EN
57.056 CVE seguite
777 Sfruttate ora
184 Usate dai ransomware
Ultima sincronia

CVE Tracker

57.056 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordinato dal più alto
CVE-2026-42834 HIGH 7.8 microsoft windows_admin_center Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network. 0,4%
CVE-2026-42833 CRIT 9.1 microsoft dynamics_365 Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network. 0,7%
CVE-2026-42832 HIGH 7.7 microsoft excel Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally. 0,2%
CVE-2026-42831 HIGH 7.8 microsoft 365_copilot Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. 0,4%
CVE-2026-42830 MED 6.5 microsoft azure_monitor_agent Untrusted search path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. 0,5%
CVE-2026-42829 HIGH 7.8 microsoft windows_11_24h2 Improper access control in Windows Administrator Protection allows an authorized attacker to bypass a security feature locally. 0,3%
CVE-2026-42828 HIGH 7.8 microsoft windows_10_1809 Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-42827 MED 6.5 microsoft 365_copilot Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network. 0,5%
CVE-2026-42826 CRIT 10.0 microsoft azure_devops Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a network. 0,8%
CVE-2026-42825 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. 0,2%
CVE-2026-42824 MED 6.5 microsoft copilot Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network. 7,6%
CVE-2026-42823 CRIT 9.9 microsoft azure_logic_apps Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network. 0,6%
CVE-2026-42822 CRIT 10.0 microsoft azure_local Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network. 0,5%
CVE-2026-42812 CRIT 9.9 apache polaris In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table and which table version to read. `write.metadata.path` is an optional table property that tells Polaris where to write those metadata fil 0,4%
CVE-2026-42811 CRIT 9.9 apache polaris In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials that only work for one table's files, but a crafted namespace or table name can cause those credentials to work across the configured bucket instead. Apache Polaris builds Google 0,4%
CVE-2026-42810 CRIT 9.9 apache polaris Apache Polaris accepts literal `*` characters in namespace and table names. When it later builds temporary S3 access policies for delegated table access, those same characters appear to be reused unescaped in S3 IAM resource patterns and `s3:prefix` conditions 0,4%
CVE-2026-42809 CRIT 9.9 apache polaris Apache Polaris can issue broad temporary ("vended") storage credentials during staged table creation before the effective table location has been validated or durably reserved. Those temporary credentials are meant to limit the scope of accessible table data 0,4%
CVE-2026-42797 MED 4.9 apache syncope Exposure of Sensitive Information Through Data Queries vulnerability in Apache Syncope. An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficient entitlements for User 0,4%
CVE-2026-42782 HIGH 7.2 apache syncope Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted code reaching a non-sandboxed execution path via the class sta 0,7%
CVE-2026-42781 MED 6.5 f5 big-ip_access_policy_manager When embedded Packet Velocity Acceleration (ePVA) acceleration is configured, undisclosed local ethernet traffic can cause an increase in ePVA and Traffic Management Microkernel (TMM) resource utilization.  Note: Software versions which have reached End of Tec 0,2%
CVE-2026-42780 MED 4.9 f5 big-ip_ssl_orchestrator A directory traversal vulnerability exists in BIG-IP SSL Orchestrator that allows an authenticated attacker with high privilege to overwrite, delete or corrupt arbitrary local files.  Note: Software versions which have reached End of Technical Support (EoTS) a 0,9%
CVE-2026-42779 CRIT 9.8 apache mina The fix for CVE-2026-41635 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: Apache MINA's AbstractIoBuffer.resolveClass() contains two branches, one of them (for static classes or primitive types) does not ch 0,9%
CVE-2026-42778 CRIT 9.8 apache mina The fix for CVE-2026-41409 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of classes allowed to be des 0,7%
CVE-2026-42588 HIGH 8.1 apache activemq Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console 0,7%
CVE-2026-42537 CRIT 9.8 apache ranger Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue. 0,7%