56.571 CVE seguite
773 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.571 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più alto |
|---|---|---|---|---|
| CVE-2026-62714 | MED 6.5 | microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. | 0,5% | — |
| CVE-2026-62713 | HIGH 7.8 | microsoft windows_10_1809 Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. | 1,9% | — |
| CVE-2026-62712 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2026-62711 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-62710 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-62709 | MED 5.5 | microsoft windows_10_1607 Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-62708 | MED 6.4 | microsoft windows_11_24h2 Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack. | 0,3% | — |
| CVE-2026-62707 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-62705 | HIGH 7.0 | microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-62703 | MED 5.5 | microsoft windows_10_1809 Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-62702 | MED 6.8 | microsoft windows_10_21h2 Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network. | 0,9% | — |
| CVE-2026-62701 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-62700 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-62699 | MED 6.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an unauthorized attacker to execute code with a physical attack. | 0,4% | — |
| CVE-2026-62698 | HIGH 7.8 | microsoft windows_10_1607 Numeric truncation error in Microsoft Digest Authentication allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2026-62696 | HIGH 7.8 | microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally. | 3,2% | — |
| CVE-2026-62695 | HIGH 7.8 | microsoft windows_11_23h2 Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-62693 | HIGH 7.0 | microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-62692 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-62690 | HIGH 7.0 | microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-62688 | HIGH 7.8 | microsoft windows_11_24h2 Heap-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2026-62418 | HIGH 8.1 | apache syncope Low-privileged authenticated Server-Side Request Forgery (SSRF) vulnerability in Apache Syncope via Connectors and Resources check. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1. | 0,3% | — |
| CVE-2026-62393 | MED 4.3 | apache kylin Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kylin. Improper authorization in job information retrieval, where an attacker may get access to unauthorized jobs in other projects. This issue affects Apache Kylin: from 4 th | 0,3% | — |
| CVE-2026-62392 | CRIT 9.8 | apache kylin Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A backend API may bring job config parameters to OS command line. This issue affects Apache Kylin: from 4 through 5.0.3. Users are recom | 1,3% | — |
| CVE-2026-62391 | HIGH 8.1 | apache kyuubi The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allowlist via unprefixed Spark config aliases. This issue affects Apache | 0,5% | — |