56.959 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.959 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più alto |
|---|---|---|---|---|
| CVE-2026-49871 | CRIT 9.3 | apache apisix Cross-Site Request Forgery (CSRF) vulnerability in the cas-auth plugin under default configurations. This defect allows a remote attacker that manages to send a victim to a webpage controlled by them can cause the victim's browser to become authenticated as a | 0,4% | — |
| CVE-2026-49845 | CRIT 9.8 | apache hive SQL injection in Hive Metastore direct SQL partition-name resolution in Apache Hive before 4.2.1 on all platforms allows authenticated users with access to Hive Metastore APIs to read, modify, or affect unintended partition metadata (including statistics updat | 0,3% | — |
| CVE-2026-49844 | MED 5.9 | apache log4j Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. This issue affects Apache Log4j API versions 2.13.1 through 2.25.4 and version 2.26.0. The fix for CVE-2026- | 0,8% | — |
| CVE-2026-49818 | MED 6.5 | apache apache-airflow-providers-samba The Apache Airflow Samba provider's `GCSToSambaOperator` joined GCS object names to the SMB destination path without a containment check, so an object named with `../` segments resolved a write path outside the configured `destination_path`. An attacker able t | 0,6% | — |
| CVE-2026-49808 | HIGH 7.8 | microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-49807 | MED 6.2 | microsoft windows_10_1809 Exposure of sensitive information to an unauthorized actor in Windows DirectX allows an unauthorized attacker to disclose information locally. | 0,5% | — |
| CVE-2026-49806 | HIGH 7.0 | microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-49805 | HIGH 7.0 | microsoft windows_10_1607 Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-49804 | MED 6.6 | microsoft windows_10_1607 Heap-based buffer overflow in Windows USB Video Driver allows an unauthorized attacker to elevate privileges with a physical attack. | 0,5% | — |
| CVE-2026-49803 | HIGH 7.0 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows AppX Deployment Service allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-49802 | HIGH 7.0 | microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-49801 | MED 5.5 | microsoft windows_10_1607 Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-49800 | HIGH 7.8 | microsoft windows_10_1809 Integer overflow or wraparound in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-49799 | MED 6.5 | microsoft windows_10_1607 Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network. | 1,1% | — |
| CVE-2026-49798 | CRIT 9.3 | microsoft windows_10_1607 Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2026-49797 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. | 0,5% | — |
| CVE-2026-49796 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally. | 0,5% | — |
| CVE-2026-49795 | HIGH 8.8 | microsoft windows_10_1809 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-49794 | MED 4.6 | microsoft windows_10_1607 Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack. | 0,5% | — |
| CVE-2026-49793 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally. | 0,3% | — |
| CVE-2026-49792 | HIGH 7.8 | microsoft windows_10_1607 Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally. | 0,3% | — |
| CVE-2026-49791 | HIGH 7.1 | microsoft windows_10_1607 Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2026-49790 | HIGH 7.3 | microsoft windows_10_1607 Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | 0,4% | — |
| CVE-2026-49789 | HIGH 7.3 | microsoft windows_10_1607 Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2026-49788 | HIGH 7.5 | microsoft windows_10_1607 Allocation of resources without limits or throttling in HTTP/2 allows an unauthorized attacker to deny service over a network. | 1,2% | — |