EN
58.352 CVE seguite
792 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.352 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordinato dal più basso In KEV dal, ordina dal più alto
CVE-2026-64914 HIGH 7.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. 0,4% —
CVE-2026-62886 HIGH 7.8 microsoft .net Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally. 0,4% —
CVE-2026-61360 MED 5.5 microsoft windows_10_1607 Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally. 0,4% —
CVE-2026-59270 CRIT 9.4 vmware spring_security Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network interfaces. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 Spring Security 6.5.0 - 0,4% —
CVE-2026-58651 HIGH 7.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0,4% —
CVE-2026-58641 HIGH 7.8 microsoft .net Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally. 0,4% —
CVE-2026-58614 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature locally. 0,4% —
CVE-2026-58155 CRIT 9.3 apache traffic_server Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and policy bypass. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recom 0,4% —
CVE-2026-54997 MED 5.5 microsoft windows_10_1607 Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally. 0,4% —
CVE-2026-50690 MED 5.5 microsoft windows_10_1607 Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally. 0,4% —
CVE-2026-50455 MED 5.5 microsoft windows_10_1607 Use of uninitialized resource in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally. 0,4% —
CVE-2026-50437 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. 0,4% —
CVE-2026-50401 MED 5.5 microsoft windows_10_1809 Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to disclose information locally. 0,4% —
CVE-2026-50383 MED 6.1 microsoft windows_10_1809 Buffer over-read in Windows Print Spooler Components allows an authorized attacker to disclose information locally. 0,4% —
CVE-2026-50381 MED 5.5 microsoft windows_10_21h2 Access of resource using incompatible type ('type confusion') in Composite Image File System Driver allows an authorized attacker to disclose information locally. 0,4% —
CVE-2026-50341 MED 5.5 microsoft windows_10_1607 Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally. 0,4% —
CVE-2026-50300 MED 5.5 microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information locally. 0,4% —
CVE-2026-49801 MED 5.5 microsoft windows_10_1607 Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally. 0,4% —
CVE-2026-45594 MED 5.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally. 0,4% —
CVE-2026-42973 MED 5.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally. 0,4% —
CVE-2026-42970 MED 5.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally. 0,4% —
CVE-2026-42906 MED 5.5 microsoft windows_10_21h2 Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally. 0,4% —
CVE-2026-40422 MED 5.5 microsoft windows_10_1607 Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally. 0,4% —
CVE-2026-20352 HIGH 8.6 A vulnerability in the RADIUS feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of certain RADIU 0,4% —
CVE-2026-20154 HIGH 8.6 A vulnerability in the system rate-limiting process for syslog message 419002 of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause h 0,4% —