58.507 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.507 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-67390 | MED 6.5 | microsoft sql_server_2017 Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2026-67389 | MED 6.5 | microsoft sql_server_2022 Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2026-67386 | MED 6.5 | microsoft sql_server_2017 Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2026-67383 | MED 6.5 | microsoft sql_server_2025 Generation of error message containing sensitive information in SQL Server allows an authorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2026-67369 | MED 6.5 | microsoft sql_server_2025 Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2026-66816 | MED 6.5 | microsoft sql_server_2022 Insufficient logging in SQL Server allows an authorized attacker to bypass a security feature over a network. | 1,0% | — |
| CVE-2026-66301 | MED 6.5 | microsoft dynamics_365 Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2026-57982 | MED 6.5 | microsoft windows_10_1607 Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2026-54116 | MED 6.5 | microsoft sql_server_2025 Access of resource using incompatible type ('type confusion') in SQL Server allows an authorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2026-50468 | MED 6.5 | microsoft sql_server_2025 Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2026-49159 | MED 6.5 | microsoft graph Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2026-47655 | MED 6.5 | microsoft graph Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2026-42907 | MED 6.5 | microsoft windows_10_1809 Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2026-40374 | MED 6.5 | microsoft power_automate_for_desktop Exposure of sensitive information to an unauthorized actor in Power Automate allows an authorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2026-34348 | MED 6.5 | microsoft windows_10_1809 Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2026-32151 | MED 6.5 | microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2026-26155 | MED 6.5 | microsoft windows_10_1607 Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability | 1,0% | — |
| CVE-2026-26122 | MED 6.5 | microsoft aci_confidential_containers Initialization of a resource with an insecure default in Azure Compute Gallery allows an authorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2024-27347 | MED 5.3 | apache hugegraph-hubble Server-Side Request Forgery (SSRF) vulnerability in Apache HugeGraph-Hubble.This issue affects Apache HugeGraph-Hubble: from 1.0.0 before 1.3.0. Users are recommended to upgrade to version 1.3.0, which fixes the issue. | 1,0% | — |
| CVE-2023-36020 | HIGH 7.6 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 1,0% | — |
| CVE-2022-30138 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 1,0% | — |
| CVE-2022-24499 | HIGH 7.8 | microsoft windows_10 Windows Installer Elevation of Privilege Vulnerability | 1,0% | — |
| CVE-2021-23040 | HIGH 8.8 | f5 big-ip_advanced_firewall_manager On BIG-IP AFM version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x, a SQL injection vulnerability exists in an undisclosed page of the BIG-IP Configuration utility. This issue is expos | 1,0% | — |
| CVE-2021-22976 | HIGH 7.5 | f5 big-ip_advanced_web_application_firewall On BIG-IP Advanced WAF and ASM version 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.6, and all 12.1.x versions, when the BIG-IP ASM system processes WebSocket requests with JSON payloads, an unusually large number | 1,0% | — |
| CVE-2021-21552 | MED 5.2 | microsoft windows_10 Dell Wyse Windows Embedded System versions WIE10 LTSC 2019 and earlier contain an improper authorization vulnerability. A local authenticated malicious user with low privileges may potentially exploit this vulnerability to bypass the restricted environment and | 1,0% | — |