57.924 CVE seguite
784 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.924 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più basso | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-69817 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Bluetooth Port Driver allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-69816 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Accounts Control allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-69814 | HIGH 7.0 | microsoft windows_11_23h2 Use after free in Windows Credential Providers allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-69567 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-69422 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Windows USB Video Driver allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-69413 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-69333 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-69287 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-68825 | HIGH 7.0 | microsoft windows_11_23h2 Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-65814 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Storage Port Driver allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-62694 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Installer allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-5283 | MED 6.5 | google chrome Inappropriate implementation in ANGLE in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) | 0,3% | — |
| CVE-2026-43334 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SMP: force responder MITM requirements before building the pairing response smp_cmd_pairing_req() currently builds the pairing response from the initiator auth_req before enforcin | 0,3% | — |
| CVE-2026-32087 | HIGH 7.0 | microsoft windows_10_1607 Heap-based buffer overflow in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-31513 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix stack-out-of-bounds read in l2cap_ecred_conn_req Syzbot reported a KASAN stack-out-of-bounds read in l2cap_build_cmd() that is triggered by a malformed Enhanced Credit | 0,3% | — |
| CVE-2026-26165 | HIGH 7.0 | microsoft windows_11_23h2 Use after free in Windows Shell allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-2321 | HIGH 8.8 | google chrome Use after free in Ozone in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) | 0,3% | — |
| CVE-2026-21280 | HIGH 8.6 | adobe illustrator Illustrator versions 29.8.3, 30.0 and earlier are affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. If the application uses a search path to locate critical resources such as pr | 0,3% | — |
| CVE-2026-20276 | HIGH 8.6 | cisco ios_xr As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple inte | 0,3% | — |
| CVE-2026-11664 | HIGH 8.8 | google chrome Use after free in Payments in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 0,3% | — |
| CVE-2026-11659 | CRIT 9.6 | google chrome Integer overflow in UI in Google Chrome on Linux prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 0,3% | — |
| CVE-2026-11638 | CRIT 9.6 | google chrome Use after free in Printing in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | 0,3% | — |
| CVE-2026-11634 | CRIT 9.6 | google chrome Use after free in Gamepad in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | 0,3% | — |
| CVE-2026-11630 | HIGH 8.8 | google chrome Use after free in File Input in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) | 0,3% | — |
| CVE-2026-10016 | HIGH 8.8 | google chrome Use after free in DOM in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | 0,3% | — |