EN
57.588 CVE seguite
783 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

57.588 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordinato dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2026-47906 HIGH 8.6 adobe dreamweaver Dreamweaver Desktop versions 21.7 and earlier are affected by a Dependency on Vulnerable Third-Party Component vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction 0,2%
CVE-2026-47835 HIGH 8.6 vmware spring_ai In Spring AI Vector Stores, special characters could be used to force the execution of arbitrary queries in Elasticsearch, OpenSearch, and GemFire VectorDB. Affected components: spring-ai-elasticsearch-store, spring-ai-opensearch-store, spring-ai-gemfire-store 0,3%
CVE-2026-46273 HIGH 8.6 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ibmveth: Disable GSO for packets with small MSS Some physical adapters on Power systems do not support segmentation offload when the MSS is less than 224 bytes. Attempting to send such packe 0,4%
CVE-2026-45169 HIGH 8.6 paloaltonetworks idira_privileged_access_manager_vault Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a validation vulnerability. Under specific circumstances and configuration scenarios, processing unexpected input could potentially lead to an 0,4%
CVE-2026-43139 HIGH 8.6 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: xfrm6: fix uninitialized saddr in xfrm6_get_saddr() xfrm6_get_saddr() does not check the return value of ipv6_dev_get_saddr(). When ipv6_dev_get_saddr() fails to find a suitable source addre 0,4%
CVE-2026-41705 HIGH 8.6 vmware spring_ai Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injection via unsanitized document IDs. Spring AI 1.0.x: affected from 1.0.0 through latest 1.0.x; upgrade to 1.0.7 or greater. Spring AI 1.1.x: affected from 1.1.0 0,4%
CVE-2026-40967 HIGH 8.6 vmware spring_ai In Spring AI, various FilterExpressionConverter implementations accept a filter expression object and translate them to specific vector store query languages. In several cases, keys and values are not properly escaped, leading to the ability to alter the query 0,4%
CVE-2026-35435 HIGH 8.6 microsoft azure_ai_foundry Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network. 1,2%
CVE-2026-34622 HIGH 8.6 adobe acrobat Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary code execution in the context 0,4%
CVE-2026-34621 HIGH 8.6 adobe acrobat Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary code execution in the context of the curren 7,1%
CVE-2026-32173 HIGH 8.6 microsoft azure_sre_agent Improper authentication in Azure SRE Agent allows an unauthorized attacker to disclose information over a network. 0,9%
CVE-2026-31611 HIGH 8.6 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: require 3 sub-authorities before reading sub_auth[2] parse_dacl() compares each ACE SID against sid_unix_NFS_mode and on match reads sid.sub_auth[2] as the file mode. If sid_unix_NFS 0,4%
CVE-2026-27290 HIGH 8.6 adobe framemaker Adobe Framemaker versions 2022.8 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the context of the current user. If the application uses a search path to locate critical resources such 0,2%
CVE-2026-26150 HIGH 8.6 microsoft purview_ediscovery Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network. 0,6%
CVE-2026-26139 HIGH 8.6 microsoft purview Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network. 0,6%
CVE-2026-26138 HIGH 8.6 microsoft purview Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network. 0,6%
CVE-2026-26125 HIGH 8.6 microsoft payment_orchestrator_service Payment Orchestrator Service Elevation of Privilege Vulnerability 1,2%
CVE-2026-24302 HIGH 8.6 microsoft azure_arc Improper access control in Azure Arc allows an unauthorized attacker to elevate privileges over a network. 1,6%
CVE-2026-23659 HIGH 8.6 microsoft azure_data_factory Exposure of sensitive information to an unauthorized actor in Azure Data Factory allows an unauthorized attacker to disclose information over a network. 0,8%
CVE-2026-23658 HIGH 8.6 microsoft azure_devops Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a network. 0,8%
CVE-2026-23512 HIGH 8.6 sumatrapdfreader sumatrapdf SumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, there is a Untrusted Search Path vulnerability when Advanced Options setting is trigger. The application executes notepad.exe without specifying an absolute path when using the Advanced Opt 0,2%
CVE-2026-23457 HIGH 8.6 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: fix Content-Length u32 truncation in sip_help_tcp() sip_help_tcp() parses the SIP Content-Length header with simple_strtoul(), which returns unsigned long, but s 0,4%
CVE-2026-22742 HIGH 8.6 vmware spring_ai Spring AI's spring-ai-bedrock-converse contains a Server-Side Request Forgery (SSRF) vulnerability in BedrockProxyChatModel when processing multimodal messages that include user-supplied media URLs. Insufficient validation of those URLs allows an attacker to i 0,4%
CVE-2026-22739 HIGH 8.6 vmware spring_cloud_config Vulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Config Server configured to the native file system as a backend, because it was possible to access files outside of the configured search directories. 1,2%
CVE-2026-22729 HIGH 8.6 vmware spring_ai A JSONPath injection vulnerability in Spring AI's AbstractFilterExpressionConverter allows authenticated users to bypass metadata-based access controls through crafted filter expressions. User-controlled input passed to FilterExpressionBuilder is concatenated 0,5%