57.298 CVE seguite
779 Sfruttate ora
184 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.298 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-50444 | HIGH 8.8 | microsoft windows_10_1607 Missing authentication for critical function in Windows Server Update Service allows an authorized attacker to elevate privileges over a network. | 0,8% | — |
| CVE-2026-50438 | HIGH 8.8 | microsoft pc_manager Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2026-50413 | HIGH 8.8 | microsoft windows_11_24h2 Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-50398 | HIGH 8.8 | microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network. | 0,6% | — |
| CVE-2026-50385 | HIGH 8.8 | microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-50382 | HIGH 8.8 | microsoft windows_10_1809 Untrusted pointer dereference in Windows DirectX allows an authorized attacker to execute code locally. | 0,3% | — |
| CVE-2026-50370 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network. | 0,5% | — |
| CVE-2026-50369 | HIGH 8.8 | microsoft windows_10_1607 Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network. | 0,7% | — |
| CVE-2026-50360 | HIGH 8.8 | microsoft windows_10_21h2 Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to elevate privileges over a network. | 0,8% | — |
| CVE-2026-50342 | HIGH 8.8 | microsoft windows_11_24h2 Improper access control in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-50223 | HIGH 8.8 | apache ofbiz Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low-privileged authenticated user with Content/DataResource editing privileges to perform template injection attacks that could lead to Remote Code Execution. Thi | 0,7% | — |
| CVE-2026-50112 | HIGH 8.8 | apache cloudstack SSRF via Metalink Mirror URL Resolution: An authenticated tenant can register a template pointing to an attacker-controlled metalink file containing internal targets. The Secondary Storage VM will retrieve the data and persist it as a template file, which can | 0,5% | — |
| CVE-2026-49795 | HIGH 8.8 | microsoft windows_10_1809 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-49298 | HIGH 8.8 | apache airflow A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API user with Kubernetes re | 0,5% | — |
| CVE-2026-49179 | HIGH 8.8 | microsoft windows_10_1607 Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network. | 0,8% | — |
| CVE-2026-49178 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network. | 0,9% | — |
| CVE-2026-49163 | HIGH 8.8 | microsoft application_insights_profiler Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network. | 0,8% | — |
| CVE-2026-49157 | HIGH 8.8 | apache activemq Incorrect Default Permissions vulnerability in Apache ActiveMQ. This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6. The default Jolokia authorization settings granted non-admin (low-privilege) web-login accounts access to Jolokia oper | 0,4% | — |
| CVE-2026-49050 | HIGH 8.8 | apache dolphinscheduler General user can mint admin access tokens via /access-tokens This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue. | — | — |
| CVE-2026-48564 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network. | 0,9% | — |
| CVE-2026-47653 | HIGH 8.8 | microsoft windows_10_1607 Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 0,6% | — |
| CVE-2026-47645 | HIGH 8.8 | microsoft 365_copilot Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to elevate privileges over a network. | 0,8% | — |
| CVE-2026-47632 | HIGH 8.8 | microsoft azure_connected_machine_agent Improper certificate validation in Azure Connected Machine Agent allows an unauthorized attacker to elevate privileges over an adjacent network. | 0,5% | — |
| CVE-2026-47359 | HIGH 8.8 | apache cloudstack Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache CloudStack's NAS backup provider plugin. The addBackupRepository API (available since 4.20.0.0) and updateBackupRepository API (introduced in 4.2 | 1,1% | — |
| CVE-2026-47342 | HIGH 8.8 | apache ofbiz A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to obtain higher privileges This issue affects Apache OFBiz: before 24.09.07. Users are recommended to upgrade to version 24.09.07, which fixes the issue. | 0,4% | — |