EN
57.139 CVE seguite
779 Sfruttate ora
184 Usate dai ransomware
Ultima sincronia

CVE Tracker

57.139 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordinato dal più alto
CVE-2026-23708 HIGH 7.5 fortinet fortisoar A improper authentication vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR on-premise 7.6.0 through 7.6.3, FortiSOAR on-premise 7.5.0 through 7.5.2 may allow an unauthenticated attacker to bypass authe 0,3%
CVE-2026-23674 HIGH 7.5 microsoft windows_10_1607 Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network. 1,2%
CVE-2026-23673 HIGH 7.8 microsoft windows_10_1607 Out-of-bounds read in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally. 0,4%
CVE-2026-23672 HIGH 7.8 microsoft windows_10_1607 Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability 0,4%
CVE-2026-23671 HIGH 7.0 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to elevate privileges locally. 0,2%
CVE-2026-23670 MED 5.7 microsoft windows_10_1607 Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally. 0,3%
CVE-2026-23669 HIGH 8.8 microsoft windows_10_1607 Use after free in RPC Runtime allows an authorized attacker to execute code over a network. 0,9%
CVE-2026-23668 HIGH 7.0 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. 3,6%
CVE-2026-23667 HIGH 7.0 microsoft windows_10_1809 Use after free in Broadcast DVR allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-23666 HIGH 7.5 microsoft .net_framework Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network. 1,3%
CVE-2026-23665 HIGH 7.8 microsoft linux_diagnostic_extension Heap-based buffer overflow in Azure Linux Virtual Machines allows an authorized attacker to elevate privileges locally. 0,4%
CVE-2026-23664 HIGH 7.5 microsoft azure_iot_explorer Improper restriction of communication channel to intended endpoints in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. 1,0%
CVE-2026-23663 HIGH 7.5 microsoft global_secure_access Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network. 0,6%
CVE-2026-23662 HIGH 7.5 microsoft azure_iot_explorer Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. 0,7%
CVE-2026-23661 HIGH 7.5 microsoft azure_iot_explorer Cleartext transmission of sensitive information in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. 0,7%
CVE-2026-23660 HIGH 7.8 microsoft windows_admin_center Improper access control in Azure Portal Windows Admin Center allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-23659 HIGH 8.6 microsoft azure_data_factory Exposure of sensitive information to an unauthorized actor in Azure Data Factory allows an unauthorized attacker to disclose information over a network. 0,8%
CVE-2026-23658 HIGH 8.6 microsoft azure_devops Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a network. 0,8%
CVE-2026-23657 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0,4%
CVE-2026-23656 MED 5.9 microsoft windows_app Insufficient verification of data authenticity in Windows App Installer allows an unauthorized attacker to perform spoofing over a network. 0,3%
CVE-2026-23655 MED 6.5 microsoft confidential_sidecar_containers Cleartext storage of sensitive information in Azure Compute Gallery allows an authorized attacker to disclose information over a network. 1,0%
CVE-2026-23654 HIGH 8.8 microsoft zero-shot-scfoundation Dependency on vulnerable third-party component in GitHub Repo: zero-shot-scfoundation allows an unauthorized attacker to execute code over a network. 0,9%
CVE-2026-23653 MED 5.7 microsoft github_copilot_chat Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an authorized attacker to disclose information over a network. 0,7%
CVE-2026-23652 CRIT 10.0 microsoft power_pages Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an unauthorized attacker to execute code over a network. 0,6%
CVE-2026-23651 MED 6.7 microsoft aci_confidential_containers Permissive regular expression in Azure Compute Gallery allows an authorized attacker to elevate privileges locally. 0,6%