57.255 CVE seguite
779 Sfruttate ora
184 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.255 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-69266 | HIGH 8.8 | microsoft windows_10_1607 Integer overflow or wraparound in Windows DHCP Server allows an unauthorized attacker to execute code over a network. | — | — |
| CVE-2026-67587 | HIGH 8.8 | apache airflow Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the stored callback path. Because `SyncCallback` is itself an Airflow class it passes the default `allowed_deserializati | 0,6% | — |
| CVE-2026-67305 | HIGH 8.8 | freerdp freerdp FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerability in the clipboard virtual channel when processing CLIPRDR_FILE_CONTENTS_RESPONSE PDUs without validating the server-provided size against the destination buffer. A malicious RDP | 0,5% | — |
| CVE-2026-66842 | HIGH 8.8 | BIG-IP has a vulnerability where an authenticated user of any role may be able to create administrative user accounts through an undisclosed request to Traffic Management User Interface (TMUI). Impact: This vulnerability may allow an authenticated attacke | 0,2% | — |
| CVE-2026-66808 | HIGH 8.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 1,1% | — |
| CVE-2026-66805 | HIGH 8.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 1,5% | — |
| CVE-2026-65815 | HIGH 8.8 | microsoft dynamics_365 Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network. | 0,9% | — |
| CVE-2026-65811 | HIGH 8.8 | microsoft power_bi_report_server Improper input validation in Power BI allows an authorized attacker to execute code over a network. | 0,5% | — |
| CVE-2026-65807 | HIGH 8.8 | microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code over a network. | 0,4% | — |
| CVE-2026-65768 | HIGH 8.8 | microsoft teams Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network. | 0,6% | — |
| CVE-2026-65767 | HIGH 8.8 | microsoft teams Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network. | 0,5% | — |
| CVE-2026-65668 | HIGH 8.8 | microsoft purview_ediscovery Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a network. | 0,5% | — |
| CVE-2026-65665 | HIGH 8.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 2,8% | — |
| CVE-2026-65663 | HIGH 8.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 1,4% | — |
| CVE-2026-65660 | HIGH 8.8 | microsoft sharepoint_server Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 0,8% | — |
| CVE-2026-65658 | HIGH 8.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 1,4% | — |
| CVE-2026-64921 | HIGH 8.8 | microsoft sharepoint_server Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | 1,0% | — |
| CVE-2026-64901 | HIGH 8.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 1,9% | — |
| CVE-2026-64881 | HIGH 8.8 | tenable security_center The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command execution. This input validation failure enables command injection when chained with a related vulnerability. | 2,2% | — |
| CVE-2026-64445 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth() OnAuth() has two bugs in the shared-key authentication path. When the Privacy bit is set, rtw_wep_decrypt() is called w | 0,3% | — |
| CVE-2026-64441 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB reads in rtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr() Three IE/attribute parsing functions have missing bounds checks. rtw_get_sec_ie() and rtw_ge | 0,3% | — |
| CVE-2026-64438 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: crypto: qat - fix VF2PF work teardown race in adf_disable_sriov() The VF2PF interrupt handler queues PF-side response work that stores a raw pointer to per-VF state (struct adf_accel_vf_info | 0,1% | — |
| CVE-2026-64437 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free of a deferred file_lock on SMB2_CLOSE then SMB2_CANCEL Commit f580d27e8928 ("ksmbd: fix use-after-free of a deferred file_lock on double SMB2_CANCEL") made smb2_can | 0,4% | — |
| CVE-2026-64434 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref l2cap_chan_timeout() runs asynchronously and accesses chan->conn. If the connection is torn down while the timer is running o | 0,3% | — |
| CVE-2026-64408 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: bnep: pin L2CAP connection during netdev registration bnep_add_connection() reads the L2CAP connection without holding the channel lock, then passes its HCI device to register_net | 0,3% | — |