EN
57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

57.971 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordinato dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2026-81947 HIGH 7.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0,3%
CVE-2026-81398 HIGH 7.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0,3%
CVE-2026-81397 HIGH 7.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0,4%
CVE-2026-81396 HIGH 7.8 microsoft 365_apps Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0,4%
CVE-2026-81388 HIGH 7.8 microsoft 365_apps Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0,4%
CVE-2026-81386 HIGH 7.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0,3%
CVE-2026-81353 HIGH 7.8 microsoft heif_image_extension Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code locally. 0,4%
CVE-2026-80161 HIGH 7.8 adobe acrobat Acrobat Reader is affected by an Access of Resource Using Incompatible Type ('Type Confusion') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary cod 0,2%
CVE-2026-80075 HIGH 7.8 microsoft windows_10_21h2 Heap-based buffer overflow in Windows Work Folders allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-7994 HIGH 7.8 google chrome Inappropriate implementation in Chromoting in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Medium) 0,1%
CVE-2026-79909 HIGH 7.8 adobe acrobat Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. 0,2%
CVE-2026-79908 HIGH 7.8 adobe acrobat Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. 0,2%
CVE-2026-79907 HIGH 7.8 adobe acrobat Acrobat Reader is affected by a Double Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. 0,2%
CVE-2026-7990 HIGH 7.8 google chrome Insufficient validation of untrusted input in Updater in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Medium) 0,1%
CVE-2026-7925 HIGH 7.8 google chrome Use after free in Chromoting in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High) 0,1%
CVE-2026-78604 HIGH 7.8 elastic elastic_agent Incorrect Permission Assignment for Critical Resource (CWE-732) in Elastic Agent can lead to local privilege escalation via Replace Binaries (CAPEC-642). On Windows systems where Elastic Agent is installed in unprivileged mode, resources used by the agent serv 0,1%
CVE-2026-78448 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. 0,2%
CVE-2026-78447 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. 0,2%
CVE-2026-77904 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an authorized attacker to elevate privileges locally. 0,2%
CVE-2026-77500 HIGH 7.8 microsoft windows_10_1607 Release of invalid pointer or reference in Windows Device Association Service allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-77489 HIGH 7.8 microsoft windows_10_1607 Null pointer dereference in Windows Biometric Service allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-7639 HIGH 7.8 imaginationtech ddk Software installed and run as a non-privileged user may conduct a sequence of improper GPU system calls causing use after free, which helps in facilitating unprivileged memory access from a shader code. Triggering failure path in the MMU mapping logic by a 0,2%
CVE-2026-75863 HIGH 7.8 adobe photoshop Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. 0,2%
CVE-2026-75862 HIGH 7.8 adobe photoshop Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. 0,2%
CVE-2026-75771 HIGH 7.8 adobe photoshop Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. 0,2%