EN
57.056 CVE seguite
777 Sfruttate ora
184 Usate dai ransomware
Ultima sincronia

CVE Tracker

57.056 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordinato dal più alto
CVE-2026-45586 HIGH 7.8 microsoft windows_10_1607 Improper link resolution before file access ('link following') in Windows Collaborative Translation Framework allows an authorized attacker to elevate privileges locally. 3,6%
CVE-2026-45585 MED 6.8 microsoft windows_11_24h2 Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this vulnerability has been made public violating coordinated vulnerability best practices. We are issuing this CVE 1,4%
CVE-2026-45584 HIGH 8.1 microsoft malware_protection_engine Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network. 0,9%
CVE-2026-45583 HIGH 7.5 microsoft exchange_server Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network. 0,5%
CVE-2026-45505 HIGH 8.8 apache activemq Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Non-parenthesized discovery wrappers such as `masterslave:vm://...,...` and `static:vm://...` 0,6%
CVE-2026-45504 HIGH 8.8 microsoft exchange_server Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. 0,8%
CVE-2026-45503 HIGH 8.1 microsoft exchange_server Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network. 0,4%
CVE-2026-45502 MED 5.0 microsoft exchange_server Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network. 20,3%
CVE-2026-45501 MED 6.5 microsoft exchange_server Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network. 0,3%
CVE-2026-45500 MED 6.1 microsoft exchange_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. 0,4%
CVE-2026-45499 CRIT 9.9 microsoft azure_openai Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network. 0,8%
CVE-2026-45497 HIGH 7.7 microsoft copilot Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an authorized attacker to execute code over a network. 0,5%
CVE-2026-45496 MED 5.5 microsoft visual_studio_code Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. 0,5%
CVE-2026-45495 HIGH 8.8 microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability 1,0%
CVE-2026-45494 MED 5.4 microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability 0,3%
CVE-2026-45492 MED 5.4 microsoft edge_chromium Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network. 0,3%
CVE-2026-45491 MED 6.2 microsoft .net Improper link resolution before file access ('link following') in .NET allows an unauthorized attacker to perform tampering locally. 0,4%
CVE-2026-45490 HIGH 7.8 microsoft .net Improper authorization in .NET allows an authorized attacker to elevate privileges locally. 0,4%
CVE-2026-45489 MED 6.5 microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability 0,9%
CVE-2026-45488 MED 5.4 microsoft edge_chromium User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. 0,4%
CVE-2026-45487 HIGH 7.8 microsoft windows_10_21h2 Time-of-check time-of-use (TOCTOU) race condition in Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally. 0,2%
CVE-2026-45486 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0,4%
CVE-2026-45485 LOW 3.3 microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. 0,4%
CVE-2026-45484 HIGH 8.8 microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. 35,2%
CVE-2026-45483 MED 4.6 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Project Server allows an authorized attacker to perform spoofing over a network. 0,5%