57.056 CVE seguite
777 Sfruttate ora
184 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.056 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più alto |
|---|---|---|---|---|
| CVE-2026-41217 | HIGH 7.9 | f5 big-ip_access_policy_manager A vulnerability exists in an undisclosed BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with resource administrator or administrator role to execute arbitrary system commands with higher privileges. In Appliance mode deployments, a s | 0,1% | — |
| CVE-2026-41154 | HIGH 7.8 | imaginationtech ddk Software installed and run as a non-privileged user may cause OOB kernel memory reads or writes through GPU API calls. When indexing pages larger than 4kB in the page freeing logic of the sparse memory implementation, incorrect buffer indexing leads to OOB | 0,2% | — |
| CVE-2026-41134 | HIGH 7.8 | microsoft kiota Kiota is an OpenAPI based HTTP Client code generator. Versions prior to 1.29.1 and 1.31.1 are affected by a code-generation literal injection vulnerability in multiple writer sinks (for example: serialization/deserialization keys, path/query parameter mappings | 0,4% | — |
| CVE-2026-41115 | MED 4.3 | apache kafka An improper authorization vulnerability has been identified in Apache Kafka. The implementation of the CONSUMER_GROUP_DESCRIBE (69) API validates the DESCRIBE operation on the GROUP resource instead of the READ operation that documented in the official kafka | 0,3% | — |
| CVE-2026-41109 | HIGH 8.8 | microsoft visual_studio_code Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to bypass a security feature over a network. | 0,9% | — |
| CVE-2026-41108 | HIGH 7.0 | microsoft windows_10_1607 Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-41107 | HIGH 7.4 | microsoft edge_chromium External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | 0,7% | — |
| CVE-2026-41106 | CRIT 9.3 | microsoft 365_copilot Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network. | 0,7% | — |
| CVE-2026-41105 | HIGH 8.1 | microsoft azure_monitor_action_group_notification_system Server-side request forgery (ssrf) in Azure Notification Service allows an authorized attacker to elevate privileges over a network. | 0,8% | — |
| CVE-2026-41104 | CRIT 10.0 | microsoft planetary_computer Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose information over a network. | 0,9% | — |
| CVE-2026-41103 | CRIT 9.1 | microsoft confluence_saml_sso Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an unauthorized attacker to elevate privileges over a network. | 5,4% | — |
| CVE-2026-41102 | HIGH 7.1 | microsoft powerpoint Improper access control in Microsoft Office PowerPoint allows an authorized attacker to perform spoofing locally. | 0,3% | — |
| CVE-2026-41101 | HIGH 7.1 | microsoft word Improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing locally. | 0,3% | — |
| CVE-2026-41100 | MED 4.4 | microsoft 365_copilot Improper access control in M365 Copilot allows an authorized attacker to perform spoofing locally. | 0,2% | — |
| CVE-2026-41098 | HIGH 8.4 | microsoft azure_stack_edge Improper neutralization of input during web page generation ('cross-site scripting') in Azure Stack Edge allows an authorized attacker to perform spoofing over a network. | 0,8% | — |
| CVE-2026-41097 | MED 6.7 | microsoft windows_10_1809 Reliance on a component that is not updateable in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | 1,4% | — |
| CVE-2026-41096 | CRIT 9.8 | microsoft windows_11_23h2 Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network. | 1,9% | — |
| CVE-2026-41095 | HIGH 7.8 | microsoft windows_server_2012 Use after free in Data Deduplication allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-41094 | HIGH 8.8 | microsoft data_formulator Improper control of generation of code ('code injection') in Microsoft Data Formulator allows an unauthorized attacker to execute code over a network. | 0,8% | — |
| CVE-2026-41092 | HIGH 7.8 | microsoft windows_10_1607 Improper access control in Microsoft Kinect allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-41090 | CRIT 9.3 | microsoft 365_copilot Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network. | 0,4% | — |
| CVE-2026-41089 | CRIT 9.8 | microsoft windows_server_2012 Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network. | 79,6% | — |
| CVE-2026-41088 | HIGH 7.8 | microsoft windows_10_21h2 Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-41087 | MED 5.5 | microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | 0,5% | — |
| CVE-2026-41086 | HIGH 8.8 | microsoft windows_admin_center Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network. | 0,4% | — |