57.622 CVE seguite
783 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.622 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più basso | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-9924 | HIGH 8.3 | google chrome Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 0,2% | — |
| CVE-2026-83955 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-7929 | HIGH 7.5 | google chrome Use after free in MediaRecording in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) | 0,2% | — |
| CVE-2026-77904 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-73015 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-73011 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-73007 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-73002 | HIGH 7.8 | microsoft windows_10_1607 Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-71378 | MED 4.6 | apache wicket ResourceIsolationRequestCycleListener protects a Wicket application against cross-site request forgery by rejecting requests that a resource isolation policy judges to come from another origin. Its default policy, FetchMetadataResourceIsolationPolicy, was deri | 0,2% | — |
| CVE-2026-69293 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-68875 | HIGH 7.8 | microsoft windows_10_1607 Buffer over-read in Windows NTFS allows an authorized attacker to execute code locally. | 0,2% | — |
| CVE-2026-68832 | HIGH 7.8 | microsoft windows_10_1607 Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-62726 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-62724 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-62723 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-61939 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Winlogon allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-61938 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Windows Installer allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-61366 | HIGH 7.0 | microsoft windows_10_1607 Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-61346 | HIGH 7.0 | microsoft windows_10_1809 Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-59125 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-50472 | HIGH 7.0 | microsoft windows_10_1607 Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-42978 | HIGH 7.8 | microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-40048 | HIGH 7.8 | apache camel The Camel-PQC FileBasedKeyLifecycleManager class deserializes the contents of `<keyId>.key` files in the configured key directory using java.io.ObjectInputStream without applying any ObjectInputFilter or class-loading restrictions. The cast to `java.security.K | 0,2% | — |
| CVE-2026-32089 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows Speech Brokered Api allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-13029 | HIGH 7.5 | google chrome Use after free in Web Authentication in Google Chrome prior to 149.0.7827.197 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High) | 0,2% | — |