57.139 CVE seguite
779 Sfruttate ora
184 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.139 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più alto |
|---|---|---|---|---|
| CVE-2026-23708 | HIGH 7.5 | fortinet fortisoar A improper authentication vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR on-premise 7.6.0 through 7.6.3, FortiSOAR on-premise 7.5.0 through 7.5.2 may allow an unauthenticated attacker to bypass authe | 0,3% | — |
| CVE-2026-23674 | HIGH 7.5 | microsoft windows_10_1607 Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network. | 1,2% | — |
| CVE-2026-23673 | HIGH 7.8 | microsoft windows_10_1607 Out-of-bounds read in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2026-23672 | HIGH 7.8 | microsoft windows_10_1607 Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | 0,4% | — |
| CVE-2026-23671 | HIGH 7.0 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-23670 | MED 5.7 | microsoft windows_10_1607 Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally. | 0,3% | — |
| CVE-2026-23669 | HIGH 8.8 | microsoft windows_10_1607 Use after free in RPC Runtime allows an authorized attacker to execute code over a network. | 0,9% | — |
| CVE-2026-23668 | HIGH 7.0 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | 3,6% | — |
| CVE-2026-23667 | HIGH 7.0 | microsoft windows_10_1809 Use after free in Broadcast DVR allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-23666 | HIGH 7.5 | microsoft .net_framework Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network. | 1,3% | — |
| CVE-2026-23665 | HIGH 7.8 | microsoft linux_diagnostic_extension Heap-based buffer overflow in Azure Linux Virtual Machines allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2026-23664 | HIGH 7.5 | microsoft azure_iot_explorer Improper restriction of communication channel to intended endpoints in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2026-23663 | HIGH 7.5 | microsoft global_secure_access Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network. | 0,6% | — |
| CVE-2026-23662 | HIGH 7.5 | microsoft azure_iot_explorer Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. | 0,7% | — |
| CVE-2026-23661 | HIGH 7.5 | microsoft azure_iot_explorer Cleartext transmission of sensitive information in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. | 0,7% | — |
| CVE-2026-23660 | HIGH 7.8 | microsoft windows_admin_center Improper access control in Azure Portal Windows Admin Center allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-23659 | HIGH 8.6 | microsoft azure_data_factory Exposure of sensitive information to an unauthorized actor in Azure Data Factory allows an unauthorized attacker to disclose information over a network. | 0,8% | — |
| CVE-2026-23658 | HIGH 8.6 | microsoft azure_devops Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a network. | 0,8% | — |
| CVE-2026-23657 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2026-23656 | MED 5.9 | microsoft windows_app Insufficient verification of data authenticity in Windows App Installer allows an unauthorized attacker to perform spoofing over a network. | 0,3% | — |
| CVE-2026-23655 | MED 6.5 | microsoft confidential_sidecar_containers Cleartext storage of sensitive information in Azure Compute Gallery allows an authorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2026-23654 | HIGH 8.8 | microsoft zero-shot-scfoundation Dependency on vulnerable third-party component in GitHub Repo: zero-shot-scfoundation allows an unauthorized attacker to execute code over a network. | 0,9% | — |
| CVE-2026-23653 | MED 5.7 | microsoft github_copilot_chat Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an authorized attacker to disclose information over a network. | 0,7% | — |
| CVE-2026-23652 | CRIT 10.0 | microsoft power_pages Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an unauthorized attacker to execute code over a network. | 0,6% | — |
| CVE-2026-23651 | MED 6.7 | microsoft aci_confidential_containers Permissive regular expression in Azure Compute Gallery allows an authorized attacker to elevate privileges locally. | 0,6% | — |