57.023 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.023 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2026-48827 | HIGH 7.1 | apache mina_sshd Path traversal vulnerability in Apache MINA SSHD bundle sshd-git. Lack of path validation in git-upload-pack, git-receive-pack, and other git operations allows users authenticated over SSH access to git repositories outside the configured git server root direc | 0,5% | — |
| CVE-2026-48726 | MED 6.5 | apache airflow A bug in Apache Airflow's auth manager logout handling left previously-issued JWT tokens valid after the user clicked logout in the UI: the logout flow for `FabAuthManager` and `KeycloakAuthManager` did not actually reach the underlying `revoke_token()` call, | 0,4% | — |
| CVE-2026-48589 | MED 5.4 | apache shiro Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login. In affected versions, insufficient validation of this client-controlled value could allow an attacker to influence the redirect target in appli | 0,4% | — |
| CVE-2026-48586 | HIGH 7.5 | apache thrift Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the is | 0,6% | — |
| CVE-2026-48584 | CRIT 9.9 | microsoft azure_synapse Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate privileges over a network. | 0,9% | — |
| CVE-2026-48583 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-48582 | CRIT 9.6 | microsoft exchange_online Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. | 0,7% | — |
| CVE-2026-48581 | HIGH 7.8 | microsoft surface_go_2_1901_firmware Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-48580 | MED 5.5 | microsoft 365_apps Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | 0,5% | — |
| CVE-2026-48579 | CRIT 9.1 | microsoft exchange_online Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2026-48578 | HIGH 7.9 | microsoft windows_10_1607 Improper access control in Windows Secure Boot allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-48576 | HIGH 7.9 | microsoft windows_10_1607 No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | 1,0% | — |
| CVE-2026-48575 | HIGH 7.9 | microsoft windows_10_1607 Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | 0,3% | — |
| CVE-2026-48574 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2026-48573 | HIGH 7.9 | microsoft windows_10_1607 No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | 1,0% | — |
| CVE-2026-48572 | HIGH 7.0 | microsoft windows_11_23h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-48571 | HIGH 7.0 | microsoft windows_11_23h2 Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-48570 | HIGH 7.9 | microsoft windows_10_1607 Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | 0,3% | — |
| CVE-2026-48569 | HIGH 7.1 | microsoft visual_studio_code Improper input validation in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | 0,4% | — |
| CVE-2026-48568 | HIGH 7.9 | microsoft windows_10_1607 Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | 0,3% | — |
| CVE-2026-48567 | CRIT 10.0 | microsoft azure_horizondb Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network. | 1,0% | — |
| CVE-2026-48566 | MED 5.5 | microsoft windows_11_24h2 Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2026-48565 | HIGH 7.8 | microsoft windows_narrator_braille Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2026-48564 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network. | 0,9% | — |
| CVE-2026-48563 | HIGH 7.5 | microsoft windows_10_1809 Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 0,5% | — |