57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.971 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più basso | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-50397 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-50392 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-50372 | HIGH 7.0 | microsoft windows_10_1607 Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-50323 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-50296 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Graphics Kernel allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-49162 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-48571 | HIGH 7.0 | microsoft windows_11_23h2 Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-47622 | MED 5.3 | nvidia dynamo NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause the generation of error messages that contain sensitive information. A successful exploit of this vulnerability might lead to information disclosure. | 0,3% | — |
| CVE-2026-3931 | HIGH 8.8 | google chrome Heap buffer overflow in Skia in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium) | 0,3% | — |
| CVE-2026-33771 | HIGH 7.4 | juniper ctp_operating_system A Weak Password Requirements vulnerability in the password management function of Juniper Networks CTP OS might allow an unauthenticated, network-based attacker to exploit weak passwords of local accounts and potentially take full control of the device. The p | 0,3% | — |
| CVE-2026-28753 | LOW 3.7 | f5 nginx_open_source NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handling of CRLF sequences in DNS responses. This allows an attacker-controlled DNS server to inject arbitrary headers into SMTP upstream requests, lea | 0,3% | — |
| CVE-2026-25088 | MED 5.4 | fortinet fortindr An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiNDR 7.6.0 through 7.6.2, FortiNDR 7.4.0 through 7.4.9, FortiNDR 7.2 all versions, FortiNDR 7.1 all versions, FortiNDR 7.0 all versions may al | 0,3% | — |
| CVE-2026-20334 | HIGH 8.4 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has cond | 0,3% | — |
| CVE-2026-20102 | MED 6.1 | cisco adaptive_security_appliance_software A vulnerability in the SAML 2.0 single sign-on (SSO) feature of Cisco Secure Firewall ASA Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against th | 0,3% | — |
| CVE-2026-20070 | MED 6.1 | cisco adaptive_security_appliance_software A vulnerability in the VPN web services component of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS | 0,3% | — |
| CVE-2026-14153 | MED 5.3 | google chrome Inappropriate implementation in Glic in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low) | 0,3% | — |
| CVE-2026-14112 | MED 5.3 | google chrome Inappropriate implementation in Enterprise in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromi | 0,3% | — |
| CVE-2026-14049 | MED 5.3 | google chrome Inappropriate implementation in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: | 0,3% | — |
| CVE-2026-14012 | MED 5.3 | google chrome Side-channel information leakage in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium) | 0,3% | — |
| CVE-2026-13896 | MED 6.5 | google chrome Insufficient policy enforcement in Glic in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium) | 0,3% | — |
| CVE-2026-13890 | MED 5.3 | google chrome Out of bounds read in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Me | 0,3% | — |
| CVE-2026-13886 | MED 6.5 | google chrome Insufficient policy enforcement in Isolated Web Apps in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium) | 0,3% | — |
| CVE-2026-11632 | HIGH 7.5 | google chrome Use after free in TabStrip in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical) | 0,3% | — |
| CVE-2026-11255 | HIGH 7.5 | google chrome Insufficient validation of untrusted input in Storage Access API in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low) | 0,3% | — |
| CVE-2026-11242 | HIGH 7.5 | google chrome Insufficient validation of untrusted input in Plugins in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low) | 0,3% | — |