57.020 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.020 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più alto |
|---|---|---|---|---|
| CVE-2026-47305 | HIGH 7.8 | microsoft visual_studio_2022 Protection mechanism failure in Visual Studio allows an unauthorized attacker to execute code locally. | 0,5% | — |
| CVE-2026-47304 | HIGH 8.1 | microsoft .net Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network. | 0,2% | — |
| CVE-2026-47303 | HIGH 8.8 | microsoft .net Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network. | 0,7% | — |
| CVE-2026-47302 | HIGH 7.5 | microsoft .net Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. | 1,0% | — |
| CVE-2026-47301 | HIGH 8.8 | microsoft configuration_manager_2503 Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network. | 1,0% | — |
| CVE-2026-47300 | HIGH 8.8 | microsoft .net Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network. | 0,5% | — |
| CVE-2026-47299 | HIGH 7.2 | microsoft azure_monitor_agent Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate privileges over a network. | 0,9% | — |
| CVE-2026-47298 | HIGH 8.0 | microsoft sharepoint_server Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 0,7% | — |
| CVE-2026-47296 | HIGH 7.5 | microsoft sql_server_2016 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | 0,5% | — |
| CVE-2026-47295 | HIGH 8.8 | microsoft sql_server_2016 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | 1,0% | — |
| CVE-2026-47294 | HIGH 8.0 | microsoft sharepoint_server Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 0,7% | — |
| CVE-2026-47293 | HIGH 7.0 | microsoft 365_apps Use after free in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-47292 | HIGH 7.8 | microsoft visual_studio_code Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2026-47291 | CRIT 9.8 | microsoft windows_10_1607 Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network. | 22,8% | — |
| CVE-2026-47290 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 0,5% | — |
| CVE-2026-47289 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 1,0% | — |
| CVE-2026-47288 | HIGH 7.1 | microsoft windows_server_2012 Integer overflow or wraparound in Windows Kerberos allows an authorized attacker to execute code over an adjacent network. | 0,5% | — |
| CVE-2026-47287 | MED 6.5 | microsoft visual_studio_code Relative path traversal in Visual Studio Code allows an unauthorized attacker to perform tampering over a network. | 0,8% | — |
| CVE-2026-47285 | MED 6.5 | microsoft visual_studio_code Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to disclose information over a network. | 0,9% | — |
| CVE-2026-47284 | MED 6.5 | microsoft visual_studio_code Exposure of sensitive information to an unauthorized actor in Visual Studio Code allows an unauthorized attacker to disclose information over a network. | 0,9% | — |
| CVE-2026-47282 | MED 6.5 | microsoft visual_studio_code Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network. | 0,9% | — |
| CVE-2026-47281 | CRIT 9.6 | microsoft visual_studio_code Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. | 0,8% | — |
| CVE-2026-47280 | CRIT 10.0 | microsoft azure_resource_manager Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a network. | 0,5% | — |
| CVE-2026-47065 | CRIT 9.8 | apache mina ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy Assessment: Fully addressed. When the serialised stream contains a TC_PROXYCLASSDESC (the marker for a java.lang.reflect.Proxy ), JDK’s ObjectInputStrea | 0,5% | — |
| CVE-2026-4680 | HIGH 8.8 | google chrome Use after free in FedCM in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | 0,4% | — |