58.507 CVE seguite
793 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.507 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più basso | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-67591 | MED 6.5 | apache qpid_protonj2 An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue. | 0,7% | — |
| CVE-2026-67555 | MED 6.5 | apache qpid_proton-dotnet It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users | 0,7% | — |
| CVE-2026-67554 | MED 6.5 | apache qpid_proton-dotnet An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to | 0,7% | — |
| CVE-2026-67553 | MED 6.5 | apache qpid_proton-dotnet An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue. | 0,7% | — |
| CVE-2026-67393 | MED 6.5 | microsoft sql_server_2017 Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2026-67390 | MED 6.5 | microsoft sql_server_2017 Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2026-67389 | MED 6.5 | microsoft sql_server_2022 Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2026-67386 | MED 6.5 | microsoft sql_server_2017 Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2026-67383 | MED 6.5 | microsoft sql_server_2025 Generation of error message containing sensitive information in SQL Server allows an authorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2026-67369 | MED 6.5 | microsoft sql_server_2025 Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2026-66816 | MED 6.5 | microsoft sql_server_2022 Insufficient logging in SQL Server allows an authorized attacker to bypass a security feature over a network. | 1,0% | — |
| CVE-2026-66391 | MED 6.5 | apache wicket Use of Insufficiently Random Values, Protection Mechanism Failure vulnerability in Apache Wicket. This issue affects Apache Wicket: from 9.0.0 through 9.23.0, from 10.0.0 through 10.9.0. Users are recommended to upgrade to version 10.10.0, which fixes the is | 0,6% | — |
| CVE-2026-66326 | MED 6.5 | microsoft edge_chromium Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0,8% | — |
| CVE-2026-66324 | MED 6.5 | microsoft edge_chromium External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | 0,9% | — |
| CVE-2026-66314 | MED 6.5 | microsoft edge_chromium Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | 0,6% | — |
| CVE-2026-66312 | MED 6.5 | microsoft edge_chromium Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network. | 1,1% | — |
| CVE-2026-66308 | MED 6.5 | microsoft skype_for_business_server Out-of-bounds read in Skype for Business allows an authorized attacker to deny service over a network. | 1,1% | — |
| CVE-2026-66306 | MED 6.5 | microsoft skype_for_business_server Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network. | 0,9% | — |
| CVE-2026-66303 | MED 6.5 | microsoft skype_for_business_server Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network. | 1,1% | — |
| CVE-2026-66301 | MED 6.5 | microsoft dynamics_365 Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2026-66277 | MED 6.5 | apache qpid_proton-j It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users ar | 0,7% | — |
| CVE-2026-66276 | MED 6.5 | apache qpid_proton-j An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgr | 0,7% | — |
| CVE-2026-66275 | MED 6.5 | apache qpid_proton-j An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue. | 0,7% | — |
| CVE-2026-65945 | MED 6.5 | apache ranger Logs contain replayable JWT tokens in Apache Ranger versions <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue. | 0,6% | — |
| CVE-2026-65813 | MED 6.5 | microsoft exchange_server Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | 0,9% | — |