EN
56.960 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia

CVE Tracker

56.960 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordinato dal più alto
CVE-2026-47888 HIGH 7.5 A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framewor 0,3%
CVE-2026-47885 HIGH 7.5 The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSize limit when maxInMemorySize is set to -1. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 0,3%
CVE-2026-47883 MED 6.1 UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns. The issue applies to the filter variants in both Spring MVC and Spring WebFlux. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 0,2%
CVE-2026-47877 HIGH 8.2 vmware spring_security Spring Security Authorization Server's default consent page renders user-controlled values without HTML entity encoding. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 0,2%
CVE-2026-47864 MED 6.4 vmware spring_integration SerializingHttpMessageConverter deserializes the body of incoming HTTP requests with a raw java.io.ObjectInputStream and no class filtering. Any request with Content-Type application/x-java-serialized-object whose body resolves to a Serializable type is read d 3,4%
CVE-2026-47862 MED 5.4 vmware spring_integration An attacker who can set the file_name header on a message reaching a ZipTransformer with ZipResultType.FILE (the default) can cause the resulting .zip archive to be written to an arbitrary filesystem path outside the configured workDirectory. Spring Integratio 0,2%
CVE-2026-47861 MED 6.3 vmware spring_integration An unauthenticated remote attacker who can send a single UDP packet to a Spring Integration UDP inbound adapter can cause the server to emit an outbound UDP datagram to an arbitrary internal or external host and port of the attacker's choosing. Spring Integrat 0,3%
CVE-2026-47860 MED 6.5 vmware spring_advanced_message_queuing_protocol An attacker who can publish to a queue consumed by an application that has enabled message decompression can crash the consumer JVM with a single ~1 MB message. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earli 0,2%
CVE-2026-47852 HIGH 7.5 A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model file. Spring AI 2.0.0 Spring AI 1.1.0 - 1.1.8 Spring AI 1.0.0 - 1.0.9 0,2%
CVE-2026-47851 HIGH 7.5 Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError in the ingestion thread. Spring AI 2.0.0 Spring AI 1.1.0 - 1.1.8 Spring AI 1.0.0 - 1.0.9 0,3%
CVE-2026-47849 HIGH 7.1 vmware spring_data_rest Spring Data REST does not guard identifier (@Id) and version (@Version) properties against mutation via RFC 6902 JSON Patch (application/json-patch+json) requests. Spring Data REST 5.1.0 Spring Data REST 5.0.0 - 5.0.6 Spring Data REST 4.5.0 - 4.5.12 Spring Dat 0,3%
CVE-2026-47842 MED 6.5 Applications using AesBytesEncryptor with the two-argument constructor or when passing a null IV generator and CBC as the encryption mode encrypt data with AES/CBC using a null (all-zero) initialization vector. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0 0,1%
CVE-2026-47841 HIGH 7.4 An application using Spring Security's WebAuthn support may be vulnerable to user verification bypass when using a distributed HTTP session store. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 Spring Security 6.5.0 - 6.5.11 Spring Security 6.4.0 - 6.4.18 0,3%
CVE-2026-47838 MED 6.8 vmware spring_security SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certificate, this can lead to an attacker impersonating another user. A 0,1%
CVE-2026-47835 HIGH 8.6 vmware spring_ai In Spring AI Vector Stores, special characters could be used to force the execution of arbitrary queries in Elasticsearch, OpenSearch, and GemFire VectorDB. Affected components: spring-ai-elasticsearch-store, spring-ai-opensearch-store, spring-ai-gemfire-store 0,3%
CVE-2026-47834 MED 4.8 Spring Data JPA's Sort validation can be bypassed when parameters containing crafted payload are accepted from untrusted sources. Spring Data JPA 4.1.0 Spring Data JPA 4.0.0 - 4.0.6 Spring Data JPA 3.5.0 - 3.5.13 Spring Data JPA 3.0.0 - 3.4.15 0,2%
CVE-2026-47827 HIGH 7.5 Command Injection in BOSH CLI tool on windows in Cloud Foundry allows a remote attacker to execute arbitrary shell commands via command injection vulnerabilities 1,2%
CVE-2026-47656 HIGH 7.9 microsoft windows_10_1607 Protection mechanism failure in Windows Boot Manager allows an authorized attacker to bypass a security feature locally. 0,3%
CVE-2026-47655 MED 6.5 microsoft graph Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network. 0,8%
CVE-2026-47654 HIGH 7.5 microsoft windows_server_2016 Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. 0,5%
CVE-2026-47653 HIGH 8.8 microsoft windows_10_1607 Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. 0,6%
CVE-2026-47652 HIGH 8.2 microsoft windows_11_23h2 Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally. 0,3%
CVE-2026-47648 HIGH 7.0 microsoft windows_10_1607 Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally. 0,2%
CVE-2026-47647 CRIT 9.9 microsoft dynamics_365 Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network. 0,8%
CVE-2026-47646 CRIT 9.3 microsoft dynamics_365_customer_voice Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allows an unauthorized attacker to perform spoofing over a network. 0,5%