58.306 CVE seguite
790 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.306 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-70469 | HIGH 7.5 | apache nifi Apache NiFi 2.11.0 disabled support for gzip-encoded HTTP requests for the application REST API and rejected requests that included the standard Content-Encoding header indicating gzip encoding. The framework enforcement filter did not check multiple instances | 0,6% | — |
| CVE-2026-70065 | HIGH 7.5 | microsoft windows_10_1607 Missing release of memory after effective lifetime in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | 1,2% | — |
| CVE-2026-69890 | HIGH 7.5 | microsoft windows_10_1809 Use after free in Windows Virtual Trusted Platform Module allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-69881 | HIGH 7.5 | microsoft windows_10_1809 Null pointer dereference in Windows IKE Extension allows an unauthorized attacker to deny service over a network. | 1,2% | — |
| CVE-2026-69852 | HIGH 7.5 | microsoft windows_10_1607 Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine | 0,7% | — |
| CVE-2026-69809 | HIGH 7.5 | microsoft windows_11_23h2 Missing release of memory after effective lifetime in Active Directory Domain Services allows an unauthorized attacker to deny service over a network. | 1,2% | — |
| CVE-2026-69804 | HIGH 7.5 | microsoft sharepoint_server Time-of-check time-of-use (toctou) race condition in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 0,5% | — |
| CVE-2026-69793 | HIGH 7.5 | microsoft windows_10_1607 Improper validation of consistency within input in Windows TCP/IP allows an unauthorized attacker to bypass a security feature over a network. | 0,8% | — |
| CVE-2026-69760 | HIGH 7.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Kerberos allows an unauthorized attacker to deny service over a network. | 1,1% | — |
| CVE-2026-69744 | HIGH 7.5 | microsoft windows_11_24h2 Null pointer dereference in Windows Kerberos allows an unauthorized attacker to deny service over a network. | 1,1% | — |
| CVE-2026-69710 | HIGH 7.5 | microsoft windows_10_21h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hello allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-69631 | HIGH 7.5 | microsoft windows_10_1607 Integer overflow or wraparound in Windows DNS allows an unauthorized attacker to deny service over a network. | 1,2% | — |
| CVE-2026-69607 | HIGH 7.5 | microsoft windows_10_1607 Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network. | 0,6% | — |
| CVE-2026-69599 | HIGH 7.5 | microsoft windows_11_23h2 Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network. | 0,7% | — |
| CVE-2026-69588 | HIGH 7.5 | microsoft windows_11_23h2 Missing release of memory after effective lifetime in Windows TCP/IP allows an unauthorized attacker to deny service over a network. | 1,2% | — |
| CVE-2026-69587 | HIGH 7.5 | microsoft windows_11_23h2 Null pointer dereference in Windows IKE Extension allows an unauthorized attacker to deny service over a network. | 1,2% | — |
| CVE-2026-69539 | HIGH 7.5 | microsoft windows_10_1607 Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network. | 0,5% | — |
| CVE-2026-69514 | HIGH 7.5 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to execute code over a network. | 0,7% | — |
| CVE-2026-69443 | HIGH 7.5 | microsoft windows_10_1809 Out-of-bounds read in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2026-69429 | HIGH 7.5 | microsoft windows_10_1809 Heap-based buffer overflow in Windows IKE Extension allows an authorized attacker to execute code over a network. | 0,7% | — |
| CVE-2026-69428 | HIGH 7.5 | microsoft windows_10_1607 Out-of-bounds read in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network. | 1,2% | — |
| CVE-2026-69397 | HIGH 7.5 | microsoft windows_10_1809 Use after free in OpenSSH for Windows allows an unauthorized attacker to execute code over a network. | 0,6% | — |
| CVE-2026-69342 | HIGH 7.5 | microsoft windows_10_1607 Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | 1,2% | — |
| CVE-2026-68981 | HIGH 7.5 | apache nifi Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding filter. The framework enforced a configurable maximum request size on the compressed payload rather than the decompressed output, allowing | 0,5% | — |
| CVE-2026-68968 | HIGH 7.5 | apache airflow Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` path segment failed to parse. The authorization dependency parsed it with `int()` while the route handler parsed it as pydantic's `NonNegative | 0,4% | — |