58.507 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.507 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più basso | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-78455 | MED 4.3 | microsoft windows_10_1607 Out-of-bounds read in Xbox allows an unauthorized attacker to disclose information with a physical attack. | 0,5% | — |
| CVE-2026-58647 | HIGH 8.0 | microsoft power_bi_report_server Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows an authorized attacker to perform spoofing over a network. | 0,5% | — |
| CVE-2026-5860 | HIGH 8.8 | google chrome Use after free in WebRTC in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | 0,5% | — |
| CVE-2026-4678 | HIGH 8.8 | google chrome Use after free in WebGPU in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | 0,5% | — |
| CVE-2026-42360 | MED 6.5 | apache airflow A bug in Apache Airflow's rendered-template field handling caused nested sensitive-key masking (e.g. nested `password` / `token` / `secret` / `api_key` keys inside a JSON template structure) to be bypassed when the rendered field exceeded `[core] max_templated | 0,5% | — |
| CVE-2026-42358 | MED 6.5 | apache airflow A bug in Apache Airflow's Variable response masker caused nested-key redaction (triggered by secret-suffixed key names like `password`, `token`, `secret`, `api_key`) to be bypassed when the JSON value's nesting depth exceeded the shared secrets masker's recurs | 0,5% | — |
| CVE-2026-32208 | HIGH 8.8 | microsoft edge_chromium Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Entra ID allows an authorized attacker to perform spoofing over a network. | 0,5% | — |
| CVE-2026-23456 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: fix OOB read in decode_int() CONS case In decode_int(), the CONS case calls get_bits(bs, 2) to read a length value, then calls get_uint(bs, len) without checkin | 0,5% | — |
| CVE-2026-20944 | HIGH 8.4 | microsoft 365_apps Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0,5% | — |
| CVE-2025-64677 | HIGH 8.2 | microsoft office_out-of-box_experience Improper neutralization of input during web page generation ('cross-site scripting') in Office Out-of-Box Experience allows an unauthorized attacker to perform spoofing over a network. | 0,5% | — |
| CVE-2025-49743 | MED 6.7 | microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | 0,5% | — |
| CVE-2025-38430 | CRIT 9.8 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: nfsd: nfsd4_spo_must_allow() must check this is a v4 compound request If the request being processed is not a v4 compound request, then examining the cstate can have undefined results. This | 0,5% | — |
| CVE-2025-38181 | HIGH 7.5 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: calipso: Fix null-ptr-deref in calipso_req_{set,del}attr(). syzkaller reported a null-ptr-deref in sock_omalloc() while allocating a CALIPSO option. [0] The NULL is of struct sock, which w | 0,5% | — |
| CVE-2025-21405 | HIGH 7.3 | microsoft visual_studio_2022 Visual Studio Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2024-45009 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: only decrement add_addr_accepted for MPJ req Adding the following warning ... WARN_ON_ONCE(msk->pm.add_addr_accepted == 0) ... before decrementing the add_addr_accepted counte | 0,5% | — |
| CVE-2023-21815 | HIGH 7.8 | microsoft visual_studio_2017 Visual Studio Remote Code Execution Vulnerability | 0,5% | — |
| CVE-2022-41054 | HIGH 7.8 | microsoft windows_10 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2022-35707 | HIGH 7.8 | adobe bridge Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vuln | 0,5% | — |
| CVE-2022-35705 | HIGH 7.8 | adobe bridge Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vuln | 0,5% | — |
| CVE-2022-27509 | MED 6.1 | citrix application_delivery_controller_firmware Unauthenticated redirection to a malicious website | 0,5% | — |
| CVE-2022-20684 | HIGH 7.4 | cisco ios_xe A vulnerability in Simple Network Management Protocol (SNMP) trap generation for wireless clients of Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family could allow an unauthenticated, adjacent attacker to cause an affected device to unexpec | 0,5% | — |
| CVE-2021-38638 | HIGH 7.8 | microsoft windows_10 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2021-38630 | HIGH 7.8 | microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2021-38628 | HIGH 7.8 | microsoft windows_10 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2021-38626 | HIGH 7.8 | microsoft windows_server_2008 Windows Kernel Elevation of Privilege Vulnerability | 0,5% | — |