57.924 CVE seguite
784 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.924 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2016-1182 | HIGH 8.2 | apache struts ActionServlet.java in Apache Struts 1 1.x through 1.3.10 does not properly restrict the Validator configuration, which allows remote attackers to conduct cross-site scripting (XSS) attacks or cause a denial of service via crafted input, a related issue to CVE- | 25,7% | — |
| CVE-2015-2546 | HIGH 8.2 | ransomware microsoft windows_10_1507 The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted appli | 10,2% | |
| CVE-1999-0468 | HIGH 8.2 | microsoft internet_explorer Internet Explorer 5.0 allows a remote server to read arbitrary files on the client's file system using the Microsoft Scriptlet Component. | 3,2% | — |
| CVE-2026-9256 | HIGH 8.1 | debian debian_linux NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/( | 10,9% | — |
| CVE-2026-8855 | HIGH 8.1 | ibm http_server IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial of service in configurations with TLS mutual authentication (client authentication). | 0,5% | — |
| CVE-2026-87554 | HIGH 8.1 | google chrome Race condition in Chromoting in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High) | 0,1% | — |
| CVE-2026-87530 | HIGH 8.1 | google chrome Uncontrolled search path element in CredentialProvider in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium) | 0,1% | — |
| CVE-2026-87509 | HIGH 8.1 | google chrome Incorrect authorization in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Low) | 0,1% | — |
| CVE-2026-87467 | HIGH 8.1 | google chrome Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High) | 0,1% | — |
| CVE-2026-87457 | HIGH 8.1 | google chrome Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium) | 0,1% | — |
| CVE-2026-8711 | HIGH 8.1 | f5 njs NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-controlled NGINX variable (for example, $http_*, $arg_*, $cookie_*) and a location invoking the ngx.fetch() operation from NGINX JavaScript. An unauth | 9,7% | — |
| CVE-2026-86466 | HIGH 8.1 | Apache Airflow FAB provider: the Authentik OAuth path in the FAB auth manager does not validate the issuer or audience claims of the id_token it accepts. An attacker holding a token that the same Authentik identity provider minted for a different client applic | 0,1% | — |
| CVE-2026-84334 | HIGH 8.1 | google chrome Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.75 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium) | 0,1% | — |
| CVE-2026-83997 | HIGH 8.1 | microsoft windows_10_21h2 Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network. | 0,5% | — |
| CVE-2026-82438 | HIGH 8.1 | Description Three separate mechanisms allowed a web page on an unrelated origin to read responses that Storm's HTTP components served to an authenticated user. The Logviewer reflected the request's `Origin` header back in `Access-Control-Allow-Origin` while | 0,2% | — |
| CVE-2026-82432 | HIGH 8.1 | Description Nimbus validated `topology.blobstore.map` against the calling subject at submission time only. The rebalance operation accepts configuration overrides and stripped a small set of keys from them, but never re-ran that validation, so a caller author | 0,3% | — |
| CVE-2026-80354 | HIGH 8.1 | apache camel Authorization bypass through User-Controlled key vulnerability in Apache Camel K. An authorization vulnerability in custom resource resolution allows a tenant to reference secrets by name in the operator namespace, potentially exposing secrets belonging to | 0,2% | — |
| CVE-2026-8018 | HIGH 8.1 | google chrome Insufficient policy enforcement in DevTools in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: Low) | 0,3% | — |
| CVE-2026-7981 | HIGH 8.1 | google chrome Out of bounds read in Codecs in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to obtain potentially sensitive information from process memory via a malicious file. (Chromium security severity: Medium) | 0,2% | — |
| CVE-2026-79194 | HIGH 8.1 | google chrome Use after free in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High) | 0,5% | — |
| CVE-2026-78689 | HIGH 8.1 | Description NGINX JavaScript (njs) has a vulnerability in the XML module's namespace prefix list parser, reachable through the xml.exclusiveC14n() method. An unauthenticated remote attacker can trigger it when an affected NGINX configuration passes an extern | 0,5% | — |
| CVE-2026-78450 | HIGH 8.1 | microsoft windows_10_1809 Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network. | 0,5% | — |
| CVE-2026-78444 | HIGH 8.1 | microsoft windows_10_1809 Untrusted pointer dereference in Windows Failover Cluster allows an unauthorized attacker to execute code over a network. | 0,5% | — |
| CVE-2026-75020 | HIGH 8.1 | apache apisix Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache APISIX. A caller who holds valid credentials for one entry in the LDAP directory can authenticate through APISIX as a consumer mapped to a different e | 0,5% | — |
| CVE-2026-7347 | HIGH 8.1 | google chrome Use after free in Chromoting in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: High) | 0,5% | — |