56.743 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.743 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più alto |
|---|---|---|---|---|
| CVE-2026-26119 | HIGH 8.8 | microsoft windows_admin_center Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network. | 1,2% | — |
| CVE-2026-26118 | HIGH 8.8 | microsoft azure_mcp_server Server-side request forgery (ssrf) in Azure MCP Server allows an authorized attacker to elevate privileges over a network. | 1,0% | — |
| CVE-2026-26117 | HIGH 7.8 | microsoft arc_enabled_servers_azure_connected_machine_agent Authentication bypass using an alternate path or channel in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2026-26116 | HIGH 8.8 | microsoft sql_server_2016 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | 1,2% | — |
| CVE-2026-26115 | HIGH 8.8 | microsoft sql_server_2016 Improper validation of specified type of input in SQL Server allows an authorized attacker to elevate privileges over a network. | 1,1% | — |
| CVE-2026-26114 | HIGH 8.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 3,0% | — |
| CVE-2026-26113 | HIGH 8.4 | microsoft 365_apps Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally. | 0,5% | — |
| CVE-2026-26112 | HIGH 7.8 | microsoft 365_apps Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0,5% | — |
| CVE-2026-26111 | HIGH 8.0 | microsoft windows_server_2012 Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. | 0,8% | — |
| CVE-2026-26110 | HIGH 8.4 | microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. | 0,5% | — |
| CVE-2026-26109 | HIGH 8.4 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2026-26108 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0,5% | — |
| CVE-2026-26107 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2026-26106 | HIGH 8.8 | microsoft sharepoint_server Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 1,4% | — |
| CVE-2026-26105 | HIGH 8.1 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | 1,2% | — |
| CVE-2026-26083 | CRIT 9.8 | fortinet fortisandbox A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.2 through 5.0.5, FortiSandbox PaaS 23.4 all versions, FortiSandbox PaaS 23.3 all versions, FortiSandbox PaaS 23.1 all v | 0,7% | — |
| CVE-2026-26057 | MED 6.5 | cisco skill_scanner Skill Scanner is a security scanner for AI Agent Skills that detects prompt injection, data exfiltration, and malicious code patterns. A vulnerability in the API Server of Skill Scanner could allow a unauthenticated, remote attacker to interact with the server | 0,3% | — |
| CVE-2026-26032 | MED 5.4 | apache ivy The PackagerResolver of Apache Ivy is able to download online artifacts and to (re)package them in a format defined by a packager.xml file. This repackaging is done by an Ant script, which is stored in a subdirectory of the configured "buildRoot" directory. Th | 0,5% | — |
| CVE-2026-26030 | CRIT 9.9 | microsoft semantic_kernel Semantic Kernel, Microsoft's semantic kernel Python SDK, has a remote code execution vulnerability in versions prior to 1.39.4, specifically within the `InMemoryVectorStore` filter functionality. The problem has been fixed in version `python-1.39.4`. Users sho | 3,7% | — |
| CVE-2026-25972 | MED 4.3 | fortinet fortisiem An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4 may allow a remote unauthenticated attacker to provide arbitrary data enabling a social engineering | 0,3% | — |
| CVE-2026-25917 | HIGH 7.2 | apache airflow Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended | 0,8% | — |
| CVE-2026-25903 | MED 6.6 | apache nifi Apache NiFi 1.1.0 through 2.7.2 are missing authorization when updating configuration properties on extension components that have specific Required Permissions based on the Restricted annotation. The Restricted annotation indicates additional privileges requi | 0,8% | — |
| CVE-2026-25854 | MED 6.1 | apache tomcat Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via the LoadBalancerDrainingValve. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M23 through 9.0.115, | 0,5% | — |
| CVE-2026-25836 | HIGH 7.2 | fortinet fortisandbox_cloud An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox Cloud 5.0.4, FortiSandbox PaaS 5.0.4 may allow a privileged attacker with super-admin profile and CLI access to execute unauth | 1,8% | — |
| CVE-2026-25766 | MED 5.3 | labstack echo Echo is a Go web framework. In versions 5.0.0 through 5.0.2 on Windows, Echo’s `middleware.Static` using the default filesystem allows path traversal via backslashes, enabling unauthenticated remote file read outside the static root. In `middleware/static.go`, | 0,3% | — |