58.450 CVE seguite
792 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.450 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più basso | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-1999-0700 | MED 6.2 | microsoft windows_2000 Buffer overflow in Microsoft Phone Dialer (dialer.exe), via a malformed dialer entry in the dialer.ini file. | 2,9% | — |
| CVE-2026-9989 | MED 6.3 | google chrome Inappropriate implementation in Media in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to bypass same origin policy via a crafted video file. (Chromium security severity: High) | 0,2% | — |
| CVE-2026-81997 | MED 6.3 | adobe acrobat Acrobat Reader is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue requ | 0,2% | — |
| CVE-2026-8010 | MED 6.3 | google chrome Insufficient validation of untrusted input in SiteIsolation in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Low) | 0,2% | — |
| CVE-2026-7977 | MED 6.3 | google chrome Inappropriate implementation in Canvas in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium) | 0,2% | — |
| CVE-2026-7971 | MED 6.3 | google chrome Inappropriate implementation in ORB in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium) | 0,2% | — |
| CVE-2026-59322 | MED 6.3 | vmware spring_integration The EmbeddedHeadersJsonMessageMapper defaults to an overly permissive header parsing posture in its constructor. When decodeNativeFormat processes raw byte payloads, it deserializes embedded JSON headers into a plain Map and constructs a GenericMessage with Mu | 0,3% | — |
| CVE-2026-58543 | MED 6.3 | microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges with a physical attack. | 0,2% | — |
| CVE-2026-57973 | MED 6.3 | microsoft windows_subsystem_for_linux Time-of-check time-of-use (toctou) race condition in Windows Subsystem for Linux allows an authorized attacker to perform tampering locally. | 0,2% | — |
| CVE-2026-55145 | MED 6.3 | microsoft copilot Improper neutralization of special elements used in a command ('command injection') in Outlook Copilot allows an authorized attacker to perform tampering over a network. | 0,5% | — |
| CVE-2026-5273 | MED 6.3 | google chrome Use after free in CSS in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | 0,2% | — |
| CVE-2026-50544 | MED 6.3 | NortheBridge/luminalshine is a Sunshine-compatible game stream host for Moonlight. Prior to version 26.05.0-rc4, a latent gap exists on a default install, the file at `src/platform/windows/misc.cpp` lives at `C:\ProgramData\LuminalShine\config\apps.json` and i | 0,1% | — |
| CVE-2026-50375 | MED 6.3 | microsoft windows_10_1809 Heap-based buffer overflow in Windows DirectX allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-50374 | MED 6.3 | microsoft windows_10_1809 Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges with a physical attack. | 0,3% | — |
| CVE-2026-47910 | MED 6.3 | adobe dreamweaver Dreamweaver Desktop versions 21.7 and earlier are affected by an Incorrect Authorization vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended ac | 0,2% | — |
| CVE-2026-47909 | MED 6.3 | adobe dreamweaver Dreamweaver Desktop versions 21.7 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended | 0,3% | — |
| CVE-2026-47861 | MED 6.3 | vmware spring_integration An unauthenticated remote attacker who can send a single UDP packet to a Spring Integration UDP inbound adapter can cause the server to emit an outbound UDP datagram to an arbitrary internal or external host and port of the attacker's choosing. Spring Integrat | 0,3% | — |
| CVE-2026-47856 | MED 6.3 | vmware spring_integration Spring Integration's JSON to object conversion uses the json__TypeId__ header to choose the deserialization target type, and resolves that header value to a class with ClassUtils.forName and no type/package allow-list. Spring Integration 7.1.0 Spring Integrati | 0,3% | — |
| CVE-2026-44911 | MED 6.3 | apache nifi Authorization handling for component configuration verification requests in Apache NiFi 1.15.0 through 2.9.0 allows clients with read access to submit proposed configuration properties. The proposed properties override current configuration, enabling users wit | 0,5% | — |
| CVE-2026-41610 | MED 6.3 | microsoft visual_studio_code Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | 0,7% | — |
| CVE-2026-34626 | MED 6.3 | adobe acrobat Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary file system read in the conte | 0,6% | — |
| CVE-2026-28712 | MED 6.3 | acronis cyber_protect Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect 17 (Windows) before build 41186. | 0,1% | — |
| CVE-2026-28711 | MED 6.3 | acronis cyber_protect Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect 17 (Windows) before build 41186. | 0,1% | — |
| CVE-2026-27299 | MED 6.3 | adobe framemaker Adobe Framemaker versions 2022.8 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read. An attacker could leverage this vulnerability to access sensitive files or data on the system. Exploitation o | 0,3% | — |
| CVE-2026-20220 | MED 6.3 | cisco crosswork_network_controller A vulnerability in the web-based management interface of Cisco Crosswork Network Controller could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. This vulnerability is due to insufficient input validation in | 0,3% | — |