EN
56.706 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia

CVE Tracker

56.706 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordinato dal più basso
CVE-2026-32673 HIGH 8.7 f5 big-ip_access_policy_manager A vulnerability exists in BIG-IP scripted monitors that may allow an authenticated attacker with the Resource Administrator or Administrator role to execute arbitrary system commands with higher privileges. In appliance mode deployments, a successful exploit c 0,2%
CVE-2026-32647 HIGH 7.8 f5 nginx_open_source NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to trigger a buffer over-read or over-write to the NGINX worker memory resulting in its termination or possibly code execution, using a speci 0,9%
CVE-2026-32643 HIGH 8.7 f5 big-ip_access_policy_manager A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running arbitrary commands.  Note: Software versions which have reached 0,2%
CVE-2026-32642 MED 4.3 apache artemis Incorrect Authorization (CWE-863) vulnerability in Apache Artemis, Apache ActiveMQ Artemis exists when an application using the OpenWire protocol attempts to create a non-durable JMS topic subscription on an address that doesn't exist with an authenticated use 0,4%
CVE-2026-32637 ND Velero is an open source tool for backing up, restoring, and migrating Kubernetes cluster resources and persistent volumes. Prior to 1.18.1, an attacker who compromises the backup object-storage backend can upload a malicious backup tarball containing parent-d 0,5%
CVE-2026-32588 MED 6.5 apache cassandra Authenticated DoS over CQL in Apache Cassandra 4.0, 4.1, 5.0 allows authenticated user to raise query latencies via repeated password changes. Users are recommended to upgrade to version 4.0.20, 4.1.11, 5.0.7, which fixes this issue. 0,5%
CVE-2026-32327 CRIT 9.1 apache apr-util A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this 0,5%
CVE-2026-32310 MED 4.1 cryptomator cryptomator Cryptomator encrypts data being stored on cloud infrastructure. From version 1.6.0 to before version 1.19.1, vault configuration is parsed before its integrity is verified, and the masterkeyfile loader uses the unverified keyId as a filesystem path. The loader 0,2%
CVE-2026-32228 HIGH 7.5 apache airflow UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue. 0,4%
CVE-2026-32227 CRIT 9.8 apache ranger SQL Injection vulnerability vulnerability in Apache Ranger. This issue affects . Users are recommended to upgrade to version 2.9.0, which fixes the issue. 0,4%
CVE-2026-32226 MED 5.9 microsoft .net_framework Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an unauthorized attacker to deny service over a network. 0,5%
CVE-2026-32225 HIGH 8.8 microsoft windows_10_1607 Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network. 1,2%
CVE-2026-32224 HIGH 7.0 microsoft windows_11_26h1 Use after free in Windows Server Update Service allows an authorized attacker to elevate privileges locally. 0,2%
CVE-2026-32223 MED 6.8 microsoft windows_11_24h2 Heap-based buffer overflow in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack. 0,5%
CVE-2026-32222 HIGH 7.8 microsoft windows_11_24h2 Untrusted pointer dereference in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-32221 HIGH 8.4 microsoft windows_11_24h2 Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code locally. 0,3%
CVE-2026-32220 MED 4.4 microsoft windows_11_24h2 Improper access control in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally. 0,3%
CVE-2026-32219 HIGH 7.0 microsoft windows_11_24h2 Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. 0,2%
CVE-2026-32218 MED 5.5 microsoft windows_10_21h2 Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally. 0,4%
CVE-2026-32217 MED 5.5 microsoft windows_10_1607 Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally. 0,4%
CVE-2026-32216 MED 5.5 microsoft windows_11_26h1 Null pointer dereference in Windows Redirected Drive Buffering allows an authorized attacker to deny service locally. 0,4%
CVE-2026-32215 MED 5.5 microsoft windows_10_1809 Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally. 0,4%
CVE-2026-32214 MED 5.5 microsoft windows_10_1607 Improper access control in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally. 0,2%
CVE-2026-32213 CRIT 10.0 microsoft azure_ai_foundry Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network. 0,9%
CVE-2026-32212 MED 5.5 microsoft windows_10_1607 Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally. 0,3%