EN
58.507 CVE seguite
793 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.507 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordinato dal più basso Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2026-56168 MED 6.5 microsoft windows_10_21h2 Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network. 1,1% —
CVE-2026-55970 MED 6.5 apache thrift Buffer Over-read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. 0,8% —
CVE-2026-55956 MED 6.5 apache tomcat Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of the constraint. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22 0,7% —
CVE-2026-55955 MED 6.5 apache tomcat Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.13 through 9. 0,4% —
CVE-2026-55054 MED 6.5 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. 0,9% —
CVE-2026-55051 MED 6.5 microsoft sharepoint_server Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. 0,9% —
CVE-2026-55003 MED 6.5 microsoft windows_10_1607 Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. 0,9% —
CVE-2026-54126 MED 6.5 microsoft windows_10_1607 Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. 0,9% —
CVE-2026-54116 MED 6.5 microsoft sql_server_2025 Access of resource using incompatible type ('type confusion') in SQL Server allows an authorized attacker to disclose information over a network. 1,0% —
CVE-2026-54108 MED 6.5 microsoft sharepoint_server External control of file name or path in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 1,1% —
CVE-2026-5291 MED 6.5 google chrome Inappropriate implementation in WebGL in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium) 0,3% —
CVE-2026-52865 MED 6.5 f5 nginx_ingress_controller When NGINX Ingress Controller processes Ingress or TransportServer resources, an authenticated, remote attacker with permission to create or modify Ingress or TransportServer resources can cause the NGINX Ingress Controller process to terminate. Impact: Th 0,5% —
CVE-2026-5283 MED 6.5 google chrome Inappropriate implementation in ANGLE in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) 0,2% —
CVE-2026-5276 MED 6.5 google chrome Insufficient policy enforcement in WebUSB in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High) 0,3% —
CVE-2026-50749 MED 6.5 apache answer Improper Authorization vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Any authenticated user can reject arbitrary pending edit-revisions without review permission due to a missing authorization check on the reject operation. 0,5% —
CVE-2026-50659 MED 6.5 microsoft .net Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network. 0,7% —
CVE-2026-50634 MED 6.5 apache cxf A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to process metadata that was not authenticated by the accepted signature. This can bypass the application's assumption that accepted `Content-Type` or protected HTTP-h 0,4% —
CVE-2026-50630 MED 6.5 apache cxf A CRLF injection vulnerability exists in the OAuth2 AuthorizationUtils class. When constructing the WWW-Authenticate response header, the 'realm' parameter is concatenated without sanitizing Carriage Return (CR) and Line Feed (LF) characters. If an attacker ca 0,6% —
CVE-2026-50519 MED 6.5 microsoft github_copilot_chat Initialization of a resource with an insecure default in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network. 0,9% —
CVE-2026-50508 MED 6.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. 0,9% —
CVE-2026-50504 MED 6.5 microsoft windows_10_1607 Buffer over-read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. 0,9% —
CVE-2026-50497 MED 6.5 microsoft windows_10_1607 Off-by-one error in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network. 0,9% —
CVE-2026-50468 MED 6.5 microsoft sql_server_2025 Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network. 1,0% —
CVE-2026-50445 MED 6.5 microsoft windows_10_1607 Buffer over-read in Windows RDP allows an unauthorized attacker to disclose information over a network. 0,9% —
CVE-2026-50376 MED 6.5 microsoft windows_10_1607 Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. 0,9% —