56.807 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.807 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2026-56162 | CRIT 10.0 | microsoft azure_sql_database Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. | 0,7% | — |
| CVE-2026-56161 | CRIT 9.6 | microsoft azure_logic_apps Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network. | 0,5% | — |
| CVE-2026-56160 | CRIT 9.1 | microsoft azure_red_hat_openshift Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network. | 0,6% | — |
| CVE-2026-56159 | CRIT 9.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network. | 1,0% | — |
| CVE-2026-56157 | MED 5.4 | microsoft sharepoint_server Improper access control in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 0,5% | — |
| CVE-2026-56156 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0,5% | — |
| CVE-2026-56140 | CRIT 9.8 | apache camel Improper Input Validation vulnerability in Apache Camel AWS SNS component. The camel-aws2-sns component filters Camel headers through a component-specific HeaderFilterStrategy, Sns2HeaderFilterStrategy. Like the sibling Sqs2HeaderFilterStrategy, it originall | 0,7% | — |
| CVE-2026-56139 | MED 5.3 | apache camel Generation of Error Message Containing Sensitive Information vulnerability in Apache Camel Undertow Component. The camel-undertow HTTP server consumer exposes a muteException option that controls what is returned to the client when a route processing error oc | 0,6% | — |
| CVE-2026-55994 | HIGH 7.5 | apache camel Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel in Iggy component. The camel-iggy consumer mapped the user-headers of inbound Iggy messages into the Camel | 0,6% | — |
| CVE-2026-55993 | HIGH 7.5 | apache camel Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel in Atmosphere Websocket Component. The camel-atmosphere-websocket consumer mapped inbound WebSocket query p | 0,9% | — |
| CVE-2026-55976 | CRIT 9.1 | apache hive Server-Side Request Forgery (SSRF) in Avro SerDe schema resolution in Apache Hive before 4.2.1 allows an authenticated remote attacker with CREATE TABLE privilege to cause the Hive server to fetch an attacker-controlled URL when resolving the avro.schema.url t | 0,4% | — |
| CVE-2026-55971 | CRIT 9.8 | apache thrift Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. | 0,6% | — |
| CVE-2026-55970 | MED 6.5 | apache thrift Buffer Over-read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. | 0,5% | — |
| CVE-2026-55969 | HIGH 7.5 | apache thrift Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi and Haxe bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. | 0,6% | — |
| CVE-2026-55968 | HIGH 7.5 | apache thrift Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Node.js bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the iss | 0,6% | — |
| CVE-2026-55957 | HIGH 7.3 | apache tomcat Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authenticate binds using GSSAPI allowed attackers to authenticate without provided the correct password. This issue affects Apache Tomcat: from 11.0.0- | 2,9% | — |
| CVE-2026-55956 | MED 6.5 | apache tomcat Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of the constraint. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22 | 1,5% | — |
| CVE-2026-55955 | MED 6.5 | apache tomcat Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.13 through 9. | 0,4% | — |
| CVE-2026-55949 | HIGH 7.8 | microsoft 365_apps Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0,5% | — |
| CVE-2026-55948 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0,5% | — |
| CVE-2026-55947 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0,5% | — |
| CVE-2026-55945 | MED 4.2 | microsoft edge_chromium Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to disclose information locally. | 0,2% | — |
| CVE-2026-55944 | CRIT 9.8 | microsoft dynamics_nav Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network. | 1,5% | — |
| CVE-2026-55899 | HIGH 7.8 | microsoft 365_apps Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0,5% | — |
| CVE-2026-55898 | MED 6.1 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | 0,5% | — |