EN
57.139 CVE seguite
779 Sfruttate ora
184 Usate dai ransomware
Ultima sincronia

CVE Tracker

57.139 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordinato dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2026-75604 CRIT 9.0 Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js applications using Pages Router or App Router without Cache Components on Windows-hosted servers do not consistently escape backslashes in rout 0,8%
CVE-2026-64106 CRIT 9.0 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits Userspace can restore an ITS Device Table Entry whose Size field encodes more EventID bits than the virtual ITS s 0,1%
CVE-2026-58289 CRIT 9.0 microsoft edge_chromium Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. 2,0%
CVE-2026-39860 CRIT 9.0 nixos nix Nix is a package manager for Linux and other Unix systems. A bug in the fix for CVE-2024-27297 allowed for arbitrary overwrites of files writable by the Nix process orchestrating the builds (typically the Nix daemon running as root in multi-user installations) 0,2%
CVE-2026-33844 CRIT 9.0 microsoft azure_managed_instance_for_apache_cassandra Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network. 1,0%
CVE-2026-26149 CRIT 9.0 microsoft power_apps Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to perform spoofing over a network. 0,6%
CVE-2026-20267 CRIT 9.0 cisco ios_xe As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple intern 0,3%
CVE-2025-59978 CRIT 9.0 juniper junos_space An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to store script tags directly in web pages that, when viewed by another user, enable the attacker to execut 0,6%
CVE-2025-55244 CRIT 9.0 microsoft azure_ai_bot_service Azure Bot Service Elevation of Privilege Vulnerability 0,6%
CVE-2025-47158 CRIT 9.0 microsoft azure_devops Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network. 0,7%
CVE-2025-36038 CRIT 9.0 ibm websphere_application_server IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence of serialized objects. 9,8%
CVE-2025-3500 CRIT 9.0 avast antivirus Integer Overflow or Wraparound vulnerability in Avast Antivirus (25.1.981.6) on Windows allows Privilege Escalation.This issue affects Antivirus: from 25.1.981.6 before 25.3. 0,5%
CVE-2025-21198 CRIT 9.0 microsoft hpc_pack_2016 Microsoft High Performance Compute (HPC) Pack Remote Code Execution Vulnerability 0,9%
CVE-2025-20363 CRIT 9.0 cisco adaptive_security_appliance_software A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, r 6,9%
CVE-2024-52577 CRIT 9.0 apache ignite In Apache Ignite versions from 2.6.0 and before 2.17.0, configured Class Serialization Filters are ignored for some Ignite endpoints. The vulnerability could be exploited if an attacker manually crafts an Ignite message containing a vulnerable object whose cla 3,1%
CVE-2024-48886 CRIT 9.0 fortinet fortianalyzer A weak authentication in Fortinet FortiOS versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15, FortiProxy versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.10, 7.0.0 through 7.0.17, 2.0.0 through 2.0.14, FortiManager ver 0,5%
CVE-2024-47572 CRIT 9.0 fortinet fortisoar An improper neutralization of formula elements in a csv file in Fortinet FortiSOAR 7.2.1 through 7.4.1 allows attacker to execute unauthorized code or commands via manipulating csv file 0,6%
CVE-2024-38220 CRIT 9.0 microsoft azure_stack_hub Azure Stack Hub Elevation of Privilege Vulnerability 1,0%
CVE-2024-38182 CRIT 9.0 microsoft dynamics_365 Weak authentication in Microsoft Dynamics 365 allows an unauthenticated attacker to elevate privileges over a network. 0,9%
CVE-2024-38124 CRIT 9.0 microsoft windows_server_2008 Windows Netlogon Elevation of Privilege Vulnerability 1,2%
CVE-2024-29990 CRIT 9.0 microsoft azure_kubernetes_service_confidential_containers Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability 18,0%
CVE-2024-21403 CRIT 9.0 microsoft azure_kubernetes_service Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability 1,3%
CVE-2024-21400 CRIT 9.0 microsoft confidental_containers Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability 2,2%
CVE-2024-21376 CRIT 9.0 microsoft azure_kubernetes_service Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability 1,2%
CVE-2024-0132 CRIT 9.0 nvidia nvidia_container_toolkit NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a specifically crafted container image may gain access to the host file system. This does not impact use cases whe 40,8%