EN
56.706 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia

CVE Tracker

56.706 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordinato dal più basso
CVE-2026-3545 CRIT 9.6 google chrome Insufficient data validation in Navigation in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) 0,4%
CVE-2026-35440 MED 5.5 microsoft 365_apps Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally. 0,4%
CVE-2026-3544 HIGH 8.8 google chrome Heap buffer overflow in WebCodecs in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High) 0,3%
CVE-2026-35439 HIGH 8.8 microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 2,0%
CVE-2026-35438 HIGH 8.3 microsoft windows_admin_center Missing authorization in Windows Admin Center allows an authorized attacker to elevate privileges over a network. 0,6%
CVE-2026-35436 HIGH 8.8 microsoft 365_apps Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. 0,2%
CVE-2026-35435 HIGH 8.6 microsoft azure_ai_foundry Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network. 1,2%
CVE-2026-35433 HIGH 7.3 microsoft .net Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally. 0,7%
CVE-2026-35431 CRIT 10.0 microsoft entra_id Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network. 0,5%
CVE-2026-35430 HIGH 8.8 microsoft azure_privileged_identity_management Authorization bypass through user-controlled key in Azure Privileged Identity Management (PIM) allows an authorized attacker to elevate privileges over a network. 0,4%
CVE-2026-3543 HIGH 8.8 google chrome Inappropriate implementation in V8 in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) 0,3%
CVE-2026-35429 MED 4.3 microsoft edge User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. 0,5%
CVE-2026-35428 CRIT 9.6 microsoft azure_cloud_shell Improper neutralization of special elements used in a command ('command injection') in Azure Cloud Shell allows an unauthorized attacker to perform spoofing over a network. 0,9%
CVE-2026-35425 HIGH 8.0 microsoft azure_api_management Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network. 0,5%
CVE-2026-35424 HIGH 7.5 microsoft windows_10_1607 Missing release of memory after effective lifetime in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network. 1,2%
CVE-2026-35423 MED 5.4 microsoft windows_10_1607 Out-of-bounds read in Telnet Client allows an unauthorized attacker to disclose information over a network. 0,7%
CVE-2026-35422 MED 6.5 microsoft windows_10_1607 Authentication bypass using an alternate path or channel in Windows TCP/IP allows an authorized attacker to bypass a security feature over a network. 0,6%
CVE-2026-35421 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows GDI allows an unauthorized attacker to execute code locally. 0,5%
CVE-2026-35420 HIGH 7.8 microsoft windows_server_2012 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-3542 HIGH 8.8 google chrome Inappropriate implementation in WebAssembly in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) 0,3%
CVE-2026-35419 MED 5.5 microsoft windows_11_24h2 Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. 0,4%
CVE-2026-35418 HIGH 7.8 microsoft windows_10_1809 Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. 0,2%
CVE-2026-35417 HIGH 7.8 microsoft windows_10_1809 Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-35416 HIGH 7.0 microsoft windows_10_1607 Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 1,6%
CVE-2026-35415 HIGH 7.8 microsoft windows_10_1607 Integer overflow or wraparound in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally. 0,3%