56.761 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.761 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più alto |
|---|---|---|---|---|
| CVE-2026-23901 | LOW 2.5 | apache shiro Observable Timing Discrepancy vulnerability in Apache Shiro. This issue affects Apache Shiro: from 1.*, 2.* before 2.0.7. Users are recommended to upgrade to version 2.0.7 or later, which fixes the issue. Prior to Shiro 2.0.7, code paths for non-existent vs | 0,2% | — |
| CVE-2026-23889 | MED 6.5 | pnpm pnpm pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's tarball extraction allows malicious packages to write files outside the package directory on Windows. The path normalization only checks for `./` but not `.\`. On Win | 0,4% | — |
| CVE-2026-23795 | MED 4.9 | apache syncope Improper Restriction of XML External Entity Reference vulnerability in Apache Syncope Console. An administrator with adequate entitlements to create or edit Keymaster parameters via Console can construct malicious XML text to launch an XXE attack, thereby caus | 1,9% | — |
| CVE-2026-23794 | MED 6.8 | apache syncope Reflected XSS in Apache Syncope's Enduser Login page. An attacker that tricks a legitimate user into clicking a malicious link and logging in to Syncope Enduser could steal that user's credentials. This issue affects Apache Syncope: from 3.0 through 3.0.15, f | 0,5% | — |
| CVE-2026-23708 | HIGH 7.5 | fortinet fortisoar A improper authentication vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR on-premise 7.6.0 through 7.6.3, FortiSOAR on-premise 7.5.0 through 7.5.2 may allow an unauthenticated attacker to bypass authe | 0,3% | — |
| CVE-2026-23674 | HIGH 7.5 | microsoft windows_10_1607 Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network. | 1,2% | — |
| CVE-2026-23673 | HIGH 7.8 | microsoft windows_10_1607 Out-of-bounds read in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2026-23672 | HIGH 7.8 | microsoft windows_10_1607 Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | 0,4% | — |
| CVE-2026-23671 | HIGH 7.0 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-23670 | MED 5.7 | microsoft windows_10_1607 Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally. | 0,3% | — |
| CVE-2026-23669 | HIGH 8.8 | microsoft windows_10_1607 Use after free in RPC Runtime allows an authorized attacker to execute code over a network. | 0,9% | — |
| CVE-2026-23668 | HIGH 7.0 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | 3,6% | — |
| CVE-2026-23667 | HIGH 7.0 | microsoft windows_10_1809 Use after free in Broadcast DVR allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-23666 | HIGH 7.5 | microsoft .net_framework Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network. | 1,3% | — |
| CVE-2026-23665 | HIGH 7.8 | microsoft linux_diagnostic_extension Heap-based buffer overflow in Azure Linux Virtual Machines allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2026-23664 | HIGH 7.5 | microsoft azure_iot_explorer Improper restriction of communication channel to intended endpoints in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2026-23663 | HIGH 7.5 | microsoft global_secure_access Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network. | 0,6% | — |
| CVE-2026-23662 | HIGH 7.5 | microsoft azure_iot_explorer Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. | 0,7% | — |
| CVE-2026-23661 | HIGH 7.5 | microsoft azure_iot_explorer Cleartext transmission of sensitive information in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. | 0,7% | — |
| CVE-2026-23660 | HIGH 7.8 | microsoft windows_admin_center Improper access control in Azure Portal Windows Admin Center allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-23659 | HIGH 8.6 | microsoft azure_data_factory Exposure of sensitive information to an unauthorized actor in Azure Data Factory allows an unauthorized attacker to disclose information over a network. | 0,8% | — |
| CVE-2026-23658 | HIGH 8.6 | microsoft azure_devops Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a network. | 0,8% | — |
| CVE-2026-23657 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2026-23656 | MED 5.9 | microsoft windows_app Insufficient verification of data authenticity in Windows App Installer allows an unauthorized attacker to perform spoofing over a network. | 0,3% | — |
| CVE-2026-23655 | MED 6.5 | microsoft confidential_sidecar_containers Cleartext storage of sensitive information in Azure Compute Gallery allows an authorized attacker to disclose information over a network. | 1,0% | — |