57.924 CVE seguite
784 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.924 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-7346 | HIGH 8.1 | google chrome Inappropriate implementation in Tint in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) | 0,3% | — |
| CVE-2026-73334 | HIGH 8.1 | apache parquet Potential problem for users of the org.apache.parquet.crypto.keytools package in Apache Parquet, versions 1.12 to 1.18. This package enables users to encrypt Parquet files via an envelope encryption mechanism that wraps (encrypts) data keys via a Key Manageme | 0,2% | — |
| CVE-2026-72987 | HIGH 8.1 | microsoft windows_10_1607 Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. | 0,6% | — |
| CVE-2026-71331 | HIGH 8.1 | microsoft windows_10_1809 Integer overflow or wraparound in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network. | 0,5% | — |
| CVE-2026-70563 | HIGH 8.1 | microsoft windows_10_1607 Improper link resolution before file access ('link following') in Windows Shell allows an unauthorized attacker to perform spoofing over a network. | 0,9% | — |
| CVE-2026-70468 | HIGH 8.1 | fortinet fortimanager A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7.4.3 through 7.4.5, FortiManager Cloud 7. | 0,7% | — |
| CVE-2026-70465 | HIGH 8.1 | fortinet forticlient A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.11 may allow an unauthenticated attacker in a position to alter or craft DNS respons | 0,7% | — |
| CVE-2026-70342 | HIGH 8.1 | microsoft windows_10_1607 Use after free in Windows Ancillary Function Driver for WinSock allows an unauthorized attacker to elevate privileges over a network. | 0,9% | — |
| CVE-2026-70340 | HIGH 8.1 | microsoft azure_cyclecloud Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network. | 0,6% | — |
| CVE-2026-69989 | HIGH 8.1 | microsoft windows_10_1607 Use after free in DNS Server allows an unauthorized attacker to execute code over a network. | 0,7% | — |
| CVE-2026-69858 | HIGH 8.1 | microsoft windows_server_2022 Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. | 0,7% | — |
| CVE-2026-69813 | HIGH 8.1 | microsoft windows_10_1607 Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. | 0,7% | — |
| CVE-2026-69620 | HIGH 8.1 | microsoft windows_10_1607 Stack-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network. | 0,7% | — |
| CVE-2026-69510 | HIGH 8.1 | microsoft windows_10_1607 Stack-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network. | 0,7% | — |
| CVE-2026-68745 | HIGH 8.1 | apache cloudstack Certificate validation failures in SAML authentication in Apache CloudStack 4.20.3.0 and 4.22.1.0 on all platforms allow a malicious agent to forge a SAML response to the management server. The agent will have to spoof the ip address of the IdP or get an url o | 0,1% | — |
| CVE-2026-68569 | HIGH 8.1 | apache tomcat Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm. This issue affects Apache Tomcat: from 11.0.0-M1 thr | 0,5% | — |
| CVE-2026-66802 | HIGH 8.1 | microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network. | 0,4% | — |
| CVE-2026-66422 | HIGH 8.1 | apache tomcat Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being incorrectly used as role aliases within the Realm in additional to the correct usage with Request.isUserInRole(). This issue affects Apache Tomcat: from 11.0. | 0,6% | — |
| CVE-2026-66362 | HIGH 8.1 | Description: When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the Authentication Filter Custom R | 0,3% | — |
| CVE-2026-66318 | HIGH 8.1 | microsoft edge_chromium Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | 0,2% | — |
| CVE-2026-65796 | HIGH 8.1 | microsoft windows_10_1607 Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network. | 0,5% | — |
| CVE-2026-65789 | HIGH 8.1 | microsoft windows_10_1607 Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. | 0,5% | — |
| CVE-2026-65679 | HIGH 8.1 | microsoft windows_10_1607 Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network. | 0,6% | — |
| CVE-2026-65183 | HIGH 8.1 | apache tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating unix domain sockets allows an unauthorised local user to access the unix domain socket. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10. | 0,5% | — |
| CVE-2026-65181 | HIGH 8.1 | apache impala Insufficient authorization of Data Source tables in Impala 2.7-4.5 allows a client with privileges to upload a file to remote storage and create a table to execute arbitrary Java code. Users are recommended to upgrade to version 4.5.2, which fixes this issue. | 0,4% | — |