56.793 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.793 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2026-5912 | HIGH 8.8 | google chrome Integer overflow in WebRTC in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Low) | 0,2% | — |
| CVE-2026-59119 | HIGH 7.3 | microsoft powershell Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-59118 | CRIT 9.3 | microsoft power_apps Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network. | 0,5% | — |
| CVE-2026-59117 | HIGH 7.5 | microsoft terminal Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code over a network. | 0,6% | — |
| CVE-2026-59115 | CRIT 9.9 | microsoft entra_provisioning_service '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. | 0,8% | — |
| CVE-2026-59113 | HIGH 8.8 | microsoft visual_studio_code Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network. | 0,7% | — |
| CVE-2026-5911 | MED 4.3 | google chrome Policy bypass in ServiceWorkers in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low) | 0,2% | — |
| CVE-2026-5910 | HIGH 8.8 | google chrome Integer overflow in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted video file. (Chromium security severity: Low) | 0,2% | — |
| CVE-2026-5909 | HIGH 8.8 | google chrome Integer overflow in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted video file. (Chromium security severity: Low) | 0,2% | — |
| CVE-2026-59085 | CRIT 9.1 | apache cloudstack Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack's webhook module, exploitable via webhook delivery requests. This issue affects Apache CloudStack: from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended | 0,3% | — |
| CVE-2026-59084 | CRIT 9.1 | apache tomcat Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1. | 0,5% | — |
| CVE-2026-59083 | CRIT 9.1 | apache tomcat Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from | 0,4% | — |
| CVE-2026-5908 | HIGH 8.8 | google chrome Integer overflow in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted video file. (Chromium security severity: Low) | 0,2% | — |
| CVE-2026-5907 | HIGH 8.1 | google chrome Insufficient data validation in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory read via a crafted video file. (Chromium security severity: Low) | 0,2% | — |
| CVE-2026-5906 | MED 4.3 | google chrome Incorrect security UI in Omnibox in Google Chrome on Android prior to 147.0.7727.55 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low) | 0,2% | — |
| CVE-2026-5905 | MED 6.5 | google chrome Incorrect security UI in Permissions in Google Chrome on Windows prior to 147.0.7727.55 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low) | 0,2% | — |
| CVE-2026-5903 | MED 6.5 | google chrome Policy bypass in IFrameSandbox in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low) | 0,3% | — |
| CVE-2026-5902 | CRIT 9.8 | google chrome Race in Media in Google Chrome on Android prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to corrupt media stream metadata via a crafted HTML page. (Chromium security severity: Low) | 0,2% | — |
| CVE-2026-5901 | MED 6.5 | google chrome Insufficient policy enforcement in DevTools in Google Chrome prior to 147.0.7727.55 allowed an attacker who convinced a user to install a malicious extension to bypass enterprise host restrictions for cookie modification via a crafted Chrome Extension. (Chromi | 0,1% | — |
| CVE-2026-5900 | MED 4.3 | google chrome Policy bypass in Downloads in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass of multi-download protections via a crafted HTML page. (Chromium security severity: Low) | 0,2% | — |
| CVE-2026-5899 | MED 6.1 | google chrome Insufficient policy enforcement in History Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium securit | 0,1% | — |
| CVE-2026-5898 | MED 4.3 | google chrome Incorrect security UI in Omnibox in Google Chrome on iOS prior to 147.0.7727.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low) | 0,2% | — |
| CVE-2026-5897 | MED 4.3 | google chrome Incorrect security UI in Downloads in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low) | 0,2% | — |
| CVE-2026-5896 | MED 6.1 | google chrome Policy bypass in Audio in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass sandbox download restrictions via a crafted HTML page. (Chromium security severity: Low) | 0,2% | — |
| CVE-2026-5895 | MED 5.4 | google chrome Incorrect security UI in Omnibox in Google Chrome on iOS prior to 147.0.7727.55 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name. (Chromium security severity: Low) | 0,2% | — |