56.663 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.663 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più alto |
|---|---|---|---|---|
| CVE-2026-45598 | HIGH 7.0 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-45597 | HIGH 7.0 | microsoft windows_11_23h2 Concurrent execution using shared resource with improper synchronization ('race condition') in UI Automation Manager (uiamanager.dll) allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-45596 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-45595 | MED 5.4 | microsoft windows_10_1607 Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature over a network. | 0,4% | — |
| CVE-2026-45594 | MED 5.5 | microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-45593 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows SDK allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-45592 | HIGH 7.8 | microsoft windows_10_1607 Integer overflow or wraparound in Windows Internet (wininet.dll) allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-45591 | HIGH 7.5 | microsoft .net Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network. | 2,4% | — |
| CVE-2026-45588 | HIGH 7.9 | microsoft windows_10_1607 Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | 0,3% | — |
| CVE-2026-45586 | HIGH 7.8 | microsoft windows_10_1607 Improper link resolution before file access ('link following') in Windows Collaborative Translation Framework allows an authorized attacker to elevate privileges locally. | 3,6% | — |
| CVE-2026-45585 | MED 6.8 | microsoft windows_11_24h2 Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this vulnerability has been made public violating coordinated vulnerability best practices. We are issuing this CVE | 1,4% | — |
| CVE-2026-45584 | HIGH 8.1 | microsoft malware_protection_engine Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network. | 0,9% | — |
| CVE-2026-45583 | HIGH 7.5 | microsoft exchange_server Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network. | 0,5% | — |
| CVE-2026-45505 | HIGH 8.8 | apache activemq Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Non-parenthesized discovery wrappers such as `masterslave:vm://...,...` and `static:vm://...` | 0,6% | — |
| CVE-2026-45504 | HIGH 8.8 | microsoft exchange_server Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | 0,8% | — |
| CVE-2026-45503 | HIGH 8.1 | microsoft exchange_server Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network. | 0,4% | — |
| CVE-2026-45502 | MED 5.0 | microsoft exchange_server Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network. | 20,3% | — |
| CVE-2026-45501 | MED 6.5 | microsoft exchange_server Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network. | 0,3% | — |
| CVE-2026-45500 | MED 6.1 | microsoft exchange_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | 0,4% | — |
| CVE-2026-45499 | CRIT 9.9 | microsoft azure_openai Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network. | 0,6% | — |
| CVE-2026-45497 | HIGH 7.7 | microsoft copilot Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an authorized attacker to execute code over a network. | 0,5% | — |
| CVE-2026-45496 | MED 5.5 | microsoft visual_studio_code Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | 0,4% | — |
| CVE-2026-45495 | HIGH 8.8 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 1,0% | — |
| CVE-2026-45494 | MED 5.4 | microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability | 0,3% | — |
| CVE-2026-45492 | MED 5.4 | microsoft edge_chromium Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network. | 0,3% | — |