EN
57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

57.971 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordinato dal più basso Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2025-21321 MED 5.5 microsoft windows_10_1507 Windows Kernel Memory Information Disclosure Vulnerability 0,9%
CVE-2025-21320 MED 5.5 microsoft windows_10_1507 Windows Kernel Memory Information Disclosure Vulnerability 0,9%
CVE-2025-21319 MED 5.5 microsoft windows_10_1507 Windows Kernel Memory Information Disclosure Vulnerability 0,9%
CVE-2025-21318 MED 5.5 microsoft windows_10_1507 Windows Kernel Memory Information Disclosure Vulnerability 0,9%
CVE-2025-21317 MED 5.5 microsoft windows_10_21h2 Windows Kernel Memory Information Disclosure Vulnerability 0,9%
CVE-2025-21316 MED 5.5 microsoft windows_10_1507 Windows Kernel Memory Information Disclosure Vulnerability 0,9%
CVE-2025-21284 MED 5.5 microsoft windows_10_1507 Windows Virtual Trusted Platform Module Denial of Service Vulnerability 0,7%
CVE-2025-21280 MED 5.5 microsoft windows_10_1507 Windows Virtual Trusted Platform Module Denial of Service Vulnerability 0,7%
CVE-2025-21274 MED 5.5 microsoft windows_10_1507 Windows Event Tracing Denial of Service Vulnerability 0,8%
CVE-2025-21257 MED 5.5 microsoft windows_10_1607 Windows WLAN AutoConfig Service Information Disclosure Vulnerability 0,7%
CVE-2025-21155 MED 5.5 adobe substance_3d_stager Substance3D - Stager versions 3.1.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-servic 0,3%
CVE-2025-21126 MED 5.5 adobe indesign InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service condition. An attacker could exploit this vulnerability to cause the application to crash, r 0,3%
CVE-2025-21125 MED 5.5 adobe indesign InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of 0,3%
CVE-2025-21124 MED 5.5 adobe indesign InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this 0,3%
CVE-2025-20213 MED 5.5 cisco catalyst_sd-wan_manager A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, local attacker to overwrite arbitrary files on the local file system of an affected device. To exploit this vulnerability, the attacker mu 0,2%
CVE-2025-13751 MED 5.5 openvpn openvpn Interactive service agent in OpenVPN version 2.5.0 through 2.6.16 and 2.7_alpha1 through 2.7_rc2 on Windows allows a local authenticated user to connect to the service and trigger an error causing a local denial of service. 0,2%
CVE-2025-1349 MED 5.5 ibm sterling_b2b_integrator IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus alte 0,2%
CVE-2025-12439 MED 5.5 google chrome Inappropriate implementation in App-Bound Encryption in Google Chrome on Windows prior to 142.0.7444.59 allowed a local attacker to obtain potentially sensitive information from process memory via a malicious file. (Chromium security severity: Medium) 0,1%
CVE-2025-10221 MED 5.5 axxonsoft axxon_one Insertion of Sensitive Information into Log File (CWE-532) in the ARP Agent component in AxxonSoft Axxon One / AxxonNet / C-WerkNet 2.0.4 and earlier on Windows platforms allows a local attacker to obtain plaintext credentials via reading TRACE log files conta 0,1%
CVE-2025-0913 MED 5.5 golang go os.OpenFile(path, os.O_CREATE|O_EXCL) behaved differently on Unix and Windows systems when the target path was a dangling symlink. On Unix systems, OpenFile with O_CREATE and O_EXCL flags never follows symlinks. On Windows, when the target path was a symlink t 0,3%
CVE-2025-0158 MED 5.5 ibm entirex IBM EntireX 11.1 could allow a local user to cause a denial of service due to an unhandled error and fault isolation. 0,1%
CVE-2024-9469 MED 5.5 paloaltonetworks cortex_xdr_agent A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows non-administrative privileges to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then t 0,2%
CVE-2024-5909 MED 5.5 paloaltonetworks cortex_xdr_agent A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a low privileged local Windows user to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform mali 0,4%
CVE-2024-58097 MED 5.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix RCU stall while reaping monitor destination ring While processing the monitor destination ring, MSDUs are reaped from the link descriptor based on the corresponding buf_id. 0,2%
CVE-2024-58095 MED 5.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: jfs: add check read-only before txBeginAnon() call Added a read-only check before calling `txBeginAnon` in `extAlloc` and `extRecord`. This prevents modification attempts on a read-only moun 0,2%