56.706 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.706 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2026-33929 | MED 4.3 | apache pdfbox Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache PDFBox Examples. This issue affects the ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.36, from 3.0.0 through 3.0.7. Users are re | 0,7% | — |
| CVE-2026-33921 | MED 5.2 | The Windows installer deployed Npcap leaving its access restriction option at the insecure default value, so the driver was accessible to every local user of the host instead of being restricted to administrators only. A local user without administrative privi | 0,1% | — |
| CVE-2026-33858 | HIGH 8.8 | apache airflow Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended | 0,6% | — |
| CVE-2026-33857 | MED 5.3 | apache http_server Out-of-bounds Read vulnerability in mod_proxy_ajp of Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue. | 0,4% | — |
| CVE-2026-33844 | CRIT 9.0 | microsoft azure_managed_instance_for_apache_cassandra Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network. | 1,0% | — |
| CVE-2026-33843 | CRIT 9.1 | microsoft entra_id Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network. | 0,5% | — |
| CVE-2026-33842 | MED 5.5 | microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | 0,5% | — |
| CVE-2026-33841 | HIGH 7.8 | microsoft windows_10_21h2 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-33840 | HIGH 7.8 | microsoft windows_11_24h2 Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. | 2,0% | — |
| CVE-2026-33839 | HIGH 7.0 | microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-33838 | HIGH 7.8 | microsoft windows_10_1607 Double free in Windows Message Queuing allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2026-33837 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows TCP/IP allows an authorized attacker to elevate privileges locally. | 1,8% | — |
| CVE-2026-33835 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. | 2,1% | — |
| CVE-2026-33834 | HIGH 7.8 | microsoft windows_10_1607 Improper access control in Windows Event Logging Service allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-33833 | HIGH 8.2 | microsoft azure_machine_learning Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network. | 0,5% | — |
| CVE-2026-33829 | MED 4.3 | microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to perform spoofing over a network. | 3,4% | — |
| CVE-2026-33828 | HIGH 7.8 | microsoft windows_10_1607 Trust boundary violation in Windows Attestation allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-33827 | HIGH 8.1 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over a network. | 0,8% | — |
| CVE-2026-33826 | HIGH 8.0 | microsoft windows_server_2012 Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network. | 0,5% | — |
| CVE-2026-33823 | CRIT 9.6 | microsoft teams Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network. | 0,7% | — |
| CVE-2026-33822 | MED 6.1 | microsoft 365_apps Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-33821 | HIGH 7.7 | microsoft dynamics_365_customer_insights Improper privilege management in Microsoft Dynamics 365 Customer Insights allows an authorized attacker to elevate privileges over a network. | 0,7% | — |
| CVE-2026-33819 | CRIT 10.0 | microsoft bing Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network. | 0,8% | — |
| CVE-2026-33803 | MED 6.5 | juniper junos_os_evolved An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause a limited information disclosure and availability impact to the device. Due t | 0,4% | — |
| CVE-2026-33802 | MED 5.5 | juniper junos A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on EX Series allows a local, authenticated attacker to cause a Denial-of-Service (DoS). On EX2300, EX4000, EX4100, EX4300-MP (Multigigabit) and EX4400 switches, an authenticated, | 0,1% | — |