56.706 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.706 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2026-32673 | HIGH 8.7 | f5 big-ip_access_policy_manager A vulnerability exists in BIG-IP scripted monitors that may allow an authenticated attacker with the Resource Administrator or Administrator role to execute arbitrary system commands with higher privileges. In appliance mode deployments, a successful exploit c | 0,2% | — |
| CVE-2026-32647 | HIGH 7.8 | f5 nginx_open_source NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to trigger a buffer over-read or over-write to the NGINX worker memory resulting in its termination or possibly code execution, using a speci | 0,9% | — |
| CVE-2026-32643 | HIGH 8.7 | f5 big-ip_access_policy_manager A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running arbitrary commands. Note: Software versions which have reached | 0,2% | — |
| CVE-2026-32642 | MED 4.3 | apache artemis Incorrect Authorization (CWE-863) vulnerability in Apache Artemis, Apache ActiveMQ Artemis exists when an application using the OpenWire protocol attempts to create a non-durable JMS topic subscription on an address that doesn't exist with an authenticated use | 0,4% | — |
| CVE-2026-32637 | ND | Velero is an open source tool for backing up, restoring, and migrating Kubernetes cluster resources and persistent volumes. Prior to 1.18.1, an attacker who compromises the backup object-storage backend can upload a malicious backup tarball containing parent-d | 0,5% | — |
| CVE-2026-32588 | MED 6.5 | apache cassandra Authenticated DoS over CQL in Apache Cassandra 4.0, 4.1, 5.0 allows authenticated user to raise query latencies via repeated password changes. Users are recommended to upgrade to version 4.0.20, 4.1.11, 5.0.7, which fixes this issue. | 0,5% | — |
| CVE-2026-32327 | CRIT 9.1 | apache apr-util A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this | 0,5% | — |
| CVE-2026-32310 | MED 4.1 | cryptomator cryptomator Cryptomator encrypts data being stored on cloud infrastructure. From version 1.6.0 to before version 1.19.1, vault configuration is parsed before its integrity is verified, and the masterkeyfile loader uses the unverified keyId as a filesystem path. The loader | 0,2% | — |
| CVE-2026-32228 | HIGH 7.5 | apache airflow UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue. | 0,4% | — |
| CVE-2026-32227 | CRIT 9.8 | apache ranger SQL Injection vulnerability vulnerability in Apache Ranger. This issue affects . Users are recommended to upgrade to version 2.9.0, which fixes the issue. | 0,4% | — |
| CVE-2026-32226 | MED 5.9 | microsoft .net_framework Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an unauthorized attacker to deny service over a network. | 0,5% | — |
| CVE-2026-32225 | HIGH 8.8 | microsoft windows_10_1607 Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network. | 1,2% | — |
| CVE-2026-32224 | HIGH 7.0 | microsoft windows_11_26h1 Use after free in Windows Server Update Service allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-32223 | MED 6.8 | microsoft windows_11_24h2 Heap-based buffer overflow in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack. | 0,5% | — |
| CVE-2026-32222 | HIGH 7.8 | microsoft windows_11_24h2 Untrusted pointer dereference in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-32221 | HIGH 8.4 | microsoft windows_11_24h2 Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code locally. | 0,3% | — |
| CVE-2026-32220 | MED 4.4 | microsoft windows_11_24h2 Improper access control in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally. | 0,3% | — |
| CVE-2026-32219 | HIGH 7.0 | microsoft windows_11_24h2 Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-32218 | MED 5.5 | microsoft windows_10_21h2 Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-32217 | MED 5.5 | microsoft windows_10_1607 Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-32216 | MED 5.5 | microsoft windows_11_26h1 Null pointer dereference in Windows Redirected Drive Buffering allows an authorized attacker to deny service locally. | 0,4% | — |
| CVE-2026-32215 | MED 5.5 | microsoft windows_10_1809 Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-32214 | MED 5.5 | microsoft windows_10_1607 Improper access control in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally. | 0,2% | — |
| CVE-2026-32213 | CRIT 10.0 | microsoft azure_ai_foundry Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network. | 0,9% | — |
| CVE-2026-32212 | MED 5.5 | microsoft windows_10_1607 Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally. | 0,3% | — |