EN
56.663 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia

CVE Tracker

56.663 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordinato dal più alto
CVE-2026-45598 HIGH 7.0 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0,2%
CVE-2026-45597 HIGH 7.0 microsoft windows_11_23h2 Concurrent execution using shared resource with improper synchronization ('race condition') in UI Automation Manager (uiamanager.dll) allows an authorized attacker to elevate privileges locally. 0,2%
CVE-2026-45596 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0,2%
CVE-2026-45595 MED 5.4 microsoft windows_10_1607 Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature over a network. 0,4%
CVE-2026-45594 MED 5.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally. 0,4%
CVE-2026-45593 HIGH 7.8 microsoft windows_10_1809 Use after free in Windows SDK allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-45592 HIGH 7.8 microsoft windows_10_1607 Integer overflow or wraparound in Windows Internet (wininet.dll) allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-45591 HIGH 7.5 microsoft .net Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network. 2,4%
CVE-2026-45588 HIGH 7.9 microsoft windows_10_1607 Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. 0,3%
CVE-2026-45586 HIGH 7.8 microsoft windows_10_1607 Improper link resolution before file access ('link following') in Windows Collaborative Translation Framework allows an authorized attacker to elevate privileges locally. 3,6%
CVE-2026-45585 MED 6.8 microsoft windows_11_24h2 Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this vulnerability has been made public violating coordinated vulnerability best practices. We are issuing this CVE 1,4%
CVE-2026-45584 HIGH 8.1 microsoft malware_protection_engine Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network. 0,9%
CVE-2026-45583 HIGH 7.5 microsoft exchange_server Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network. 0,5%
CVE-2026-45505 HIGH 8.8 apache activemq Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Non-parenthesized discovery wrappers such as `masterslave:vm://...,...` and `static:vm://...` 0,6%
CVE-2026-45504 HIGH 8.8 microsoft exchange_server Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. 0,8%
CVE-2026-45503 HIGH 8.1 microsoft exchange_server Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network. 0,4%
CVE-2026-45502 MED 5.0 microsoft exchange_server Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network. 20,3%
CVE-2026-45501 MED 6.5 microsoft exchange_server Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network. 0,3%
CVE-2026-45500 MED 6.1 microsoft exchange_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. 0,4%
CVE-2026-45499 CRIT 9.9 microsoft azure_openai Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network. 0,6%
CVE-2026-45497 HIGH 7.7 microsoft copilot Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an authorized attacker to execute code over a network. 0,5%
CVE-2026-45496 MED 5.5 microsoft visual_studio_code Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. 0,4%
CVE-2026-45495 HIGH 8.8 microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability 1,0%
CVE-2026-45494 MED 5.4 microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability 0,3%
CVE-2026-45492 MED 5.4 microsoft edge_chromium Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network. 0,3%