58.306 CVE seguite
790 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.306 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-1999-1593 | HIGH 7.6 | microsoft windows_2000 Windows Internet Naming Service (WINS) allows remote attackers to cause a denial of service (connectivity loss) or steal credentials via a 1Ch registration that causes WINS to change the domain controller to point to a malicious server. NOTE: this problem may | 18,1% | — |
| CVE-1999-0802 | HIGH 7.6 | microsoft internet_explorer Buffer overflow in Internet Explorer 5 allows remote attackers to execute commands via a malformed Favorites icon. | 10,2% | — |
| CVE-2026-9960 | HIGH 7.5 | google chrome Integer overflow in PDFium in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted font file. (Chromium security severity: High) | 0,2% | — |
| CVE-2026-9954 | HIGH 7.5 | google chrome Use after free in TabStrip in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 0,2% | — |
| CVE-2026-9933 | HIGH 7.5 | google chrome Use after free in Input in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 0,2% | — |
| CVE-2026-9909 | HIGH 7.5 | google chrome Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | 0,3% | — |
| CVE-2026-9901 | HIGH 7.5 | google chrome Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) | 0,3% | — |
| CVE-2026-91866 | HIGH 7.5 | apache neethi A specially crafted pair of WS-Policy documents can force Neethi's policy-intersection to do exponential amounts of work, pinning the CPU for a long time (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes this issue. | 0,5% | — |
| CVE-2026-91865 | HIGH 7.5 | apache neethi A small WS-Policy document using repeated policy references can force Neethi to re-expand the same references exponentially during normalization, consuming huge amounts of CPU and memory (denial of service). Users are recommended to upgrade to version 3.2.4, w | 0,5% | — |
| CVE-2026-91864 | HIGH 7.5 | apache neethi A specially crafted WS-Policy document can pack unlimited content inside a policy assertion, which Neethi copies into memory without counting it against its size limits, exhausting the heap (denial of service). Users are recommended to upgrade to version 3.2.4 | 0,5% | — |
| CVE-2026-91863 | HIGH 7.5 | apache neethi A specially crafted WS-Policy document with deeply nested policy elements can bypass Neethi's nesting-depth limit and exhaust the thread stack, crashing the parser (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes this issue. | 0,5% | — |
| CVE-2026-9123 | HIGH 7.5 | google chrome Heap buffer overflow in Chromecast in Google Chrome on Android, Linux, ChromeOS prior to 148.0.7778.179 allowed a local attacker to execute arbitrary code inside a sandbox via malicious network traffic. (Chromium security severity: Medium) | 0,2% | — |
| CVE-2026-9117 | HIGH 7.5 | google chrome Type Confusion in GFX in Google Chrome on Linux, ChromeOS prior to 148.0.7778.179 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: High) | 0,3% | — |
| CVE-2026-9071 | HIGH 7.5 | ibm websphere_application_server IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to c | 0,5% | — |
| CVE-2026-8854 | HIGH 7.5 | ibm http_server IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_mem_cache. | 0,4% | — |
| CVE-2026-8850 | HIGH 7.5 | ibm http_server IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_ibm_upload. | 0,4% | — |
| CVE-2026-8671 | HIGH 7.5 | avantra avantra Insertion of sensitive information into log file vulnerability in syslink software AG Avantra on Linux, Windows allows Resource Leak Exposure. This issue affects Avantra: before 25.3.0. | 0,2% | — |
| CVE-2026-85917 | HIGH 7.5 | microsoft foundry Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network. | 1,0% | — |
| CVE-2026-8547 | HIGH 7.5 | google chrome Insufficient policy enforcement in Passwords in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: High) | 0,3% | — |
| CVE-2026-8521 | HIGH 7.5 | google chrome Use after free in Tab Groups in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical) | 0,2% | — |
| CVE-2026-8510 | HIGH 7.5 | google chrome Integer overflow in Skia in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical) | 0,2% | — |
| CVE-2026-8451 | HIGH 7.5 | citrix netscaler_application_delivery_controller Insufficient input validation in NetScaler ADC and NetScaler Gateway leading to memory overread if NetScaler ADC or NetScaler Gateway is configured as a SAML IDP | 15,7% | — |
| CVE-2026-84001 | HIGH 7.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Key Distribution Center allows an unauthorized attacker to deny service over a network. | 1,2% | — |
| CVE-2026-83989 | HIGH 7.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to deny service over a network. | 1,2% | — |
| CVE-2026-81355 | HIGH 7.5 | microsoft windows_10_1607 Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to execute code locally. | 0,2% | — |