EN
58.535 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.535 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più basso In KEV dal, ordina dal più alto
CVE-2024-38808 MED 4.3 netapp active_iq_unified_manager In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a user to provide a specially crafted Spring Expression Language (SpEL) expression that may cause a denial of service (DoS) condition. Specifically, an application 0,6% —
CVE-2024-26235 HIGH 7.8 microsoft windows_server_2022_23h2 Windows Update Stack Elevation of Privilege Vulnerability 0,6% —
CVE-2024-2433 MED 4.3 paloaltonetworks pan-os An improper authorization vulnerability in Palo Alto Networks Panorama software enables an authenticated read-only administrator to upload files using the web interface and completely fill one of the disk partitions with those uploaded files, which prevents th 0,6% —
CVE-2024-20464 HIGH 8.6 cisco ios_xe A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient valida 0,6% —
CVE-2023-48633 HIGH 7.8 adobe after_effects Adobe After Effects versions 24.0.3 (and earlier) and 23.6.0 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in 0,6% —
CVE-2022-38457 MED 6.3 linux linux_kernel A use-after-free(UAF) vulnerability was found in function 'vmw_cmd_res_check' in drivers/gpu/vmxgfx/vmxgfx_execbuf.c in Linux kernel's vmwgfx driver with device file '/dev/dri/renderD128 (or Dxxx)'. This flaw allows a local attacker with a user account on the 0,6% —
CVE-2020-2016 HIGH 7.0 paloaltonetworks pan-os A race condition due to insecure creation of a file in a temporary directory vulnerability in PAN-OS allows for root privilege escalation from a limited linux user account. This allows an attacker who has escaped the restricted shell as a low privilege adminis 0,6% —
CVE-2014-7825 HIGH 7.8 linux linux_kernel kernel/trace/trace_syscalls.c in the Linux kernel through 3.17.2 does not properly handle private syscall numbers during use of the perf subsystem, which allows local users to cause a denial of service (out-of-bounds read and OOPS) or bypass the ASLR protectio 0,6% —
CVE-2026-58608 HIGH 8.8 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to execute code over a network. 0,6% —
CVE-2026-50414 HIGH 7.5 microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network. 0,6% —
CVE-2026-50398 HIGH 8.8 microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network. 0,6% —
CVE-2024-46910 HIGH 7.1 apache atlas An authenticated user can perform XSS and potentially impersonate another user. This issue affects Apache Atlas versions 2.3.0 and earlier. Users are recommended to upgrade to version 2.4.0, which fixes the issue. 0,6% —
CVE-2024-43640 HIGH 7.8 microsoft windows_10_21h2 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability 0,6% —
CVE-2024-20657 HIGH 7.0 microsoft windows_10_1507 Windows Group Policy Elevation of Privilege Vulnerability 0,6% —
CVE-2023-38363 MED 4.3 ibm cics_tx IBM CICS TX Advanced 10.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be 0,6% —
CVE-2023-21764 HIGH 7.8 microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability 0,6% —
CVE-2022-30610 MED 4.5 ibm spectrum_copy_data_management IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 is vulnerable to reverse tabnabbing where it could allow a page linked to from within IBM Spectrum Copy Data Management to rewrite it. An administrator could enter a link to a malicious URL that anothe 0,6% —
CVE-2021-41019 LOW 3.5 fortinet fortios An improper validation of certificate with host mismatch [CWE-297] vulnerability in FortiOS versions 6.4.6 and below may allow the connection to a malicious LDAP server via options in GUI, leading to disclosure of sensitive information, such as AD credentials. 0,6% —
CVE-2021-28314 HIGH 7.8 microsoft windows_10 Windows Hyper-V Elevation of Privilege Vulnerability 0,6% —
CVE-2020-27152 MED 5.5 linux linux_kernel An issue was discovered in ioapic_lazy_update_eoi in arch/x86/kvm/ioapic.c in the Linux kernel before 5.9.2. It has an infinite loop related to improper interaction between a resampler and edge triggering, aka CID-77377064c3a9. 0,6% —
CVE-2019-11396 HIGH 7.8 avira free_security_suite An issue was discovered in Avira Free Security Suite 10. The permissive access rights on the SoftwareUpdater folder (files / folders and configuration) are incompatible with the privileged file manipulation performed by the product. Files can be created that c 0,6% —
CVE-2018-25015 HIGH 7.8 linux linux_kernel An issue was discovered in the Linux kernel before 4.14.16. There is a use-after-free in net/sctp/socket.c for a held lock after a peel off, aka CID-a0ff660058b8. 0,6% —
CVE-2017-12283 MED 6.1 cisco aironet_3800_firmware A vulnerability in the handling of 802.11w Protected Management Frames (PAF) by Cisco Aironet 3800 Series Access Points could allow an unauthenticated, adjacent attacker to terminate a valid user connection to an affected device, aka Denial of Service. The vul 0,6% —
CVE-2017-12282 MED 6.1 cisco wireless_lan_controller_software A vulnerability in the Access Network Query Protocol (ANQP) ingress frame processing functionality of Cisco Wireless LAN Controllers could allow an unauthenticated, Layer 2 RF-adjacent attacker to cause an affected device to restart unexpectedly, resulting in 0,6% —
CVE-2015-8785 MED 6.2 linux linux_kernel The fuse_fill_write_pages function in fs/fuse/file.c in the Linux kernel before 4.4 allows local users to cause a denial of service (infinite loop) via a writev system call that triggers a zero length for the first segment of an iov. 0,6% —