56.959 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.959 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più alto |
|---|---|---|---|---|
| CVE-2026-50304 | HIGH 7.5 | microsoft windows_10_1607 Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network. | 1,2% | — |
| CVE-2026-50303 | MED 5.5 | microsoft windows_10_1809 Use of a cryptographic primitive with a risky implementation in Windows Key Guard allows an authorized attacker to bypass a security feature locally. | 0,3% | — |
| CVE-2026-50302 | MED 4.2 | microsoft windows_10_21h2 Improper certificate validation in Windows Cryptographic Services allows an unauthorized attacker to bypass a security feature over a network. | 0,3% | — |
| CVE-2026-50301 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | 0,5% | — |
| CVE-2026-50300 | MED 5.5 | microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-50299 | MED 6.8 | microsoft windows_10_1607 Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to execute code with a physical attack. | 0,4% | — |
| CVE-2026-50298 | MED 6.8 | microsoft windows_10_1607 Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a physical attack. | 0,4% | — |
| CVE-2026-50297 | HIGH 7.0 | microsoft windows_10_1607 Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-50296 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Graphics Kernel allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-50295 | MED 5.5 | microsoft windows_11_24h2 Improper privilege management in Microsoft Windows DNS allows an authorized attacker to bypass a security feature locally. | 0,3% | — |
| CVE-2026-50294 | MED 6.2 | microsoft windows_10_1607 Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an unauthorized attacker to disclose information locally. | 0,5% | — |
| CVE-2026-50293 | HIGH 7.8 | microsoft windows_10_21h2 Use after free in Windows Internal Task Bar allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-50229 | MED 6.1 | apache tomcat Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example for Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through | 4,1% | — |
| CVE-2026-50223 | HIGH 8.8 | apache ofbiz Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low-privileged authenticated user with Content/DataResource editing privileges to perform template injection attacks that could lead to Remote Code Execution. Thi | 0,7% | — |
| CVE-2026-50222 | HIGH 7.5 | apache cloudstack Missing Authorization, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's Userdata reference APIs. Several userdata-related APIs in Apache CloudStack, including deleteUserData, linkUserDataToTemplate, resetUserData | 0,2% | — |
| CVE-2026-50203 | CRIT 9.1 | apache apache-airflow-providers-sftp A path traversal in the SFTP provider (`SFTPHook.retrieve_directory` / `SFTPOperator(operation=get)`) let a malicious or compromised remote SFTP server write files outside the configured local destination directory via crafted directory-entry names. No Airflow | 0,6% | — |
| CVE-2026-50112 | HIGH 8.8 | apache cloudstack SSRF via Metalink Mirror URL Resolution: An authenticated tenant can register a template pointing to an attacker-controlled metalink file containing internal targets. The Secondary Storage VM will retrieve the data and persist it as a template file, which can | 0,4% | — |
| CVE-2026-50107 | HIGH 8.1 | f5 nginx_gateway_fabric When NGINX Plus or NGINX Open Source is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the NginxProxy Custom Reso | 0,5% | — |
| CVE-2026-50076 | CRIT 9.1 | apache fory Deserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-core Java SDK before 1.1.0 on Java/JVM platforms allows a remote attacker to bypass class registration, TypeChecker, and DisallowedList checks and invoke classpath-present r | 0,5% | — |
| CVE-2026-49975 | HIGH 7.5 | apache http_server Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67. | 31,0% | — |
| CVE-2026-49938 | MED 6.5 | fortinet fortiportal A improper access control vulnerability in Fortinet FortiPortal 7.4.0 through 7.4.7, FortiPortal 7.2.0 through 7.2.8, FortiPortal 7.0 all versions may allow attacker to improper access control via <insert attack vector here> | 0,2% | — |
| CVE-2026-49877 | HIGH 8.1 | apache activemq Improper Authorization vulnerability in Apache ActiveMQ. An authenticated low-privilege Web Console user by default can access /admin/* paths in the Web Console. The default Jetty settings incorrectly did not limit those paths to only admins. This issue affec | 0,5% | — |
| CVE-2026-49876 | MED 6.5 | apache gravitino Authenticated SSRF in Gravitino JobManager allows server-side HTTP requests to internal network and cloud metadata endpoints via unvalidated job template URIs. A vulnerability in Apache Gravitino. This issue affects Apache Gravitino: from 1.0.0 through 1.2.1. | 0,5% | — |
| CVE-2026-49875 | CRIT 9.8 | apache cxf Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to upgrade to versions 4.2.2 o | 0,5% | — |
| CVE-2026-49872 | HIGH 8.1 | apache apisix Improper Authentication vulnerability in Apache APISIX. When the cas-auth plugin is used in a route, an attacker can possibly authenticate itself with credentials from a different source. This issue affects Apache APISIX: from 3.0.0 through 3.16.0. Users are | 0,5% | — |