57.139 CVE seguite
779 Sfruttate ora
184 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.139 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-75604 | CRIT 9.0 | Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js applications using Pages Router or App Router without Cache Components on Windows-hosted servers do not consistently escape backslashes in rout | 0,8% | — |
| CVE-2026-64106 | CRIT 9.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits Userspace can restore an ITS Device Table Entry whose Size field encodes more EventID bits than the virtual ITS s | 0,1% | — |
| CVE-2026-58289 | CRIT 9.0 | microsoft edge_chromium Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 2,0% | — |
| CVE-2026-39860 | CRIT 9.0 | nixos nix Nix is a package manager for Linux and other Unix systems. A bug in the fix for CVE-2024-27297 allowed for arbitrary overwrites of files writable by the Nix process orchestrating the builds (typically the Nix daemon running as root in multi-user installations) | 0,2% | — |
| CVE-2026-33844 | CRIT 9.0 | microsoft azure_managed_instance_for_apache_cassandra Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network. | 1,0% | — |
| CVE-2026-26149 | CRIT 9.0 | microsoft power_apps Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to perform spoofing over a network. | 0,6% | — |
| CVE-2026-20267 | CRIT 9.0 | cisco ios_xe As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple intern | 0,3% | — |
| CVE-2025-59978 | CRIT 9.0 | juniper junos_space An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to store script tags directly in web pages that, when viewed by another user, enable the attacker to execut | 0,6% | — |
| CVE-2025-55244 | CRIT 9.0 | microsoft azure_ai_bot_service Azure Bot Service Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2025-47158 | CRIT 9.0 | microsoft azure_devops Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network. | 0,7% | — |
| CVE-2025-36038 | CRIT 9.0 | ibm websphere_application_server IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence of serialized objects. | 9,8% | — |
| CVE-2025-3500 | CRIT 9.0 | avast antivirus Integer Overflow or Wraparound vulnerability in Avast Antivirus (25.1.981.6) on Windows allows Privilege Escalation.This issue affects Antivirus: from 25.1.981.6 before 25.3. | 0,5% | — |
| CVE-2025-21198 | CRIT 9.0 | microsoft hpc_pack_2016 Microsoft High Performance Compute (HPC) Pack Remote Code Execution Vulnerability | 0,9% | — |
| CVE-2025-20363 | CRIT 9.0 | cisco adaptive_security_appliance_software A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, r | 6,9% | — |
| CVE-2024-52577 | CRIT 9.0 | apache ignite In Apache Ignite versions from 2.6.0 and before 2.17.0, configured Class Serialization Filters are ignored for some Ignite endpoints. The vulnerability could be exploited if an attacker manually crafts an Ignite message containing a vulnerable object whose cla | 3,1% | — |
| CVE-2024-48886 | CRIT 9.0 | fortinet fortianalyzer A weak authentication in Fortinet FortiOS versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15, FortiProxy versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.10, 7.0.0 through 7.0.17, 2.0.0 through 2.0.14, FortiManager ver | 0,5% | — |
| CVE-2024-47572 | CRIT 9.0 | fortinet fortisoar An improper neutralization of formula elements in a csv file in Fortinet FortiSOAR 7.2.1 through 7.4.1 allows attacker to execute unauthorized code or commands via manipulating csv file | 0,6% | — |
| CVE-2024-38220 | CRIT 9.0 | microsoft azure_stack_hub Azure Stack Hub Elevation of Privilege Vulnerability | 1,0% | — |
| CVE-2024-38182 | CRIT 9.0 | microsoft dynamics_365 Weak authentication in Microsoft Dynamics 365 allows an unauthenticated attacker to elevate privileges over a network. | 0,9% | — |
| CVE-2024-38124 | CRIT 9.0 | microsoft windows_server_2008 Windows Netlogon Elevation of Privilege Vulnerability | 1,2% | — |
| CVE-2024-29990 | CRIT 9.0 | microsoft azure_kubernetes_service_confidential_containers Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability | 18,0% | — |
| CVE-2024-21403 | CRIT 9.0 | microsoft azure_kubernetes_service Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability | 1,3% | — |
| CVE-2024-21400 | CRIT 9.0 | microsoft confidental_containers Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability | 2,2% | — |
| CVE-2024-21376 | CRIT 9.0 | microsoft azure_kubernetes_service Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability | 1,2% | — |
| CVE-2024-0132 | CRIT 9.0 | nvidia nvidia_container_toolkit NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a specifically crafted container image may gain access to the host file system. This does not impact use cases whe | 40,8% | — |