows NTFS Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2021-34456 | HIGH 7.8 | microsoft windows_10 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2021-20446 | MED 5.4 | ibm maximo_for_civil_infrastructure IBM Maximo for Civil Infrastructure 7.6.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a tr | 0,6% | — |
| CVE-2020-5904 | HIGH 8.8 | f5 big-ip_access_policy_manager In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, a cross-site request forgery (CSRF) vulnerability in the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, exists in an undisclosed pa | 0,6% | — |
| CVE-2020-4933 | MED 5.4 | ibm jazz_reporting_service IBM Jazz Reporting Service 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclo | 0,6% | — |