57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.971 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-40400 | HIGH 8.0 | microsoft windows_10_1607 Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network. | 0,9% | — |
| CVE-2026-40368 | HIGH 8.0 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 2,0% | — |
| CVE-2026-35425 | HIGH 8.0 | microsoft azure_api_management Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network. | 0,5% | — |
| CVE-2026-34693 | HIGH 8.0 | adobe experience_manager Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevat | 0,3% | — |
| CVE-2026-34332 | HIGH 8.0 | microsoft windows_server_2025 Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to execute code over a network. | 0,5% | — |
| CVE-2026-33826 | HIGH 8.0 | microsoft windows_server_2012 Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network. | 0,5% | — |
| CVE-2026-32172 | HIGH 8.0 | microsoft power_apps Uncontrolled search path element in Microsoft Power Apps allows an unauthorized attacker to execute code over a network. | 0,3% | — |
| CVE-2026-27912 | HIGH 8.0 | microsoft windows_server_2012 Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over an adjacent network. | 0,4% | — |
| CVE-2026-26111 | HIGH 8.0 | microsoft windows_server_2012 Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. | 0,8% | — |
| CVE-2026-25173 | HIGH 8.0 | microsoft windows_10_1607 Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. | 0,9% | — |
| CVE-2026-25172 | HIGH 8.0 | microsoft windows_server_2012 Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. | 0,9% | — |
| CVE-2026-22720 | HIGH 8.0 | vmware aria_operations VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with privileges to create custom benchmarks may be able to inject script to perform administrative actions in VMware Aria Operations. To remediate CVE-2026-22720, | 0,4% | — |
| CVE-2026-21523 | HIGH 8.0 | microsoft visual_studio_code Time-of-check time-of-use (toctou) race condition in GitHub Copilot and Visual Studio allows an authorized attacker to execute code over a network. | 0,8% | — |
| CVE-2026-21257 | HIGH 8.0 | microsoft visual_studio_2022 Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an authorized attacker to elevate privileges over a network. | 0,9% | — |
| CVE-2026-21229 | HIGH 8.0 | microsoft power_bi_report_server Improper input validation in Power BI allows an authorized attacker to execute code over a network. | 0,9% | — |
| CVE-2026-20960 | HIGH 8.0 | microsoft power_apps Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network. | 0,5% | — |
| CVE-2026-20931 | HIGH 8.0 | microsoft windows_10_1607 External control of file name or path in Windows Telephony Service allows an authorized attacker to elevate privileges over an adjacent network. | 0,9% | — |
| CVE-2026-20155 | HIGH 8.0 | cisco evolved_programmable_network_manager A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker with low privileges to access sensitive information that they are not authorized to access. This vulnera | 0,3% | — |
| CVE-2026-11241 | HIGH 8.0 | google chrome Insufficient validation of untrusted input in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low) | 0,1% | — |
| CVE-2025-66467 | HIGH 8.0 | apache cloudstack Missing MinIO policy cleanup on bucket deletion via Apache CloudStack allows users to retain access to buckets which they previously owned. If another user creates a new bucket with the same name, the previous owners can gain unauthorized read and write access | 0,4% | — |
| CVE-2025-64660 | HIGH 8.0 | microsoft visual_studio_code Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to execute code over a network. | 0,6% | — |
| CVE-2025-62452 | HIGH 8.0 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. | 0,8% | — |
| CVE-2025-62204 | HIGH 8.0 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 2,1% | — |
| CVE-2025-60715 | HIGH 8.0 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. | 0,8% | — |
| CVE-2025-53786 | HIGH 8.0 | microsoft exchange_server On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. Microsoft made these changes in the general interest of improving the security of hybrid Exchange deployments. Following furt | 7,4% | — |