EN
56.747 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia

CVE Tracker

56.747 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordinato dal più alto
CVE-2026-61926 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-61925 HIGH 7.8 microsoft windows_10_1607 Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally. 0,4%
CVE-2026-61924 MED 6.5 microsoft windows_10_1607 Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. 0,8%
CVE-2026-61923 HIGH 7.8 microsoft windows_10_1809 Heap-based buffer overflow in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-61921 MED 6.5 microsoft windows_10_1607 Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. 0,8%
CVE-2026-61920 MED 6.6 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an authorized attacker to execute code over a network. 0,5%
CVE-2026-61918 MED 6.5 microsoft windows_10_1607 Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. 0,9%
CVE-2026-61899 HIGH 7.5 apache tapestry Vulnerability in tapestry-core in Apache Tapestry 5.5.0+ on all platforms allows attackers to download clsspath assets via specially crafted URLs. Users are recommended to upgrade to version 5.9.1, which fixes this issue. 0,5%
CVE-2026-61487 MED 6.5 apache activemq Improper Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. An authenticated low-privilege user can bypass a per-destination write ACL by sending to an ActiveMQ temporary composite destination whose physical name is 0,4%
CVE-2026-61486 CRIT 9.8 apache lucy ** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an al 0,6%
CVE-2026-61485 HIGH 7.5 apache lucy ** UNSUPPORTED WHEN ASSIGNED ** Memory Allocation with Excessive Size Value vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommend 0,6%
CVE-2026-61484 CRIT 9.8 apache lucy ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find 0,6%
CVE-2026-61483 HIGH 7.5 apache lucy ** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alterna 0,6%
CVE-2026-61466 CRIT 9.1 apache cxf In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client registration request verbatim, without validating it against an AS-defined allowlist. This could lead to a client 0,4%
CVE-2026-61422 MED 4.3 apache cloudstack Authenticated pre-validation SSRF vulnerability in Apache CloudStack's template and ISO registration functionality. When registering a template or ISO, CloudStack makes a live HTTP HEAD/GET call to determine file size for secondary storage usage-limit checks, 0,2%
CVE-2026-61400 HIGH 8.8 apache cloudstack Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache CloudStack's run and get diagnostics functionality for the system VMs and virtual routers. An authenticated user holding the permissions required to in 1,2%
CVE-2026-61399 MED 4.8 apache cloudstack Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Lock User Functionality. This issue affects Apache CloudStack: from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to 0,1%
CVE-2026-61398 CRIT 9.1 apache cloudstack Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Instance Reset Password functionality. This issue affects Apache CloudStack: from 4.15.1.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended 0,2%
CVE-2026-61397 HIGH 7.5 apache cloudstack Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAuth2 authentication plugin and Google OAuth integration. This issue affects Apache CloudStack: from 4.19.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. 0,3%
CVE-2026-61372 HIGH 7.5 apache jena_fuseki Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fuseki. This issue affects Apache Jena Fuseki: through 6.1.0. Users are recommended to upgrade to version 6.2.0, which fixes the issue. 0,6%
CVE-2026-61368 MED 5.0 microsoft windows_10_1607 Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally. 0,4%
CVE-2026-61367 HIGH 7.8 microsoft windows_10_1607 Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-61366 HIGH 7.0 microsoft windows_10_1607 Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally. 0,2%
CVE-2026-61365 HIGH 7.8 microsoft windows_10_1607 Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-61364 HIGH 7.8 microsoft windows_10_1607 Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. 0,3%