58.462 CVE seguite
793 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.462 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più basso | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-1999-0074 | MED 6.4 | freebsd freebsd Listening TCP ports are sequentially allocated, allowing spoofing attacks. | 8,3% | — |
| CVE-2026-9981 | MED 6.5 | google chrome Inappropriate implementation in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High) | 0,3% | — |
| CVE-2026-9953 | MED 6.5 | google chrome Out of bounds read in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High) | 0,3% | — |
| CVE-2026-9882 | MED 6.5 | google chrome Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Critical) | 0,3% | — |
| CVE-2026-9639 | MED 6.5 | canonical lxd Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticated user with can_create_storage_volumes permissions to cause a denial of service via a specially crafted custom-volume backup tarball that o | 0,5% | — |
| CVE-2026-9262 | MED 6.5 | canon eos_network_setting_tool Use of a non-secure protocol as the default FTP configuration in Canon EOS Network Setting Tool Version 1.5.0 or earlier | 0,5% | — |
| CVE-2026-9259 | MED 6.5 | canon eos_network_setting_tool Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier | 0,3% | — |
| CVE-2026-9258 | MED 6.5 | canon eos_network_setting_tool Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier | 0,5% | — |
| CVE-2026-9186 | MED 6.5 | langflow langflow IBM Langflow OSS 1.0.0 through 1.11.2 allows remote authenticated attackers to bypass localhost-only MCP configuration installation by spoofing X-Forwarded-For: 127.0.0.1 header, enabling arbitrary writes to IDE config files (~/.cursor/mcp.json, etc.). | 0,4% | — |
| CVE-2026-9153 | MED 6.5 | gnu sed Arbitrary File Read vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to read arbitrary files via the expression parameter due to insufficient input validation. | 0,5% | — |
| CVE-2026-9138 | MED 6.5 | langflow langflow IBM Langflow OSS 1.0.0 through 1.11.2 Langflow could allow an authenticated attacker to write arbitrary files to the server due to improper input validation in the SaveToFileComponent. The application constructs local file paths using attacker‑controlled input | 0,4% | — |
| CVE-2026-87454 | MED 6.5 | google chrome Information leak in Enterprise in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | 0,3% | — |
| CVE-2026-86465 | MED 6.5 | apache apache-airflow-providers-akeyless Apache Airflow Akeyless provider: the Akeyless secrets backend's team-scope guard can be bypassed with a user-controlled key. In a multi-team deployment, a Dag author scoped to one team can supply a Variable key containing a path separator that causes the back | 0,8% | — |
| CVE-2026-8550 | MED 6.5 | google chrome Use after free in Google Lens in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High | 0,3% | — |
| CVE-2026-82561 | MED 6.5 | apache nifi Apache NiFi 1.5.0 through 2.11.0 provide REST API methods that replace the entire contents of a Process Group using a client-supplied flow definition, covering Process Group flow replacement together with versioned flow update and rebase operations. Framework | 0,5% | — |
| CVE-2026-82434 | MED 6.5 | Description When ZooKeeper authentication is configured, Storm deliberately retains `storm.zookeeper.topology.auth.payload` in the topology configuration, because workers need it. Nimbus then served that configuration verbatim to any caller holding read-only | 0,5% | — |
| CVE-2026-82433 | MED 6.5 | Description `getNimbusConf` returned the complete daemon configuration without redaction after only a user-level authorization check. Where the cluster is configured with them, that response includes `storm.zookeeper.auth.payload` and the keystore and trustst | 0,4% | — |
| CVE-2026-82426 | MED 6.5 | Description Nimbus accepted the `uploadedJarLocation` argument of `submitTopology` / `submitTopologyWithOpts` as a server-side path and opened it directly, without checking that it referred to a file the caller had actually uploaded. The intended flow is that | 0,5% | — |
| CVE-2026-81381 | MED 6.5 | microsoft visual_studio_code Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network. | 0,6% | — |
| CVE-2026-81377 | MED 6.5 | microsoft visual_studio_code Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to perform tampering over a network. | 0,8% | — |
| CVE-2026-80091 | MED 6.5 | microsoft 365_apps Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information over a network. | 0,9% | — |
| CVE-2026-80090 | MED 6.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. | 0,9% | — |
| CVE-2026-80089 | MED 6.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network. | 0,9% | — |
| CVE-2026-80088 | MED 6.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. | 0,9% | — |
| CVE-2026-80087 | MED 6.5 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to disclose information over a network. | 0,9% | — |