EN
58.462 CVE seguite
793 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.462 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordinato dal più basso Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-1999-0074 MED 6.4 freebsd freebsd Listening TCP ports are sequentially allocated, allowing spoofing attacks. 8,3% —
CVE-2026-9981 MED 6.5 google chrome Inappropriate implementation in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High) 0,3% —
CVE-2026-9953 MED 6.5 google chrome Out of bounds read in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High) 0,3% —
CVE-2026-9882 MED 6.5 google chrome Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Critical) 0,3% —
CVE-2026-9639 MED 6.5 canonical lxd Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticated user with can_create_storage_volumes permissions to cause a denial of service via a specially crafted custom-volume backup tarball that o 0,5% —
CVE-2026-9262 MED 6.5 canon eos_network_setting_tool Use of a non-secure protocol as the default FTP configuration in Canon EOS Network Setting Tool Version 1.5.0 or earlier 0,5% —
CVE-2026-9259 MED 6.5 canon eos_network_setting_tool Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier 0,3% —
CVE-2026-9258 MED 6.5 canon eos_network_setting_tool Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier 0,5% —
CVE-2026-9186 MED 6.5 langflow langflow IBM Langflow OSS 1.0.0 through 1.11.2 allows remote authenticated attackers to bypass localhost-only MCP configuration installation by spoofing X-Forwarded-For: 127.0.0.1 header, enabling arbitrary writes to IDE config files (~/.cursor/mcp.json, etc.). 0,4% —
CVE-2026-9153 MED 6.5 gnu sed Arbitrary File Read vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to read arbitrary files via the expression parameter due to insufficient input validation. 0,5% —
CVE-2026-9138 MED 6.5 langflow langflow IBM Langflow OSS 1.0.0 through 1.11.2 Langflow could allow an authenticated attacker to write arbitrary files to the server due to improper input validation in the SaveToFileComponent. The application constructs local file paths using attacker‑controlled input 0,4% —
CVE-2026-87454 MED 6.5 google chrome Information leak in Enterprise in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) 0,3% —
CVE-2026-86465 MED 6.5 apache apache-airflow-providers-akeyless Apache Airflow Akeyless provider: the Akeyless secrets backend's team-scope guard can be bypassed with a user-controlled key. In a multi-team deployment, a Dag author scoped to one team can supply a Variable key containing a path separator that causes the back 0,8% —
CVE-2026-8550 MED 6.5 google chrome Use after free in Google Lens in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High 0,3% —
CVE-2026-82561 MED 6.5 apache nifi Apache NiFi 1.5.0 through 2.11.0 provide REST API methods that replace the entire contents of a Process Group using a client-supplied flow definition, covering Process Group flow replacement together with versioned flow update and rebase operations. Framework 0,5% —
CVE-2026-82434 MED 6.5 Description When ZooKeeper authentication is configured, Storm deliberately retains `storm.zookeeper.topology.auth.payload` in the topology configuration, because workers need it. Nimbus then served that configuration verbatim to any caller holding read-only 0,5% —
CVE-2026-82433 MED 6.5 Description `getNimbusConf` returned the complete daemon configuration without redaction after only a user-level authorization check. Where the cluster is configured with them, that response includes `storm.zookeeper.auth.payload` and the keystore and trustst 0,4% —
CVE-2026-82426 MED 6.5 Description Nimbus accepted the `uploadedJarLocation` argument of `submitTopology` / `submitTopologyWithOpts` as a server-side path and opened it directly, without checking that it referred to a file the caller had actually uploaded. The intended flow is that 0,5% —
CVE-2026-81381 MED 6.5 microsoft visual_studio_code Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network. 0,6% —
CVE-2026-81377 MED 6.5 microsoft visual_studio_code Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to perform tampering over a network. 0,8% —
CVE-2026-80091 MED 6.5 microsoft 365_apps Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information over a network. 0,9% —
CVE-2026-80090 MED 6.5 microsoft 365_apps Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. 0,9% —
CVE-2026-80089 MED 6.5 microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network. 0,9% —
CVE-2026-80088 MED 6.5 microsoft 365_apps Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. 0,9% —
CVE-2026-80087 MED 6.5 microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to disclose information over a network. 0,9% —