57.921 CVE seguite
783 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.921 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-7352 | HIGH 8.3 | google chrome Use after free in Media in Google Chrome on Android prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 0,3% | — |
| CVE-2026-7350 | HIGH 8.3 | google chrome Use after free in WebMIDI in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 0,3% | — |
| CVE-2026-7345 | HIGH 8.3 | google chrome Insufficient validation of untrusted input in Feedback in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Hig | 0,3% | — |
| CVE-2026-72970 | HIGH 8.3 | microsoft edge_chromium Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0,5% | — |
| CVE-2026-69646 | HIGH 8.3 | microsoft skype_for_business_server Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perform spoofing over an adjacent network. | 0,2% | — |
| CVE-2026-6921 | HIGH 8.3 | google chrome Race in GPU in Google Chrome on Windows prior to 147.0.7727.117 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: Medium) | 0,2% | — |
| CVE-2026-6314 | HIGH 8.3 | google chrome Out of bounds write in GPU in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the GPU process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 0,3% | — |
| CVE-2026-6311 | HIGH 8.3 | google chrome Uninitialized Use in Accessibility in Google Chrome on Windows prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 0,3% | — |
| CVE-2026-6310 | HIGH 8.3 | google chrome Use after free in Dawn in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 0,3% | — |
| CVE-2026-6309 | HIGH 8.3 | google chrome Use after free in Viz in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 0,3% | — |
| CVE-2026-6304 | HIGH 8.3 | google chrome Use after free in Graphite in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 0,3% | — |
| CVE-2026-6297 | HIGH 8.3 | google chrome Use after free in Proxy in Google Chrome prior to 147.0.7727.101 allowed an attacker in a privileged network position to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | 0,2% | — |
| CVE-2026-58596 | HIGH 8.3 | microsoft edge_chromium Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network. | 0,6% | — |
| CVE-2026-58295 | HIGH 8.3 | microsoft edge_chromium Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network. | 0,5% | — |
| CVE-2026-58288 | HIGH 8.3 | microsoft edge_chromium Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0,6% | — |
| CVE-2026-58287 | HIGH 8.3 | microsoft edge_chromium Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0,6% | — |
| CVE-2026-58285 | HIGH 8.3 | microsoft edge_chromium Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0,6% | — |
| CVE-2026-58284 | HIGH 8.3 | microsoft edge_chromium Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0,6% | — |
| CVE-2026-58281 | HIGH 8.3 | microsoft edge_chromium Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 1,0% | — |
| CVE-2026-58153 | HIGH 8.3 | apache traffic_server Apache Traffic Server forwards HTTP/2 origin trailers to HTTP/1 clients without proper chunked framing when converting HTTP/2 to HTTP/1. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 | 0,5% | — |
| CVE-2026-56181 | HIGH 8.3 | microsoft windows_11_24h2 Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network. | 0,3% | — |
| CVE-2026-56179 | HIGH 8.3 | microsoft windows_11_24h2 Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network. | 0,2% | — |
| CVE-2026-55723 | HIGH 8.3 | f5 nginx_ingress_controller When NGINX Ingress Controller is configured with Custom Resource Definitions (CRDs) or Ingress annotations, an injection vulnerability exists in the configuration generator of NGINX Ingress Controller. Multiple user-controllable fields are written into the gen | 0,5% | — |
| CVE-2026-52920 | HIGH 8.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_policy: fix strict mode inbound policy matching match_policy_in() walks sec_path entries from the last transform to the first one, but strict policy matching needs to consume i | 0,3% | — |
| CVE-2026-50521 | HIGH 8.3 | microsoft edge_chromium Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network. | 0,5% | — |