57.961 CVE seguite
784 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.961 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2025-21309 | HIGH 8.1 | microsoft windows_server_2012 Windows Remote Desktop Services Remote Code Execution Vulnerability | 14,9% | — |
| CVE-2025-21297 | HIGH 8.1 | microsoft windows_server_2008 Windows Remote Desktop Services Remote Code Execution Vulnerability | 1,4% | — |
| CVE-2025-21295 | HIGH 8.1 | microsoft windows_10_1507 SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability | 1,6% | — |
| CVE-2025-21294 | HIGH 8.1 | microsoft windows_10_1507 Microsoft Digest Authentication Remote Code Execution Vulnerability | 1,2% | — |
| CVE-2025-21224 | HIGH 8.1 | microsoft windows_10_21h2 Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability | 1,9% | — |
| CVE-2025-20160 | HIGH 8.1 | cisco ios A vulnerability in the implementation of the TACACS+ protocol in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to view sensitive data or bypass authentication. This vulnerability exists because the system does | — | — |
| CVE-2025-1915 | HIGH 8.1 | google chrome Improper Limitation of a Pathname to a Restricted Directory in DevTools in Google Chrome on Windows prior to 134.0.6998.35 allowed an attacker who convinced a user to install a malicious extension to bypass file access restrictions via a crafted Chrome Extensi | 0,4% | — |
| CVE-2025-13639 | HIGH 8.1 | google chrome Inappropriate implementation in WebRTC in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Low) | 0,3% | — |
| CVE-2025-13316 | HIGH 8.1 | lynxtechnology twonky_server Twonky Server 8.5.2 on Linux and Windows is vulnerable to a cryptographic flaw, use of hard-coded cryptographic keys. An attacker with knowledge of the encrypted administrator password can decrypt the value with static keys to view the plain text password and | 2,7% | — |
| CVE-2025-13148 | HIGH 8.1 | ibm aspera_orchestrator IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow could an authenticated user to change the password of another user without prior knowledge of that password. | 0,3% | — |
| CVE-2025-1290 | HIGH 8.1 | google chrome_os A race condition Use-After-Free vulnerability exists in the virtio_transport_space_update function within the Kernel 5.4 on ChromeOS. Concurrent allocation and freeing of the virtio_vsock_sock structure during an AF_VSOCK connect syscall can occur before a wo | 0,3% | — |
| CVE-2025-11458 | HIGH 8.1 | google chrome Heap buffer overflow in Sync in Google Chrome prior to 141.0.7390.65 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High) | 0,3% | — |
| CVE-2024-8535 | HIGH 8.1 | citrix netscaler_application_delivery_controller Authenticated user can access unintended user capabilities in NetScaler ADC and NetScaler Gateway if the appliance must be configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) with KCDAccount configuration for Kerberos SSO to access backend resources | 0,4% | — |
| CVE-2024-8534 | HIGH 8.1 | citrix netscaler_application_delivery_controller Memory safety vulnerability leading to memory corruption and Denial of Service in NetScaler ADC and Gateway if the appliance must be configured as a Gateway (VPN Vserver) with RDP Feature enabled OR the appliance must be configured as a Gateway (VPN Vserver) a | 0,6% | — |
| CVE-2024-57973 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: rdma/cxgb4: Prevent potential integer overflow on 32bit The "gl->tot_len" variable is controlled by the user. It comes from process_responses(). On 32bit systems, the "gl->tot_len + sizeof | 0,7% | — |
| CVE-2024-56627 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix Out-of-Bounds Read in ksmbd_vfs_stream_read An offset from client could be a negative value, It could lead to an out-of-bounds read from the stream_buf. Note that this issue is co | 0,6% | — |
| CVE-2024-50215 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: assign dh_key to NULL after kfree_sensitive ctrl->dh_key might be used across multiple calls to nvmet_setup_dhgroup() for the same controller. So it's better to nullify it after | 0,6% | — |
| CVE-2024-49132 | HIGH 8.1 | microsoft windows_10_1809 Windows Remote Desktop Services Remote Code Execution Vulnerability | 1,1% | — |
| CVE-2024-49128 | HIGH 8.1 | microsoft windows_server_2012 Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. | 1,2% | — |
| CVE-2024-49127 | HIGH 8.1 | microsoft windows_10_1507 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 1,3% | — |
| CVE-2024-49126 | HIGH 8.1 | microsoft windows_10_1507 Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability | 1,3% | — |
| CVE-2024-49124 | HIGH 8.1 | microsoft windows_10_1507 Lightweight Directory Access Protocol (LDAP) Client Remote Code Execution Vulnerability | 1,4% | — |
| CVE-2024-49123 | HIGH 8.1 | microsoft windows_10_1809 Windows Remote Desktop Services Remote Code Execution Vulnerability | 1,1% | — |
| CVE-2024-49122 | HIGH 8.1 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 20,4% | — |
| CVE-2024-49120 | HIGH 8.1 | microsoft windows_server_2012 Windows Remote Desktop Services Remote Code Execution Vulnerability | 1,1% | — |