58.360 CVE seguite
792 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.360 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più basso | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-50453 | MED 6.1 | microsoft windows_10_1607 Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack. | 0,5% | — |
| CVE-2026-50383 | MED 6.1 | microsoft windows_10_1809 Buffer over-read in Windows Print Spooler Components allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-50229 | MED 6.1 | apache tomcat Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example for Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through | 4,1% | — |
| CVE-2026-49174 | MED 6.1 | microsoft windows_10_1809 Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. | 0,3% | — |
| CVE-2026-48361 | MED 6.1 | adobe connect Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page | 0,2% | — |
| CVE-2026-47887 | MED 6.1 | vmware spring_framework A Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and does not have a configured prefix is vulnerable to an open redirect. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6. | 0,2% | — |
| CVE-2026-47883 | MED 6.1 | vmware spring_framework UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns. The issue applies to the filter variants in both Spring MVC and Spring WebFlux. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 | 0,2% | — |
| CVE-2026-45500 | MED 6.1 | microsoft exchange_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | 0,4% | — |
| CVE-2026-45249 | MED 6.1 | apache echarts A cross-site scripting (XSS) vulnerability exists in Apache ECharts in the Lines series tooltip rendering logic. This issue affects Apache ECharts: from before 6.1.0. In versions prior to 6.1.0, if both Lines series and tooltip are used, and no user-speci | 0,7% | — |
| CVE-2026-44915 | MED 6.1 | apache apisix URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The default configuration of cas-auth in Apache APISIX is vulnerable to phishing and credential theft. This issue affects Apache APISIX: from 3.0.0 through 3.16.0. Users are | 0,6% | — |
| CVE-2026-44613 | MED 6.1 | apache zeppelin Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin. The default CORS configuration allowed cross-origin state-changing requests and accepted text/plain request bodies, allowing an attacker who lures an authenticated user to a | 0,4% | — |
| CVE-2026-42509 | MED 6.1 | apache wicket Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket. This issue affects Apache Wicket: from 8.0.0 through 8.17.0, 9.0.0, from 10.0.0 through 10.8.0. Users are recommended to upgrade to version 1 | 0,4% | — |
| CVE-2026-42253 | MED 6.1 | apache activemq Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web. The MessageServlet in the ActiveMQ web console API copies every JMS message property into an HTTP response header witho | 1,1% | — |
| CVE-2026-41706 | MED 6.1 | vmware spring_security Spring Security's CookieRequestCache and CookieServerRequestCache store the pre-authentication request URL in a browser cookie so that users can be redirected back to their intended destination after a successful login. In affected versions, the full absolute | 0,2% | — |
| CVE-2026-41008 | MED 6.1 | broadcom spring_authorization_server Spring Security Authorization Server's authorization endpoint performs insufficient validation of the request_uri parameter. An attacker can craft a malicious authorization request containing an invalid request_uri and an arbitrary, unvalidated redirect_uri, w | 0,2% | — |
| CVE-2026-40979 | MED 6.1 | vmware spring_ai In Spring AI, having access to a shared environment can expose the ONNX model used by the application. Affected versions: Spring AI: 1.0.0 - 1.0.5 (fixed in 1.0.6), 1.1.0 - 1.1.4 (fixed in 1.1.5) | 0,1% | — |
| CVE-2026-35199 | MED 6.1 | microsoft symcrypt SymCrypt is the core cryptographic function library currently used by Windows. From 103.5.0 to before 103.11.0, The SymCryptXmssSign function passes a 64-bit leaf count value to a helper function that accepts a 32-bit parameter. For XMSS^MT parameter sets with | 0,3% | — |
| CVE-2026-34614 | MED 6.1 | adobe connect Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within | 0,2% | — |
| CVE-2026-33822 | MED 6.1 | microsoft 365_apps Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-32773 | MED 6.1 | apache spark There is a lack of XSS escaping in the Spark History Server prior to 3.5.8 which allows a malicious Spark job to generate arbitrary unescaped frontend code which could lead to a minimal privilege escalation in browser. Users are encouraged to upgrade to Spark | 0,7% | — |
| CVE-2026-32196 | MED 6.1 | microsoft windows_admin_center Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network. | 0,3% | — |
| CVE-2026-32088 | MED 6.1 | microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Biometric Service allows an unauthorized attacker to bypass a security feature with a physical attack. | 0,2% | — |
| CVE-2026-31906 | MED 6.1 | apache ofbiz Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue. | 0,4% | — |
| CVE-2026-31379 | MED 6.1 | apache ofbiz Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This | 0,6% | — |
| CVE-2026-29170 | MED 6.1 | apache http_server A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via forward or reverse proxy configuration. Users are recommended to upgrade to v | 0,5% | — |