58.441 CVE seguite
792 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.441 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più basso | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2025-55334 | MED 6.2 | microsoft windows_11_22h2 Cleartext storage of sensitive information in Windows Kernel allows an unauthorized attacker to bypass a security feature locally. | 0,4% | — |
| CVE-2025-47980 | MED 6.2 | microsoft windows_10_1507 Exposure of sensitive information to an unauthorized actor in Windows Imaging Component allows an unauthorized attacker to disclose information locally. | 0,6% | — |
| CVE-2025-3908 | MED 6.2 | openvpn openvpn3linux The configuration initialization tool in OpenVPN 3 Linux v20 through v24 on Linux allows a local attacker to use symlinks pointing at an arbitrary directory which will change the ownership and permissions of that destination directory. | 0,2% | — |
| CVE-2025-36083 | MED 6.2 | ibm concert IBM Concert Software 1.0.0 through 2.0.0 could allow a local user to obtain sensitive information from buffers due to improper clearing of heap memory before release. | 0,1% | — |
| CVE-2025-36051 | MED 6.2 | ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 stores potentially sensitive information in configuration files that could be read by a local user. | 0,1% | — |
| CVE-2025-36050 | MED 6.2 | ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 stores potentially sensitive information in log files that could be read by a local user. | 0,2% | — |
| CVE-2025-29957 | MED 6.2 | microsoft windows_10_1507 Uncontrolled resource consumption in Windows Deployment Services allows an unauthorized attacker to deny service locally. | 0,6% | — |
| CVE-2025-29955 | MED 6.2 | microsoft windows_11_24h2 Improper input validation in Windows Hyper-V allows an unauthorized attacker to deny service locally. | 0,6% | — |
| CVE-2025-29819 | MED 6.2 | microsoft windows_admin_center External control of file name or path in Azure Portal Windows Admin Center allows an unauthorized attacker to disclose information locally. | 1,1% | — |
| CVE-2025-21278 | MED 6.2 | microsoft windows_10_1507 Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability | 0,6% | — |
| CVE-2024-52898 | MED 6.2 | ibm mq IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a local user to obtain sensitive information when a detailed technical error message is returned. | 0,2% | — |
| CVE-2024-52897 | MED 6.2 | ibm mq IBM MQ 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned. | 0,2% | — |
| CVE-2024-52896 | MED 6.2 | ibm mq IBM MQ 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned. | 0,3% | — |
| CVE-2024-50251 | MED 6.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_payload: sanitize offset and length before calling skb_checksum() If access to offset + length is larger than the skbuff length, then skb_checksum() triggers BUG_ON(). skb_ch | 0,5% | — |
| CVE-2024-46671 | MED 6.2 | fortinet fortiweb An Incorrect User Management vulnerability [CWE-286] in FortiWeb version 7.6.2 and below, version 7.4.6 and below, version 7.2.10 and below, version 7.0.11 and below widgets dashboard may allow an authenticated attacker with at least read-only admin permission | 0,4% | — |
| CVE-2024-39884 | MED 6.2 | apache http_server A regression in the core of Apache HTTP Server 2.4.60 ignores some use of the legacy content-type based configuration of handlers. "AddType" and similar configuration, under some circumstances where files are requested indirectly, result in source code discl | 0,9% | — |
| CVE-2024-39490 | MED 6.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: fix missing sk_buff release in seg6_input_core The seg6_input() function is responsible for adding the SRH into a packet, delegating the operation to the seg6_input_core(). This fu | 0,2% | — |
| CVE-2024-38203 | MED 6.2 | microsoft windows_10_1507 Windows Package Library Manager Information Disclosure Vulnerability | 0,7% | — |
| CVE-2024-36888 | MED 6.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: workqueue: Fix selection of wake_cpu in kick_pool() With cpu_possible_mask=0-63 and cpu_online_mask=0-7 the following kernel oops was observed: smp: Bringing up secondary CPUs ... smp: Brou | 0,2% | — |
| CVE-2024-29064 | MED 6.2 | microsoft windows_10_1507 Windows Hyper-V Denial of Service Vulnerability | 0,7% | — |
| CVE-2024-28917 | MED 6.2 | microsoft azure_arc_extension_microsoft.azstackhci.operator Azure Arc-enabled Kubernetes Extension Cluster-Scope Elevation of Privilege Vulnerability | 0,9% | — |
| CVE-2024-24966 | MED 6.2 | f5 f5os-a When LDAP remote authentication is configured on F5OS, a remote user without an assigned role will be incorrectly authorized. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0,2% | — |
| CVE-2024-23454 | MED 6.2 | apache hadoop Apache Hadoop’s RunJar.run() does not set permissions for temporary directory by default. If sensitive data will be present in this file, all the other local users may be able to view the content. This is because, on unix-like systems, the system temporary dir | 0,4% | — |
| CVE-2024-20301 | MED 6.2 | cisco duo_authentication_for_windows_logon_and_rdp A vulnerability in Cisco Duo Authentication for Windows Logon and RDP could allow an authenticated, physical attacker to bypass secondary authentication and access an affected Windows device. This vulnerability is due to a failure to invalidate locally cre | 0,3% | — |
| CVE-2023-6915 | MED 6.2 | linux linux_kernel A Null pointer dereference problem was found in ida_free in lib/idr.c in the Linux Kernel. This issue may allow an attacker using this library to cause a denial of service problem due to a missing check at a function return. | 0,3% | — |