EN
58.441 CVE seguite
792 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.441 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordinato dal più basso Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2025-55334 MED 6.2 microsoft windows_11_22h2 Cleartext storage of sensitive information in Windows Kernel allows an unauthorized attacker to bypass a security feature locally. 0,4% —
CVE-2025-47980 MED 6.2 microsoft windows_10_1507 Exposure of sensitive information to an unauthorized actor in Windows Imaging Component allows an unauthorized attacker to disclose information locally. 0,6% —
CVE-2025-3908 MED 6.2 openvpn openvpn3linux The configuration initialization tool in OpenVPN 3 Linux v20 through v24 on Linux allows a local attacker to use symlinks pointing at an arbitrary directory which will change the ownership and permissions of that destination directory. 0,2% —
CVE-2025-36083 MED 6.2 ibm concert IBM Concert Software 1.0.0 through 2.0.0 could allow a local user to obtain sensitive information from buffers due to improper clearing of heap memory before release. 0,1% —
CVE-2025-36051 MED 6.2 ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 stores potentially sensitive information in configuration files that could be read by a local user. 0,1% —
CVE-2025-36050 MED 6.2 ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 stores potentially sensitive information in log files that could be read by a local user. 0,2% —
CVE-2025-29957 MED 6.2 microsoft windows_10_1507 Uncontrolled resource consumption in Windows Deployment Services allows an unauthorized attacker to deny service locally. 0,6% —
CVE-2025-29955 MED 6.2 microsoft windows_11_24h2 Improper input validation in Windows Hyper-V allows an unauthorized attacker to deny service locally. 0,6% —
CVE-2025-29819 MED 6.2 microsoft windows_admin_center External control of file name or path in Azure Portal Windows Admin Center allows an unauthorized attacker to disclose information locally. 1,1% —
CVE-2025-21278 MED 6.2 microsoft windows_10_1507 Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability 0,6% —
CVE-2024-52898 MED 6.2 ibm mq IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a local user to obtain sensitive information when a detailed technical error message is returned. 0,2% —
CVE-2024-52897 MED 6.2 ibm mq IBM MQ 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned. 0,2% —
CVE-2024-52896 MED 6.2 ibm mq IBM MQ 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned. 0,3% —
CVE-2024-50251 MED 6.2 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_payload: sanitize offset and length before calling skb_checksum() If access to offset + length is larger than the skbuff length, then skb_checksum() triggers BUG_ON(). skb_ch 0,5% —
CVE-2024-46671 MED 6.2 fortinet fortiweb An Incorrect User Management vulnerability [CWE-286] in FortiWeb version 7.6.2 and below, version 7.4.6 and below, version 7.2.10 and below, version 7.0.11 and below widgets dashboard may allow an authenticated attacker with at least read-only admin permission 0,4% —
CVE-2024-39884 MED 6.2 apache http_server A regression in the core of Apache HTTP Server 2.4.60 ignores some use of the legacy content-type based configuration of handlers.   "AddType" and similar configuration, under some circumstances where files are requested indirectly, result in source code discl 0,9% —
CVE-2024-39490 MED 6.2 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: fix missing sk_buff release in seg6_input_core The seg6_input() function is responsible for adding the SRH into a packet, delegating the operation to the seg6_input_core(). This fu 0,2% —
CVE-2024-38203 MED 6.2 microsoft windows_10_1507 Windows Package Library Manager Information Disclosure Vulnerability 0,7% —
CVE-2024-36888 MED 6.2 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: workqueue: Fix selection of wake_cpu in kick_pool() With cpu_possible_mask=0-63 and cpu_online_mask=0-7 the following kernel oops was observed: smp: Bringing up secondary CPUs ... smp: Brou 0,2% —
CVE-2024-29064 MED 6.2 microsoft windows_10_1507 Windows Hyper-V Denial of Service Vulnerability 0,7% —
CVE-2024-28917 MED 6.2 microsoft azure_arc_extension_microsoft.azstackhci.operator Azure Arc-enabled Kubernetes Extension Cluster-Scope Elevation of Privilege Vulnerability 0,9% —
CVE-2024-24966 MED 6.2 f5 f5os-a When LDAP remote authentication is configured on F5OS, a remote user without an assigned role will be incorrectly authorized.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. 0,2% —
CVE-2024-23454 MED 6.2 apache hadoop Apache Hadoop’s RunJar.run() does not set permissions for temporary directory by default. If sensitive data will be present in this file, all the other local users may be able to view the content. This is because, on unix-like systems, the system temporary dir 0,4% —
CVE-2024-20301 MED 6.2 cisco duo_authentication_for_windows_logon_and_rdp A vulnerability in Cisco Duo Authentication for Windows Logon and RDP could allow an authenticated, physical attacker to bypass secondary authentication and access an affected Windows device. This vulnerability is due to a failure to invalidate locally cre 0,3% —
CVE-2023-6915 MED 6.2 linux linux_kernel A Null pointer dereference problem was found in ida_free in lib/idr.c in the Linux Kernel. This issue may allow an attacker using this library to cause a denial of service problem due to a missing check at a function return. 0,3% —