58.518 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.518 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-57990 | HIGH 7.4 | microsoft edge_chromium Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | 0,9% | — |
| CVE-2026-57989 | HIGH 7.4 | microsoft edge_chromium Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | 0,4% | — |
| CVE-2026-54127 | HIGH 7.4 | microsoft windows_11_24h2 Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-53561 | HIGH 7.4 | apache hive An improper authentication vulnerability in HiveServer2 SAML bearer-token validation in Apache Hive 4.0.0 through 4.2.0 (and later unreleased branches) on deployments using HTTP transport with hive.server2.authentication=SAML allows an unauthenticated network | 0,3% | — |
| CVE-2026-50631 | HIGH 7.4 | apache cxf A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypass single-use semantics and generate multiple valid Access Tokens, when 'recycleRefreshTokens' is set to false. A leaked refresh token can be replayed | 0,4% | — |
| CVE-2026-48287 | HIGH 7.4 | adobe c2pa CAI Content Credentials is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires use | 0,2% | — |
| CVE-2026-47841 | HIGH 7.4 | vmware spring_security An application using Spring Security's WebAuthn support may be vulnerable to user verification bypass when using a distributed HTTP session store. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 Spring Security 6.5.0 - 6.5.11 Spring Security 6.4.0 - 6.4.18 | 0,4% | — |
| CVE-2026-46320 | HIGH 7.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tap: free page on error paths in tap_get_user_xdp() tap_get_user_xdp() rejects a frame shorter than ETH_HLEN with -EINVAL, and returns -ENOMEM when build_skb() fails. Both paths jump to the | 0,4% | — |
| CVE-2026-42893 | HIGH 7.4 | microsoft outlook Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to perform tampering over a network. | 0,7% | — |
| CVE-2026-41707 | HIGH 7.4 | vmware spring_security Authentication Bypass by Capture-replay vulnerability in Spring Spring Security allows Spring Security's DPoPProofJwtDecoderFactory contains a cache-based replay attack vulnerability. The internal cache storing JWT ID claims has a strict size limit, allowing a | 0,4% | — |
| CVE-2026-41107 | HIGH 7.4 | microsoft edge_chromium External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | 0,9% | — |
| CVE-2026-40414 | HIGH 7.4 | microsoft windows_10_1607 Windows TCP/IP Denial of Service Vulnerability | 0,6% | — |
| CVE-2026-40413 | HIGH 7.4 | microsoft windows_10_1607 Windows TCP/IP Denial of Service Vulnerability | 0,6% | — |
| CVE-2026-35561 | HIGH 7.4 | amazon athena_odbc Insufficient authentication security controls in the browser-based authentication components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to intercept or hijack authentication sessions due to insufficient protections in the browser-ba | 0,7% | — |
| CVE-2026-35560 | HIGH 7.4 | amazon athena_odbc Improper certificate validation in the identity provider connection components in Amazon Athena ODBC driver before 2.1.0.0 might allow a man-in-the-middle threat actor to intercept authentication credentials due to insufficient default transport security when | 0,4% | — |
| CVE-2026-33797 | HIGH 7.4 | juniper junos An Improper Input Validation vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker, sending a specific genuine BGP packet in an already established BGP session to reset only that session causing a Denial o | 0,3% | — |
| CVE-2026-33771 | HIGH 7.4 | juniper ctp_operating_system A Weak Password Requirements vulnerability in the password management function of Juniper Networks CTP OS might allow an unauthenticated, network-based attacker to exploit weak passwords of local accounts and potentially take full control of the device. The p | 0,4% | — |
| CVE-2026-32156 | HIGH 7.4 | microsoft windows_10_1607 Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to execute code locally. | 0,3% | — |
| CVE-2026-2713 | HIGH 7.4 | ibm trusteer_rapport IBM Trusteer Rapport installer 3.5.2309.290 IBM Trusteer Rapport could allow a local attacker to execute arbitrary code on the system, caused by DLL uncontrolled search path element vulnerability. By placing a specially crafted file in a compromised folder, an | 0,2% | — |
| CVE-2026-25167 | HIGH 7.4 | microsoft windows_11_24h2 Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-24281 | HIGH 7.4 | apache zookeeper Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, allowing attackers who control or spoof PTR records to impersonate ZooKeeper servers or clients with a valid certificate for the PTR name. It | 0,6% | — |
| CVE-2026-23364 | HIGH 7.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: Compare MACs in constant time To prevent timing attacks, MAC comparisons need to be constant-time. Replace the memcmp() with the correct function, crypto_memneq(). | 0,4% | — |
| CVE-2026-21524 | HIGH 7.4 | microsoft azure_data_explorer Exposure of sensitive information to an unauthorized actor in Azure Data Explorer allows an unauthorized attacker to disclose information over a network. | 0,6% | — |
| CVE-2026-21521 | HIGH 7.4 | microsoft 365_word_copilot Improper neutralization of escape, meta, or control sequences in Copilot allows an unauthorized attacker to disclose information over a network. | 0,6% | — |
| CVE-2026-20853 | HIGH 7.4 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows WalletService allows an unauthorized attacker to elevate privileges locally. | 0,3% | — |