EN
56.571 CVE seguite
773 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia

CVE Tracker

56.571 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordinato dal più basso
CVE-2026-62390 CRIT 9.8 apache kylin Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. A backend API refreshing table catalog may cause the injection to the generated SQL. This issue affects Apache Kylin: from 4 through 5.0.3. Us 0,4%
CVE-2026-62354 MED 4.3 apache nifi Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients with read access to submit proposed Parameter values. The proposed values override current configuration, enabling users with read access to in 0,3%
CVE-2026-62183 CRIT 9.8 apache syncope Improper Privilege Management vulnerability in Apache Syncope. When: * the all-Java user workflow adapter is configured, or * the Flowable user workflow adapter is configured, bearing a BPMN definition not requiring admin approval for user self registration 0,4%
CVE-2026-61939 HIGH 7.0 microsoft windows_10_1607 Use after free in Winlogon allows an authorized attacker to elevate privileges locally. 0,2%
CVE-2026-61938 HIGH 7.0 microsoft windows_11_24h2 Use after free in Windows Installer allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-61937 HIGH 7.8 microsoft windows_10_1607 Integer overflow or wraparound in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-61936 MED 5.5 microsoft windows_10_1809 Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally. 0,3%
CVE-2026-61934 HIGH 7.8 microsoft windows_11_23h2 Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-61933 MED 5.5 microsoft windows_11_24h2 Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. 0,4%
CVE-2026-61932 HIGH 7.8 microsoft windows_10_1607 Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-61930 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. 2,0%
CVE-2026-61929 HIGH 7.0 microsoft windows_11_23h2 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. 1,5%
CVE-2026-61928 MED 5.5 microsoft windows_10_1607 Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally. 0,2%
CVE-2026-61927 HIGH 7.0 microsoft windows_11_24h2 Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally. 0,2%
CVE-2026-61926 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-61925 HIGH 7.8 microsoft windows_10_1607 Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-61924 MED 6.5 microsoft windows_10_1607 Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. 0,8%
CVE-2026-61923 HIGH 7.8 microsoft windows_10_1809 Heap-based buffer overflow in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-61921 MED 6.5 microsoft windows_10_1607 Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. 0,8%
CVE-2026-61920 MED 6.6 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an authorized attacker to execute code over a network. 0,5%
CVE-2026-61918 MED 6.5 microsoft windows_10_1607 Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. 0,9%
CVE-2026-61899 HIGH 7.5 apache tapestry Vulnerability in tapestry-core in Apache Tapestry 5.5.0+ on all platforms allows attackers to download clsspath assets via specially crafted URLs. Users are recommended to upgrade to version 5.9.1, which fixes this issue. 0,4%
CVE-2026-61487 MED 6.5 apache activemq Improper Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. An authenticated low-privilege user can bypass a per-destination write ACL by sending to an ActiveMQ temporary composite destination whose physical name is 0,5%
CVE-2026-61486 CRIT 9.8 apache lucy ** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an al 0,6%
CVE-2026-61485 HIGH 7.5 apache lucy ** UNSUPPORTED WHEN ASSIGNED ** Memory Allocation with Excessive Size Value vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommend 0,5%