58.462 CVE seguite
793 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.462 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più basso | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-69395 | MED 6.5 | microsoft windows_10_1607 Use of externally-controlled format string in Active Directory Certificate Services (AD CS) allows an authorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2026-6938 | MED 6.5 | ibm db2 IBM Db2 12.1.0 through 12.1.4 is vulnerable to authorization bypass when uploading to a remote object storage path with a special query. | 0,3% | — |
| CVE-2026-69375 | MED 6.5 | microsoft exchange_server Authorization bypass through user-controlled key in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network. | 0,7% | — |
| CVE-2026-69374 | MED 6.5 | microsoft windows_10_21h2 Allocation of resources without limits or throttling in Windows SMB Server allows an authorized attacker to deny service over a network. | 1,1% | — |
| CVE-2026-69361 | MED 6.5 | microsoft exchange_server Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network. | 0,9% | — |
| CVE-2026-69297 | MED 6.5 | microsoft windows_10_1607 Storing passwords in a recoverable format in Windows DHCP Server allows an authorized attacker to disclose information over a network. | 0,8% | — |
| CVE-2026-69267 | MED 6.5 | microsoft windows_10_1809 Insufficient granularity of access control in Windows Connected User Experiences and Telemetry allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-68971 | MED 6.5 | apache airflow Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check on `wait_dag_run_until_finished` authorized the target Dag without its team, unlike every other authorization site. A team-aware auth manag | 0,3% | — |
| CVE-2026-68970 | MED 6.5 | apache airflow Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that shape appeared in cleartext in task logs and in the Rendered Templates UI. Masking was applied only when the deserialized value was a string | 0,2% | — |
| CVE-2026-68969 | MED 6.5 | apache airflow Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoints (`PATCH /api/v2/variables` and `PATCH /api/v2/connections`). The audit-log masking recognised only top-level | 0,4% | — |
| CVE-2026-68898 | MED 6.5 | microsoft windows_10_1607 Out-of-bounds read in Windows iSCSI allows an unauthorized attacker to deny service over a network. | 0,9% | — |
| CVE-2026-68872 | MED 6.5 | apache apache-airflow-providers-amazon The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mo | 0,6% | — |
| CVE-2026-68871 | MED 6.5 | apache apache-airflow-providers-apache-yandex The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with this backend, a caller in | 0,6% | — |
| CVE-2026-68868 | MED 6.5 | apache apache-airflow-providers-google The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when resolving Connections and Variables: the caller's `team_name` was accepted by the backend but dropped at the internal call boundary, so every | 0,6% | — |
| CVE-2026-68784 | MED 6.5 | microsoft sql_server_2017 Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. | 0,7% | — |
| CVE-2026-68781 | MED 6.5 | microsoft sql_server_2017 Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. | 0,7% | — |
| CVE-2026-68780 | MED 6.5 | microsoft sql_server_2017 Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. | 0,7% | — |
| CVE-2026-68779 | MED 6.5 | microsoft sql_server_2017 Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. | 0,6% | — |
| CVE-2026-68778 | MED 6.5 | microsoft sql_server_2017 Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. | 0,7% | — |
| CVE-2026-68777 | MED 6.5 | microsoft sql_server_2017 Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. | 0,7% | — |
| CVE-2026-68776 | MED 6.5 | microsoft sql_server_2017 Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network. | 0,6% | — |
| CVE-2026-68080 | MED 6.5 | apache qpid_broker-j It was not possible to govern the rate at which the broker would respond to an echo flow, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are | 0,7% | — |
| CVE-2026-68078 | MED 6.5 | apache qpid_broker-j It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users ar | 0,7% | — |
| CVE-2026-68077 | MED 6.5 | apache qpid_broker-j An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgr | 0,7% | — |
| CVE-2026-68075 | MED 6.5 | apache qpid_broker-j An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the issue. | 0,7% | — |