EN
57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

57.971 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più basso In KEV dal, ordina dal più alto
CVE-2026-50397 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-50392 HIGH 7.0 microsoft windows_11_24h2 Use after free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-50372 HIGH 7.0 microsoft windows_10_1607 Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-50323 HIGH 7.0 microsoft windows_11_24h2 Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-50296 HIGH 7.0 microsoft windows_10_1607 Use after free in Graphics Kernel allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-49162 HIGH 7.0 microsoft windows_11_24h2 Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-48571 HIGH 7.0 microsoft windows_11_23h2 Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-47622 MED 5.3 nvidia dynamo NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause the generation of error messages that contain sensitive information. A successful exploit of this vulnerability might lead to information disclosure. 0,3%
CVE-2026-3931 HIGH 8.8 google chrome Heap buffer overflow in Skia in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium) 0,3%
CVE-2026-33771 HIGH 7.4 juniper ctp_operating_system A Weak Password Requirements vulnerability in the password management function of Juniper Networks CTP OS might allow an unauthenticated, network-based attacker to exploit weak passwords of local accounts and potentially take full control of the device. The p 0,3%
CVE-2026-28753 LOW 3.7 f5 nginx_open_source NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handling of CRLF sequences in DNS responses. This allows an attacker-controlled DNS server to inject arbitrary headers into SMTP upstream requests, lea 0,3%
CVE-2026-25088 MED 5.4 fortinet fortindr An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiNDR 7.6.0 through 7.6.2, FortiNDR 7.4.0 through 7.4.9, FortiNDR 7.2 all versions, FortiNDR 7.1 all versions, FortiNDR 7.0 all versions may al 0,3%
CVE-2026-20334 HIGH 8.4 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has cond 0,3%
CVE-2026-20102 MED 6.1 cisco adaptive_security_appliance_software A vulnerability in the SAML 2.0 single sign-on (SSO) feature of Cisco Secure Firewall ASA Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against th 0,3%
CVE-2026-20070 MED 6.1 cisco adaptive_security_appliance_software A vulnerability in the VPN web services component of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS 0,3%
CVE-2026-14153 MED 5.3 google chrome Inappropriate implementation in Glic in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low) 0,3%
CVE-2026-14112 MED 5.3 google chrome Inappropriate implementation in Enterprise in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromi 0,3%
CVE-2026-14049 MED 5.3 google chrome Inappropriate implementation in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: 0,3%
CVE-2026-14012 MED 5.3 google chrome Side-channel information leakage in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium) 0,3%
CVE-2026-13896 MED 6.5 google chrome Insufficient policy enforcement in Glic in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium) 0,3%
CVE-2026-13890 MED 5.3 google chrome Out of bounds read in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Me 0,3%
CVE-2026-13886 MED 6.5 google chrome Insufficient policy enforcement in Isolated Web Apps in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium) 0,3%
CVE-2026-11632 HIGH 7.5 google chrome Use after free in TabStrip in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical) 0,3%
CVE-2026-11255 HIGH 7.5 google chrome Insufficient validation of untrusted input in Storage Access API in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low) 0,3%
CVE-2026-11242 HIGH 7.5 google chrome Insufficient validation of untrusted input in Plugins in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low) 0,3%