57.588 CVE seguite
783 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.588 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-47906 | HIGH 8.6 | adobe dreamweaver Dreamweaver Desktop versions 21.7 and earlier are affected by a Dependency on Vulnerable Third-Party Component vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction | 0,2% | — |
| CVE-2026-47835 | HIGH 8.6 | vmware spring_ai In Spring AI Vector Stores, special characters could be used to force the execution of arbitrary queries in Elasticsearch, OpenSearch, and GemFire VectorDB. Affected components: spring-ai-elasticsearch-store, spring-ai-opensearch-store, spring-ai-gemfire-store | 0,3% | — |
| CVE-2026-46273 | HIGH 8.6 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ibmveth: Disable GSO for packets with small MSS Some physical adapters on Power systems do not support segmentation offload when the MSS is less than 224 bytes. Attempting to send such packe | 0,4% | — |
| CVE-2026-45169 | HIGH 8.6 | paloaltonetworks idira_privileged_access_manager_vault Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a validation vulnerability. Under specific circumstances and configuration scenarios, processing unexpected input could potentially lead to an | 0,4% | — |
| CVE-2026-43139 | HIGH 8.6 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: xfrm6: fix uninitialized saddr in xfrm6_get_saddr() xfrm6_get_saddr() does not check the return value of ipv6_dev_get_saddr(). When ipv6_dev_get_saddr() fails to find a suitable source addre | 0,4% | — |
| CVE-2026-41705 | HIGH 8.6 | vmware spring_ai Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injection via unsanitized document IDs. Spring AI 1.0.x: affected from 1.0.0 through latest 1.0.x; upgrade to 1.0.7 or greater. Spring AI 1.1.x: affected from 1.1.0 | 0,4% | — |
| CVE-2026-40967 | HIGH 8.6 | vmware spring_ai In Spring AI, various FilterExpressionConverter implementations accept a filter expression object and translate them to specific vector store query languages. In several cases, keys and values are not properly escaped, leading to the ability to alter the query | 0,4% | — |
| CVE-2026-35435 | HIGH 8.6 | microsoft azure_ai_foundry Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network. | 1,2% | — |
| CVE-2026-34622 | HIGH 8.6 | adobe acrobat Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary code execution in the context | 0,4% | — |
| CVE-2026-34621 | HIGH 8.6 | adobe acrobat Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary code execution in the context of the curren | 7,1% | |
| CVE-2026-32173 | HIGH 8.6 | microsoft azure_sre_agent Improper authentication in Azure SRE Agent allows an unauthorized attacker to disclose information over a network. | 0,9% | — |
| CVE-2026-31611 | HIGH 8.6 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: require 3 sub-authorities before reading sub_auth[2] parse_dacl() compares each ACE SID against sid_unix_NFS_mode and on match reads sid.sub_auth[2] as the file mode. If sid_unix_NFS | 0,4% | — |
| CVE-2026-27290 | HIGH 8.6 | adobe framemaker Adobe Framemaker versions 2022.8 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the context of the current user. If the application uses a search path to locate critical resources such | 0,2% | — |
| CVE-2026-26150 | HIGH 8.6 | microsoft purview_ediscovery Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network. | 0,6% | — |
| CVE-2026-26139 | HIGH 8.6 | microsoft purview Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network. | 0,6% | — |
| CVE-2026-26138 | HIGH 8.6 | microsoft purview Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network. | 0,6% | — |
| CVE-2026-26125 | HIGH 8.6 | microsoft payment_orchestrator_service Payment Orchestrator Service Elevation of Privilege Vulnerability | 1,2% | — |
| CVE-2026-24302 | HIGH 8.6 | microsoft azure_arc Improper access control in Azure Arc allows an unauthorized attacker to elevate privileges over a network. | 1,6% | — |
| CVE-2026-23659 | HIGH 8.6 | microsoft azure_data_factory Exposure of sensitive information to an unauthorized actor in Azure Data Factory allows an unauthorized attacker to disclose information over a network. | 0,8% | — |
| CVE-2026-23658 | HIGH 8.6 | microsoft azure_devops Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a network. | 0,8% | — |
| CVE-2026-23512 | HIGH 8.6 | sumatrapdfreader sumatrapdf SumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, there is a Untrusted Search Path vulnerability when Advanced Options setting is trigger. The application executes notepad.exe without specifying an absolute path when using the Advanced Opt | 0,2% | — |
| CVE-2026-23457 | HIGH 8.6 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: fix Content-Length u32 truncation in sip_help_tcp() sip_help_tcp() parses the SIP Content-Length header with simple_strtoul(), which returns unsigned long, but s | 0,4% | — |
| CVE-2026-22742 | HIGH 8.6 | vmware spring_ai Spring AI's spring-ai-bedrock-converse contains a Server-Side Request Forgery (SSRF) vulnerability in BedrockProxyChatModel when processing multimodal messages that include user-supplied media URLs. Insufficient validation of those URLs allows an attacker to i | 0,4% | — |
| CVE-2026-22739 | HIGH 8.6 | vmware spring_cloud_config Vulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Config Server configured to the native file system as a backend, because it was possible to access files outside of the configured search directories. | 1,2% | — |
| CVE-2026-22729 | HIGH 8.6 | vmware spring_ai A JSONPath injection vulnerability in Spring AI's AbstractFilterExpressionConverter allows authenticated users to bypass metadata-based access controls through crafted filter expressions. User-controlled input passed to FilterExpressionBuilder is concatenated | 0,5% | — |