58.507 CVE seguite
793 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.507 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più basso | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-56168 | MED 6.5 | microsoft windows_10_21h2 Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network. | 1,1% | — |
| CVE-2026-55970 | MED 6.5 | apache thrift Buffer Over-read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. | 0,8% | — |
| CVE-2026-55956 | MED 6.5 | apache tomcat Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of the constraint. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22 | 0,7% | — |
| CVE-2026-55955 | MED 6.5 | apache tomcat Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.13 through 9. | 0,4% | — |
| CVE-2026-55054 | MED 6.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. | 0,9% | — |
| CVE-2026-55051 | MED 6.5 | microsoft sharepoint_server Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. | 0,9% | — |
| CVE-2026-55003 | MED 6.5 | microsoft windows_10_1607 Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. | 0,9% | — |
| CVE-2026-54126 | MED 6.5 | microsoft windows_10_1607 Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. | 0,9% | — |
| CVE-2026-54116 | MED 6.5 | microsoft sql_server_2025 Access of resource using incompatible type ('type confusion') in SQL Server allows an authorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2026-54108 | MED 6.5 | microsoft sharepoint_server External control of file name or path in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 1,1% | — |
| CVE-2026-5291 | MED 6.5 | google chrome Inappropriate implementation in WebGL in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium) | 0,3% | — |
| CVE-2026-52865 | MED 6.5 | f5 nginx_ingress_controller When NGINX Ingress Controller processes Ingress or TransportServer resources, an authenticated, remote attacker with permission to create or modify Ingress or TransportServer resources can cause the NGINX Ingress Controller process to terminate. Impact: Th | 0,5% | — |
| CVE-2026-5283 | MED 6.5 | google chrome Inappropriate implementation in ANGLE in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) | 0,2% | — |
| CVE-2026-5276 | MED 6.5 | google chrome Insufficient policy enforcement in WebUSB in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High) | 0,3% | — |
| CVE-2026-50749 | MED 6.5 | apache answer Improper Authorization vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Any authenticated user can reject arbitrary pending edit-revisions without review permission due to a missing authorization check on the reject operation. | 0,5% | — |
| CVE-2026-50659 | MED 6.5 | microsoft .net Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network. | 0,7% | — |
| CVE-2026-50634 | MED 6.5 | apache cxf A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to process metadata that was not authenticated by the accepted signature. This can bypass the application's assumption that accepted `Content-Type` or protected HTTP-h | 0,4% | — |
| CVE-2026-50630 | MED 6.5 | apache cxf A CRLF injection vulnerability exists in the OAuth2 AuthorizationUtils class. When constructing the WWW-Authenticate response header, the 'realm' parameter is concatenated without sanitizing Carriage Return (CR) and Line Feed (LF) characters. If an attacker ca | 0,6% | — |
| CVE-2026-50519 | MED 6.5 | microsoft github_copilot_chat Initialization of a resource with an insecure default in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network. | 0,9% | — |
| CVE-2026-50508 | MED 6.5 | microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. | 0,9% | — |
| CVE-2026-50504 | MED 6.5 | microsoft windows_10_1607 Buffer over-read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. | 0,9% | — |
| CVE-2026-50497 | MED 6.5 | microsoft windows_10_1607 Off-by-one error in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network. | 0,9% | — |
| CVE-2026-50468 | MED 6.5 | microsoft sql_server_2025 Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2026-50445 | MED 6.5 | microsoft windows_10_1607 Buffer over-read in Windows RDP allows an unauthorized attacker to disclose information over a network. | 0,9% | — |
| CVE-2026-50376 | MED 6.5 | microsoft windows_10_1607 Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. | 0,9% | — |