58.507 CVE seguite
793 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.507 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più basso | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-65806 | MED 6.5 | microsoft azure_cyclecloud Missing authorization in Azure CycleCloud allows an authorized attacker to disclose information over a network. | 0,8% | — |
| CVE-2026-65794 | MED 6.5 | microsoft windows_10_1607 Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network. | 0,9% | — |
| CVE-2026-65785 | MED 6.5 | microsoft windows_11_24h2 Uncontrolled resource consumption in Windows DHCP Client allows an unauthorized attacker to deny service over an adjacent network. | 0,6% | — |
| CVE-2026-65769 | MED 6.5 | microsoft teams Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to disclose information over a network. | 0,9% | — |
| CVE-2026-65115 | MED 6.5 | nvidia infra_controller NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker may cause uncontrolled resource consumption. A successful exploit of this vulnerability may lead to denial of service. | 0,5% | — |
| CVE-2026-65112 | MED 6.5 | nvidia infra_controller NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service. | 0,5% | — |
| CVE-2026-65017 | MED 6.5 | apache airflow Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments. When an administrator has enabled multi-team mode and exposed the Config API, an authenticated Viewer holding only configuration-read access — with n | 0,7% | — |
| CVE-2026-64918 | MED 6.5 | microsoft 365_apps Insufficiently protected credentials in Microsoft Office allows an unauthorized attacker to perform spoofing over a network. | 0,9% | — |
| CVE-2026-64640 | MED 6.5 | apache polaris Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenticated principal with permission to register a table or view could, depending on the affected release and registration path, cause Polaris to | 0,5% | — |
| CVE-2026-63523 | MED 6.5 | microsoft skype_for_business_server Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network. | 0,6% | — |
| CVE-2026-63516 | MED 6.5 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 1,9% | — |
| CVE-2026-63512 | MED 6.5 | microsoft sharepoint_server Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network. | 0,7% | — |
| CVE-2026-62915 | MED 6.5 | microsoft exchange_server Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network. | 0,6% | — |
| CVE-2026-62912 | MED 6.5 | microsoft exchange_server Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network. | 2,0% | — |
| CVE-2026-62902 | MED 6.5 | microsoft .net Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network. | 0,9% | — |
| CVE-2026-62839 | MED 6.5 | microsoft sharepoint_server Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 0,9% | — |
| CVE-2026-62837 | MED 6.5 | microsoft sharepoint_server Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. | 1,2% | — |
| CVE-2026-62814 | MED 6.5 | microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. | 0,5% | — |
| CVE-2026-62801 | MED 6.5 | microsoft windows_10_1607 Improper limitation of a pathname to a restricted directory ('path traversal') in Windows PowerShell allows an unauthorized attacker to bypass a security feature over a network. | 0,8% | — |
| CVE-2026-62782 | MED 6.5 | microsoft windows_10_1607 Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disclose information over a network. | 0,9% | — |
| CVE-2026-62764 | MED 6.5 | apache accumulo Improper Handling of Insufficient Privileges vulnerability in Apache Accumulo. An authenticated, but low-privileged user without system permissions may issue a remote command to gracefully shutdown system components (compaction-coordinator, compactor, gc, mana | 0,8% | — |
| CVE-2026-62762 | MED 6.5 | microsoft windows_10_1607 Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network. | 1,1% | — |
| CVE-2026-62750 | MED 6.5 | microsoft windows_10_1607 Partial string comparison in Windows HTTP Protocol Stack allows an unauthorized attacker to perform tampering over an adjacent network. | 0,7% | — |
| CVE-2026-62745 | MED 6.5 | microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. | 0,5% | — |
| CVE-2026-62742 | MED 6.5 | microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. | 0,5% | — |