EN
57.056 CVE seguite
777 Sfruttate ora
184 Usate dai ransomware
Ultima sincronia

CVE Tracker

57.056 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordinato dal più alto
CVE-2026-45836 MED 5.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_get_sndtimeo_cb() Add the same NULL guard already present in l2cap_sock_resume_cb() and l2cap_sock_ready_cb(). 0,1%
CVE-2026-45835 MED 5.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() Add the same NULL guard already present in l2cap_sock_resume_cb() and l2cap_sock_ready_cb(). 0,1%
CVE-2026-45834 MED 5.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() Add the same NULL guard already present in l2cap_sock_resume_cb() and l2cap_sock_ready_cb(). 0,1%
CVE-2026-45816 HIGH 7.5 apache nimble NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event. This requires disabled asserts (otherwise assert would trigger before NULL dereference) and bogus (or misbehaving) controller, thus severity is low. This issue affects 0,6%
CVE-2026-45815 HIGH 7.5 apache nimble Reachable Assertion vulnerability in Apache NimBLE. A specially crafted ATT Read Multiple Variable Response (BLE_ATT_OP_READ_MULT_VAR_RSP) may trigger assert in ATT parser. Severity is medium as this requires DUT to first send ATT Read Multiple Variable Reque 0,6%
CVE-2026-45813 HIGH 8.8 apache nimble Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apache NimBLE BASS service. Improper validation when parsing BASS service  "Add Source" and "Modify Source" operation PDU could results in stack buffer overflow or arbitrary out-of-bo 0,4%
CVE-2026-45812 MED 6.5 apache nimble Incorrect Calculation of Buffer Size vulnerability in Apache NimBLE when processing Legacy Advertising Report HCI event. When a single HCI advertising report event bundles multiple reports, NimBLE miscalculated the offset to the next report. This can cause th 0,4%
CVE-2026-45811 HIGH 7.5 apache nimble Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. The HCI socket transport did not check whether a received HCI event would fit the configured event pool before copying it, allowing a buffer overflow. Severi 0,3%
CVE-2026-45658 HIGH 7.8 microsoft windows_10_1607 Improper access control in Windows BitLocker allows an authorized attacker to bypass a security feature locally. 0,4%
CVE-2026-45657 CRIT 9.8 microsoft windows_11_23h2 Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network. 15,5%
CVE-2026-45656 HIGH 7.8 microsoft windows_10_1607 Protection mechanism failure in Windows UEFI allows an authorized attacker to bypass a security feature locally. 0,3%
CVE-2026-45655 MED 5.3 microsoft windows_10_1607 Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. 0,4%
CVE-2026-45654 HIGH 7.9 microsoft windows_11_24h2 Improper access control in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. 0,3%
CVE-2026-45653 HIGH 7.0 microsoft windows_10_1607 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-45650 MED 4.3 microsoft bing User interface (ui) misrepresentation of critical information in Microsoft Bing allows an unauthorized attacker to perform spoofing over a network. 0,6%
CVE-2026-45649 HIGH 7.1 microsoft excel Improper access control in Office for Android allows an unauthorized attacker to perform spoofing locally. 0,4%
CVE-2026-45648 HIGH 8.8 microsoft windows_server_2022 Stack-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network. 1,1%
CVE-2026-45647 MED 5.5 microsoft defender_for_endpoint Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally. 0,2%
CVE-2026-45646 HIGH 7.5 microsoft asp.net_core_odata Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. 1,2%
CVE-2026-45645 HIGH 7.8 microsoft 365_apps Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally. 0,4%
CVE-2026-45644 HIGH 8.0 microsoft live_share_canvas Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Live Share Canvas SDK allows an authorized attacker to elevate privileges over a network. 0,6%
CVE-2026-45643 HIGH 7.8 microsoft 365_apps Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0,4%
CVE-2026-45642 LOW 3.9 microsoft windows_10_1607 Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authorized attacker to perform spoofing with a physical attack. 0,3%
CVE-2026-45641 HIGH 8.4 microsoft windows_10_21h2 Access of resource using incompatible type ('type confusion') in Windows Hyper-V allows an unauthorized attacker to execute code locally. 0,3%
CVE-2026-45640 HIGH 7.0 microsoft windows_10_21h2 Use after free in Windows Bluetooth Port Driver allows an authorized attacker to elevate privileges locally. 0,2%