EN
57.298 CVE seguite
779 Sfruttate ora
184 Usate dai ransomware
Ultima sincronia

CVE Tracker

57.298 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordinato dal più basso
CVE-2026-23672 HIGH 7.8 microsoft windows_10_1607 Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability 0,4%
CVE-2026-23671 HIGH 7.0 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to elevate privileges locally. 0,2%
CVE-2026-23670 MED 5.7 microsoft windows_10_1607 Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally. 0,3%
CVE-2026-23669 HIGH 8.8 microsoft windows_10_1607 Use after free in RPC Runtime allows an authorized attacker to execute code over a network. 0,9%
CVE-2026-23668 HIGH 7.0 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. 3,6%
CVE-2026-23667 HIGH 7.0 microsoft windows_10_1809 Use after free in Broadcast DVR allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-23666 HIGH 7.5 microsoft .net_framework Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network. 1,3%
CVE-2026-23665 HIGH 7.8 microsoft linux_diagnostic_extension Heap-based buffer overflow in Azure Linux Virtual Machines allows an authorized attacker to elevate privileges locally. 0,4%
CVE-2026-23664 HIGH 7.5 microsoft azure_iot_explorer Improper restriction of communication channel to intended endpoints in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. 1,0%
CVE-2026-23663 HIGH 7.5 microsoft global_secure_access Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network. 0,6%
CVE-2026-23662 HIGH 7.5 microsoft azure_iot_explorer Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. 0,7%
CVE-2026-23661 HIGH 7.5 microsoft azure_iot_explorer Cleartext transmission of sensitive information in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. 0,7%
CVE-2026-23660 HIGH 7.8 microsoft windows_admin_center Improper access control in Azure Portal Windows Admin Center allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-23659 HIGH 8.6 microsoft azure_data_factory Exposure of sensitive information to an unauthorized actor in Azure Data Factory allows an unauthorized attacker to disclose information over a network. 0,8%
CVE-2026-23658 HIGH 8.6 microsoft azure_devops Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a network. 0,8%
CVE-2026-23657 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0,4%
CVE-2026-23656 MED 5.9 microsoft windows_app Insufficient verification of data authenticity in Windows App Installer allows an unauthorized attacker to perform spoofing over a network. 0,3%
CVE-2026-23655 MED 6.5 microsoft confidential_sidecar_containers Cleartext storage of sensitive information in Azure Compute Gallery allows an authorized attacker to disclose information over a network. 1,0%
CVE-2026-23654 HIGH 8.8 microsoft zero-shot-scfoundation Dependency on vulnerable third-party component in GitHub Repo: zero-shot-scfoundation allows an unauthorized attacker to execute code over a network. 0,9%
CVE-2026-23653 MED 5.7 microsoft github_copilot_chat Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an authorized attacker to disclose information over a network. 0,7%
CVE-2026-23652 CRIT 10.0 microsoft power_pages Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an unauthorized attacker to execute code over a network. 0,6%
CVE-2026-23651 MED 6.7 microsoft aci_confidential_containers Permissive regular expression in Azure Compute Gallery allows an authorized attacker to elevate privileges locally. 0,6%
CVE-2026-23573 MED 6.1 fortinet fortios An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiPAM 1.8.0, FortiPAM 1.7 all versions, 0,4%
CVE-2026-23571 MED 6.8 teamviewer digital_employee_experience A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-RunPkgStatusRequest instruction. Improper input validation allows authenticated attackers with actioner privilege to run elevated arbitrary com 0,7%
CVE-2026-23570 MED 6.5 teamviewer digital_employee_experience A missing validation of a user-controlled value in the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an adjacent network attacker to tamper with log timestamps via crafted UDP Sy 0,7%