56.625 CVE seguite
773 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.625 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2026-47909 | MED 6.3 | adobe dreamweaver Dreamweaver Desktop versions 21.7 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended | 0,1% | — |
| CVE-2026-47908 | HIGH 7.8 | adobe dreamweaver Dreamweaver Desktop versions 21.7 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a vict | 0,2% | — |
| CVE-2026-47907 | HIGH 8.6 | adobe dreamweaver Dreamweaver Desktop versions 21.7 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exp | 0,2% | — |
| CVE-2026-47906 | HIGH 8.6 | adobe dreamweaver Dreamweaver Desktop versions 21.7 and earlier are affected by a Dependency on Vulnerable Third-Party Component vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction | 0,2% | — |
| CVE-2026-47898 | CRIT 9.8 | apache lucene.net Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common library). This issue affects Apache Lucene.Net.Analysis.Common: from 4.8.0-beta00005 before 4.8.0-beta00018. Users are recommended to upgrade | 0,3% | — |
| CVE-2026-47897 | HIGH 7.5 | apache lucene.net Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library). This issue affects Apache Lucene.Net.Replicator: from 4.8.0-beta00005 before 4.8.0-beta00018. Users are recomme | 0,6% | — |
| CVE-2026-47896 | HIGH 7.5 | apache lucene.net Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library). This issue affects Apache Lucene.Net.Replicator: from 4.8.0-beta00005 through 4.8.0-beta00017. Users are recomm | 0,7% | — |
| CVE-2026-47838 | MED 6.8 | vmware spring_security SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certificate, this can lead to an attacker impersonating another user. A | 0,1% | — |
| CVE-2026-47835 | HIGH 8.6 | vmware spring_ai In Spring AI Vector Stores, special characters could be used to force the execution of arbitrary queries in Elasticsearch, OpenSearch, and GemFire VectorDB. Affected components: spring-ai-elasticsearch-store, spring-ai-opensearch-store, spring-ai-gemfire-store | 0,3% | — |
| CVE-2026-47656 | HIGH 7.9 | microsoft windows_10_1607 Protection mechanism failure in Windows Boot Manager allows an authorized attacker to bypass a security feature locally. | 0,3% | — |
| CVE-2026-47655 | MED 6.5 | microsoft graph Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network. | 0,8% | — |
| CVE-2026-47654 | HIGH 7.5 | microsoft windows_server_2016 Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 0,5% | — |
| CVE-2026-47653 | HIGH 8.8 | microsoft windows_10_1607 Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 0,6% | — |
| CVE-2026-47652 | HIGH 8.2 | microsoft windows_11_23h2 Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally. | 0,3% | — |
| CVE-2026-47648 | HIGH 7.0 | microsoft windows_10_1607 Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-47647 | CRIT 9.9 | microsoft dynamics_365 Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network. | 0,8% | — |
| CVE-2026-47646 | CRIT 9.3 | microsoft dynamics_365_customer_voice Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allows an unauthorized attacker to perform spoofing over a network. | 0,3% | — |
| CVE-2026-47645 | HIGH 8.8 | microsoft 365_copilot Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to elevate privileges over a network. | 0,8% | — |
| CVE-2026-47644 | MED 6.5 | microsoft copilot_chat Improper neutralization of special elements in output used by a downstream component ('injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network. | 0,7% | — |
| CVE-2026-47643 | CRIT 9.8 | microsoft azure_stack_edge External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a network. | 0,8% | — |
| CVE-2026-47642 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2026-47641 | MED 4.6 | microsoft sharepoint_server Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 0,5% | — |
| CVE-2026-47640 | MED 4.6 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 0,5% | — |
| CVE-2026-47639 | MED 5.4 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | 0,5% | — |
| CVE-2026-47638 | MED 4.6 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 0,5% | — |