EN
57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

57.971 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordinato dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2026-69423 HIGH 8.0 microsoft windows_10_1607 Heap-based buffer overflow in Windows USB Video Driver allows an authorized attacker to elevate privileges over a network. 0,7%
CVE-2026-69412 HIGH 8.0 microsoft windows_10_1607 Stack-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over an adjacent network. 0,5%
CVE-2026-69332 HIGH 8.0 microsoft windows_10_1607 Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges over a network. 0,7%
CVE-2026-68838 HIGH 8.0 microsoft windows_10_1607 Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network. 0,4%
CVE-2026-68834 HIGH 8.0 microsoft windows_10_1607 Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network. 0,6%
CVE-2026-68827 HIGH 8.0 microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Windows GDI+ allows an authorized attacker to elevate privileges over a network. 0,4%
CVE-2026-64406 HIGH 8.0 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix UAF in bt_accept_dequeue() bt_accept_get() takes a temporary reference before dropping the accept queue lock. bt_accept_dequeue() currently drops that reference before bt_acce 0,3%
CVE-2026-62911 HIGH 8.0 microsoft exchange_server Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. 1,3%
CVE-2026-59307 HIGH 8.0 vmware spring_integration An operator who calls JdbcMessageStore.addAllowedPatterns(...) to restrict deserialization receives no protection at all when the store is a Spring-managed bean. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring 0,3%
CVE-2026-58647 HIGH 8.0 microsoft power_bi_report_server Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows an authorized attacker to perform spoofing over a network. 0,3%
CVE-2026-57105 HIGH 8.0 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 0,6%
CVE-2026-53357 HIGH 8.0 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() bt_accept_dequeue() unlinks a not-yet-accepted child from the parent accept queue and release_sock()s it before returnin 0,3%
CVE-2026-53256 HIGH 8.0 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() rfcomm_get_sock_by_channel() scans rfcomm_sk_list under the list lock, but returns the selected listener after dropping that l 0,2%
CVE-2026-50683 HIGH 8.0 microsoft windows_10_1607 Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to elevate privileges over an adjacent network. 0,6%
CVE-2026-50502 HIGH 8.0 microsoft windows_10_1607 Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network. 0,7%
CVE-2026-50365 HIGH 8.0 microsoft windows_10_1607 Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent network. 0,5%
CVE-2026-49169 HIGH 8.0 microsoft windows_server_2025 Use after free in DNS Server allows an authorized attacker to execute code over a network. 0,8%
CVE-2026-47298 HIGH 8.0 microsoft sharepoint_server Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 0,7%
CVE-2026-47294 HIGH 8.0 microsoft sharepoint_server Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 0,7%
CVE-2026-46332 HIGH 8.0 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: greybus: gb-beagleplay: bound bootloader receive buffering cc1352_bootloader_rx() appends each serdev chunk into the fixed rx_buffer before parsing bootloader packets. The helper can keep le 0,2%
CVE-2026-45644 HIGH 8.0 microsoft live_share_canvas Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Live Share Canvas SDK allows an authorized attacker to elevate privileges over a network. 0,6%
CVE-2026-42975 HIGH 8.0 microsoft windows_10_1607 Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network. 0,5%
CVE-2026-41724 HIGH 8.0 vmware aria_operations VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundat 0,3%
CVE-2026-41723 HIGH 8.0 vmware aria_operations VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundat 0,4%
CVE-2026-41722 HIGH 8.0 vmware aria_operations VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundat 0,3%