56.705 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.705 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2026-41707 | HIGH 7.4 | Authentication Bypass by Capture-replay vulnerability in Spring Spring Security allows Spring Security's DPoPProofJwtDecoderFactory contains a cache-based replay attack vulnerability. The internal cache storing JWT ID claims has a strict size limit, allowing a | 0,3% | — |
| CVE-2026-41706 | MED 6.1 | vmware spring_security Spring Security's CookieRequestCache and CookieServerRequestCache store the pre-authentication request URL in a browser cookie so that users can be redirected back to their intended destination after a successful login. In affected versions, the full absolute | 0,2% | — |
| CVE-2026-41705 | HIGH 8.6 | vmware spring_ai Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injection via unsanitized document IDs. Spring AI 1.0.x: affected from 1.0.0 through latest 1.0.x; upgrade to 1.0.7 or greater. Spring AI 1.1.x: affected from 1.1.0 | 0,4% | — |
| CVE-2026-41702 | HIGH 7.8 | vmware fusion VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a SETUID binary. A malicious actor with local non-administrative user privileges may exploit this vulnerability to escalate privileges to roo | 0,1% | — |
| CVE-2026-41700 | HIGH 8.1 | vmware spring_for_graphql Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSocket Hijacking. An attacker can trick an authenticated user into visiting a malicious page, allowing the attacker to execute arbitrary GraphQL operation | 0,2% | — |
| CVE-2026-41699 | HIGH 8.1 | vmware spring_for_graphql Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. An attacker can craft a malicious GraphQL request that can lead to Remote Code Execution when the application exposes a paginated (Connection) f | 0,4% | — |
| CVE-2026-41696 | MED 5.9 | vmware spring_data_mongodb Spring Data MongoDB repository query methods annotated with @Query that use regex parameter binding perform insufficient validation of the bound parameter. An attacker can supply a crafted string to break out of the intended regular expression quoting. Affect | 0,3% | — |
| CVE-2026-41694 | LOW 3.7 | vmware spring_security Since Spring Security SAML decrypts SAML Responses as well as elements of SAML LogoutRequests and LogoutResponses without requiring a valid signature, attackers may be able to craft these SAML payloads and use the Service Provider as a decryption oracle. Affe | 0,1% | — |
| CVE-2026-41636 | HIGH 7.5 | apache thrift Uncontrolled Recursion vulnerability in Apache Thrift Node.js bindings This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. | 0,5% | — |
| CVE-2026-41635 | CRIT 9.8 | apache mina Apache MINA's AbstractIoBuffer.resolveClass() contains two branches, one of them (for static classes or primitive types) does not check the class at all, bypassing the classname allowlist and allowing arbitrary code to be executed. The fix checks if the cl | 0,6% | — |
| CVE-2026-41615 | CRIT 9.6 | microsoft authenticator Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to disclose information over a network. | 0,6% | — |
| CVE-2026-41614 | MED 6.2 | microsoft 365_copilot Improper access control in M365 Copilot for Desktop allows an unauthorized attacker to perform spoofing locally. | 0,4% | — |
| CVE-2026-41613 | HIGH 8.8 | microsoft visual_studio_code Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. | 0,5% | — |
| CVE-2026-41612 | MED 5.5 | microsoft live_preview Relative path traversal in Visual Studio Code allows an unauthorized attacker to disclose information locally. | 0,5% | — |
| CVE-2026-41611 | HIGH 7.8 | microsoft visual_studio_code Improper neutralization of script-related html tags in a web page (basic xss) in Visual Studio Code allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2026-41610 | MED 6.3 | microsoft visual_studio_code Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | 0,6% | — |
| CVE-2026-41608 | HIGH 7.5 | apache thrift Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. | 0,6% | — |
| CVE-2026-41607 | MED 6.5 | apache thrift Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. | 0,9% | — |
| CVE-2026-41606 | MED 5.3 | apache thrift Uncontrolled Recursion vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. | 1,1% | — |
| CVE-2026-41605 | HIGH 7.3 | apache thrift Integer Overflow or Wraparound vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. | 0,9% | — |
| CVE-2026-41604 | HIGH 8.2 | apache thrift Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. | 0,9% | — |
| CVE-2026-41602 | HIGH 7.5 | apache thrift Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. | 1,2% | — |
| CVE-2026-41409 | CRIT 9.8 | apache mina The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of classes allowed to be deserialized was applied too late after a static initializer in a class to be read might already have been executed. Aff | 0,4% | — |
| CVE-2026-41293 | CRIT 9.8 | apache tomcat Improper Input Validation vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 10.0.0-M1 through 10.0.27. Older, end of support versions may also | 1,6% | — |
| CVE-2026-41284 | HIGH 7.5 | apache tomcat Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117. Older, unsupported versions may also be affec | 0,8% | — |