EN
57.023 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia

CVE Tracker

57.023 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordinato dal più basso
CVE-2026-48827 HIGH 7.1 apache mina_sshd Path traversal vulnerability in Apache MINA SSHD bundle sshd-git. Lack of path validation in git-upload-pack, git-receive-pack, and other git operations allows users authenticated over SSH access to git repositories outside the configured git server root direc 0,5%
CVE-2026-48726 MED 6.5 apache airflow A bug in Apache Airflow's auth manager logout handling left previously-issued JWT tokens valid after the user clicked logout in the UI: the logout flow for `FabAuthManager` and `KeycloakAuthManager` did not actually reach the underlying `revoke_token()` call, 0,4%
CVE-2026-48589 MED 5.4 apache shiro Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login. In affected versions, insufficient validation of this client-controlled value could allow an attacker to influence the redirect target in appli 0,4%
CVE-2026-48586 HIGH 7.5 apache thrift Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the is 0,6%
CVE-2026-48584 CRIT 9.9 microsoft azure_synapse Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate privileges over a network. 0,9%
CVE-2026-48583 HIGH 7.8 microsoft windows_10_1607 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-48582 CRIT 9.6 microsoft exchange_online Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. 0,7%
CVE-2026-48581 HIGH 7.8 microsoft surface_go_2_1901_firmware Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-48580 MED 5.5 microsoft 365_apps Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 0,5%
CVE-2026-48579 CRIT 9.1 microsoft exchange_online Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to disclose information over a network. 1,0%
CVE-2026-48578 HIGH 7.9 microsoft windows_10_1607 Improper access control in Windows Secure Boot allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-48576 HIGH 7.9 microsoft windows_10_1607 No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. 1,0%
CVE-2026-48575 HIGH 7.9 microsoft windows_10_1607 Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. 0,3%
CVE-2026-48574 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally. 0,4%
CVE-2026-48573 HIGH 7.9 microsoft windows_10_1607 No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. 1,0%
CVE-2026-48572 HIGH 7.0 microsoft windows_11_23h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer allows an authorized attacker to elevate privileges locally. 0,2%
CVE-2026-48571 HIGH 7.0 microsoft windows_11_23h2 Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-48570 HIGH 7.9 microsoft windows_10_1607 Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. 0,3%
CVE-2026-48569 HIGH 7.1 microsoft visual_studio_code Improper input validation in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. 0,4%
CVE-2026-48568 HIGH 7.9 microsoft windows_10_1607 Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. 0,3%
CVE-2026-48567 CRIT 10.0 microsoft azure_horizondb Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network. 1,0%
CVE-2026-48566 MED 5.5 microsoft windows_11_24h2 Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. 0,4%
CVE-2026-48565 HIGH 7.8 microsoft windows_narrator_braille Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally. 0,4%
CVE-2026-48564 HIGH 8.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network. 0,9%
CVE-2026-48563 HIGH 7.5 microsoft windows_10_1809 Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. 0,5%