56.706 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.706 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2026-3545 | CRIT 9.6 | google chrome Insufficient data validation in Navigation in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 0,4% | — |
| CVE-2026-35440 | MED 5.5 | microsoft 365_apps Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-3544 | HIGH 8.8 | google chrome Heap buffer overflow in WebCodecs in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High) | 0,3% | — |
| CVE-2026-35439 | HIGH 8.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 2,0% | — |
| CVE-2026-35438 | HIGH 8.3 | microsoft windows_admin_center Missing authorization in Windows Admin Center allows an authorized attacker to elevate privileges over a network. | 0,6% | — |
| CVE-2026-35436 | HIGH 8.8 | microsoft 365_apps Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-35435 | HIGH 8.6 | microsoft azure_ai_foundry Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network. | 1,2% | — |
| CVE-2026-35433 | HIGH 7.3 | microsoft .net Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally. | 0,7% | — |
| CVE-2026-35431 | CRIT 10.0 | microsoft entra_id Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network. | 0,5% | — |
| CVE-2026-35430 | HIGH 8.8 | microsoft azure_privileged_identity_management Authorization bypass through user-controlled key in Azure Privileged Identity Management (PIM) allows an authorized attacker to elevate privileges over a network. | 0,4% | — |
| CVE-2026-3543 | HIGH 8.8 | google chrome Inappropriate implementation in V8 in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) | 0,3% | — |
| CVE-2026-35429 | MED 4.3 | microsoft edge User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | 0,5% | — |
| CVE-2026-35428 | CRIT 9.6 | microsoft azure_cloud_shell Improper neutralization of special elements used in a command ('command injection') in Azure Cloud Shell allows an unauthorized attacker to perform spoofing over a network. | 0,9% | — |
| CVE-2026-35425 | HIGH 8.0 | microsoft azure_api_management Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network. | 0,5% | — |
| CVE-2026-35424 | HIGH 7.5 | microsoft windows_10_1607 Missing release of memory after effective lifetime in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network. | 1,2% | — |
| CVE-2026-35423 | MED 5.4 | microsoft windows_10_1607 Out-of-bounds read in Telnet Client allows an unauthorized attacker to disclose information over a network. | 0,7% | — |
| CVE-2026-35422 | MED 6.5 | microsoft windows_10_1607 Authentication bypass using an alternate path or channel in Windows TCP/IP allows an authorized attacker to bypass a security feature over a network. | 0,6% | — |
| CVE-2026-35421 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows GDI allows an unauthorized attacker to execute code locally. | 0,5% | — |
| CVE-2026-35420 | HIGH 7.8 | microsoft windows_server_2012 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-3542 | HIGH 8.8 | google chrome Inappropriate implementation in WebAssembly in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) | 0,3% | — |
| CVE-2026-35419 | MED 5.5 | microsoft windows_11_24h2 Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-35418 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-35417 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-35416 | HIGH 7.0 | microsoft windows_10_1607 Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 1,6% | — |
| CVE-2026-35415 | HIGH 7.8 | microsoft windows_10_1607 Integer overflow or wraparound in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally. | 0,3% | — |