57.921 CVE seguite
783 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.921 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2012-5458 | HIGH 8.3 | vmware player VMware Workstation 8.x before 8.0.5 and VMware Player 4.x before 4.0.5 on Windows use weak permissions for unspecified process threads, which allows host OS users to gain host OS privileges via a crafted application. | 0,7% | — |
| CVE-2012-3074 | HIGH 8.3 | cisco telepresence_system_1300_65 An unspecified API on Cisco TelePresence Immersive Endpoint Devices before 1.9.1 allows remote attackers to execute arbitrary commands by leveraging certain adjacency and sending a malformed request on TCP port 61460, aka Bug ID CSCtz38382. | 1,2% | — |
| CVE-2012-2486 | HIGH 8.3 | cisco telepresence_manager The Cisco Discovery Protocol (CDP) implementation on Cisco TelePresence Multipoint Switch before 1.9.0, Cisco TelePresence Immersive Endpoint Devices before 1.9.1, Cisco TelePresence Manager before 1.9.0, and Cisco TelePresence Recording Server before 1.8.1 al | 1,7% | — |
| CVE-2012-2004 | HIGH 8.3 | hp insight_management_agents Open redirect vulnerability in HP Insight Management Agents before 9.0.0.0 on Windows Server 2003 and 2008 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. | 4,3% | — |
| CVE-2012-1518 | HIGH 8.3 | vmware esx VMware Workstation 8.x before 8.0.2, VMware Player 4.x before 4.0.2, VMware Fusion 4.x before 4.1.2, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 use an incorrect ACL for the VMware Tools folder, which allows guest OS users to gain guest OS priv | 1,7% | — |
| CVE-2012-1515 | HIGH 8.3 | vmware esx VMware ESXi 3.5, 4.0, and 4.1 and ESX 3.5, 4.0, and 4.1 do not properly implement port-based I/O operations, which allows guest OS users to gain guest OS privileges by overwriting memory locations in a read-only memory block associated with the Virtual DOS Mac | 0,8% | — |
| CVE-2011-2497 | HIGH 8.3 | linux linux_kernel Integer underflow in the l2cap_config_req function in net/bluetooth/l2cap_core.c in the Linux kernel before 3.0 allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a small command-size val | 2,0% | — |
| CVE-2011-0378 | HIGH 8.3 | cisco telepresence_system_1000 The XML-RPC implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote attackers to execute arbitrary commands via a TCP request, related to a "command injection vulnerability," aka Bug ID CSCtb52587. | 1,4% | — |
| CVE-2010-3705 | HIGH 8.3 | canonical ubuntu_linux The sctp_auth_asoc_get_hmac function in net/sctp/auth.c in the Linux kernel before 2.6.36 does not properly validate the hmac_ids array of an SCTP peer, which allows remote attackers to cause a denial of service (memory corruption and panic) via a crafted valu | 2,0% | — |
| CVE-2008-4395 | HIGH 8.3 | linux linux_kernel Multiple buffer overflows in the ndiswrapper module 1.53 for the Linux kernel 2.6 allow remote attackers to execute arbitrary code by sending packets over a local wireless network that specify long ESSIDs. | 2,4% | — |
| CVE-2008-1453 | HIGH 8.3 | microsoft windows-nt The Bluetooth stack in Microsoft Windows XP SP2 and SP3, and Vista Gold and SP1, allows physically proximate attackers to execute arbitrary code via a large series of Service Discovery Protocol (SDP) packets. | 2,4% | — |
| CVE-2026-85921 | HIGH 8.2 | Double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-83939 | HIGH 8.2 | microsoft windows_11_26h1 Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-81994 | HIGH 8.2 | adobe acrobat Acrobat Reader is affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and d | 0,3% | — |
| CVE-2026-81379 | HIGH 8.2 | microsoft visual_studio_code Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. | 0,3% | — |
| CVE-2026-81378 | HIGH 8.2 | microsoft visual_studio_code Interpretation conflict in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. | 0,3% | — |
| CVE-2026-81357 | HIGH 8.2 | microsoft visual_studio_code Server-side request forgery (ssrf) in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. | 0,3% | — |
| CVE-2026-81356 | HIGH 8.2 | microsoft visual_studio_code Inconsistent interpretation of http requests ('http request/response smuggling') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. | 0,3% | — |
| CVE-2026-81354 | HIGH 8.2 | microsoft windows_10_1809 Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-76413 | HIGH 8.2 | A vulnerability in Cisco Adaptive Security Device Manager (ASDM) single sign-on (SSO) handler for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to log in as the Cisco ASDM administrator user. This vulnerability is due to improper | — | — |
| CVE-2026-76191 | HIGH 8.2 | adobe animate Animate is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary | 0,3% | — |
| CVE-2026-69906 | HIGH 8.2 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-69874 | HIGH 8.2 | microsoft windows_10_1809 Untrusted pointer dereference in Windows ALPC allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-69846 | HIGH 8.2 | microsoft windows_10_1607 Integer overflow or wraparound in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-69820 | HIGH 8.2 | microsoft windows_10_21h2 Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally. | 0,3% | — |