EN
56.571 CVE seguite
773 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia

CVE Tracker

56.571 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordinato dal più basso
CVE-2026-61484 CRIT 9.8 apache lucy ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find 0,6%
CVE-2026-61483 HIGH 7.5 apache lucy ** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alterna 0,5%
CVE-2026-61466 CRIT 9.1 apache cxf In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client registration request verbatim, without validating it against an AS-defined allowlist. This could lead to a client 0,4%
CVE-2026-61372 HIGH 7.5 apache jena_fuseki Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fuseki. This issue affects Apache Jena Fuseki: through 6.1.0. Users are recommended to upgrade to version 6.2.0, which fixes the issue. 0,6%
CVE-2026-61368 MED 5.0 microsoft windows_10_1607 Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally. 0,4%
CVE-2026-61367 HIGH 7.8 microsoft windows_10_1607 Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-61366 HIGH 7.0 microsoft windows_10_1607 Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally. 0,2%
CVE-2026-61365 HIGH 7.8 microsoft windows_10_1607 Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-61364 HIGH 7.8 microsoft windows_10_1607 Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-61363 HIGH 7.5 microsoft windows_10_1607 Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. 0,6%
CVE-2026-61360 MED 5.5 microsoft windows_10_1607 Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally. 0,4%
CVE-2026-61359 HIGH 7.8 microsoft windows_11_23h2 Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-61358 HIGH 7.8 microsoft windows_10_1809 Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally. 3,7%
CVE-2026-61357 HIGH 7.8 microsoft windows_11_24h2 Use after free in Application Information Services allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-61356 HIGH 7.8 microsoft windows_10_1809 Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-61355 HIGH 7.8 microsoft windows_10_21h2 Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-61353 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2026-61352 HIGH 7.5 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network. 0,4%
CVE-2026-61350 MED 4.6 microsoft windows_10_1607 Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack. 0,4%
CVE-2026-61349 HIGH 7.8 microsoft windows_10_1607 Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally. 0,2%
CVE-2026-61348 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 1,6%
CVE-2026-61347 MED 5.5 microsoft windows_10_1607 Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally. 0,4%
CVE-2026-61346 HIGH 7.0 microsoft windows_10_1809 Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally. 0,2%
CVE-2026-61345 MED 6.5 microsoft windows_10_1607 Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network. 1,0%
CVE-2026-6053 MED 5.5 ibm db2 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service when a specially crafted query is run with range partitioned tables. 0,1%