EN
57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

57.971 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordinato dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2026-40400 HIGH 8.0 microsoft windows_10_1607 Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network. 0,9%
CVE-2026-40368 HIGH 8.0 microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 2,0%
CVE-2026-35425 HIGH 8.0 microsoft azure_api_management Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network. 0,5%
CVE-2026-34693 HIGH 8.0 adobe experience_manager Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevat 0,3%
CVE-2026-34332 HIGH 8.0 microsoft windows_server_2025 Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to execute code over a network. 0,5%
CVE-2026-33826 HIGH 8.0 microsoft windows_server_2012 Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network. 0,5%
CVE-2026-32172 HIGH 8.0 microsoft power_apps Uncontrolled search path element in Microsoft Power Apps allows an unauthorized attacker to execute code over a network. 0,3%
CVE-2026-27912 HIGH 8.0 microsoft windows_server_2012 Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over an adjacent network. 0,4%
CVE-2026-26111 HIGH 8.0 microsoft windows_server_2012 Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. 0,8%
CVE-2026-25173 HIGH 8.0 microsoft windows_10_1607 Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. 0,9%
CVE-2026-25172 HIGH 8.0 microsoft windows_server_2012 Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. 0,9%
CVE-2026-22720 HIGH 8.0 vmware aria_operations VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with privileges to create custom benchmarks may be able to inject script to perform administrative actions in VMware Aria Operations.  To remediate CVE-2026-22720, 0,4%
CVE-2026-21523 HIGH 8.0 microsoft visual_studio_code Time-of-check time-of-use (toctou) race condition in GitHub Copilot and Visual Studio allows an authorized attacker to execute code over a network. 0,8%
CVE-2026-21257 HIGH 8.0 microsoft visual_studio_2022 Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an authorized attacker to elevate privileges over a network. 0,9%
CVE-2026-21229 HIGH 8.0 microsoft power_bi_report_server Improper input validation in Power BI allows an authorized attacker to execute code over a network. 0,9%
CVE-2026-20960 HIGH 8.0 microsoft power_apps Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network. 0,5%
CVE-2026-20931 HIGH 8.0 microsoft windows_10_1607 External control of file name or path in Windows Telephony Service allows an authorized attacker to elevate privileges over an adjacent network. 0,9%
CVE-2026-20155 HIGH 8.0 cisco evolved_programmable_network_manager A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker with low privileges to access sensitive information that they are not authorized to access. This vulnera 0,3%
CVE-2026-11241 HIGH 8.0 google chrome Insufficient validation of untrusted input in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low) 0,1%
CVE-2025-66467 HIGH 8.0 apache cloudstack Missing MinIO policy cleanup on bucket deletion via Apache CloudStack allows users to retain access to buckets which they previously owned. If another user creates a new bucket with the same name, the previous owners can gain unauthorized read and write access 0,4%
CVE-2025-64660 HIGH 8.0 microsoft visual_studio_code Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to execute code over a network. 0,6%
CVE-2025-62452 HIGH 8.0 microsoft windows_10_1607 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. 0,8%
CVE-2025-62204 HIGH 8.0 microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 2,1%
CVE-2025-60715 HIGH 8.0 microsoft windows_10_1607 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. 0,8%
CVE-2025-53786 HIGH 8.0 microsoft exchange_server On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. Microsoft made these changes in the general interest of improving the security of hybrid Exchange deployments. Following furt 7,4%