56.855 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.855 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più alto |
|---|---|---|---|---|
| CVE-2026-50673 | HIGH 7.8 | microsoft windows_10_1607 Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-50672 | HIGH 7.0 | microsoft windows_10_1809 Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-50670 | HIGH 8.8 | microsoft windows_10_1809 Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-50669 | HIGH 7.0 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-50668 | MED 6.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to elevate privileges with a physical attack. | 0,4% | — |
| CVE-2026-50667 | HIGH 7.8 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows NTFS allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-50666 | HIGH 8.8 | microsoft windows_10_1607 Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges over a network. | 0,9% | — |
| CVE-2026-50665 | HIGH 7.8 | microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | 0,5% | — |
| CVE-2026-50663 | HIGH 8.8 | microsoft age_of_empires_ii Relative path traversal in Age of Empires II: Definitive Edition Game allows an unauthorized attacker to execute code over a network. | 0,9% | — |
| CVE-2026-50661 | MED 6.1 | microsoft windows_10_1607 Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. | 0,5% | — |
| CVE-2026-50659 | MED 6.5 | microsoft .net Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network. | 0,5% | — |
| CVE-2026-50658 | HIGH 7.0 | microsoft defender_for_endpoint Time-of-check time-of-use (toctou) race condition in Microsoft Defender allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-50657 | MED 4.7 | microsoft defender_for_endpoint Exposure of private personal information to an unauthorized actor in Microsoft Defender allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-50656 | HIGH 7.8 | microsoft malware_protection_engine Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ". | 11,4% | — |
| CVE-2026-50655 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally. | 0,5% | — |
| CVE-2026-50653 | HIGH 7.5 | microsoft .net_framework Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network. | 1,2% | — |
| CVE-2026-50652 | HIGH 7.5 | microsoft .net_framework Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network. | 1,7% | — |
| CVE-2026-50651 | HIGH 7.5 | microsoft .net Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. | 0,8% | — |
| CVE-2026-50650 | HIGH 7.8 | microsoft .net Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-50649 | HIGH 7.8 | microsoft .net Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally. | 0,9% | — |
| CVE-2026-50648 | HIGH 7.5 | microsoft .net Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network. | 0,8% | — |
| CVE-2026-50647 | HIGH 7.5 | microsoft .net_framework Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network. | 1,2% | — |
| CVE-2026-50646 | HIGH 7.8 | microsoft .net Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally. | 1,0% | — |
| CVE-2026-50645 | HIGH 7.5 | apache cxf There is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache CXF, which can lead to uncontrolled resource consumption or a denial of service attack. Users are recommended to upgrade to versions 4.2.2 | 0,5% | — |
| CVE-2026-50634 | MED 6.5 | apache cxf A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to process metadata that was not authenticated by the accepted signature. This can bypass the application's assumption that accepted `Content-Type` or protected HTTP-h | 0,3% | — |