56.571 CVE seguite
773 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.571 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più alto |
|---|---|---|---|---|
| CVE-2026-5915 | HIGH 8.1 | google chrome Insufficient validation of untrusted input in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Low) | 0,2% | — |
| CVE-2026-5914 | HIGH 8.8 | google chrome Type Confusion in CSS in Google Chrome prior to 147.0.7727.55 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Low) | 0,2% | — |
| CVE-2026-59138 | MED 6.5 | microsoft windows_10_1607 Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network. | 1,0% | — |
| CVE-2026-59137 | MED 5.5 | microsoft windows_10_1607 Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-59136 | MED 5.5 | microsoft windows_10_1607 Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-59135 | MED 5.5 | microsoft windows_10_1607 Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally. | 0,3% | — |
| CVE-2026-59134 | HIGH 7.5 | microsoft windows_10_1607 Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 0,6% | — |
| CVE-2026-59133 | HIGH 8.8 | microsoft windows_app Execution with unnecessary privileges in Microsoft High Performance Computing (HPC) Pack allows an authorized attacker to elevate privileges over a network. | 0,9% | — |
| CVE-2026-59132 | HIGH 7.5 | microsoft windows_10_1607 Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network. | 1,3% | — |
| CVE-2026-59131 | MED 5.6 | microsoft windows_10_1607 No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally. | 0,3% | — |
| CVE-2026-59130 | MED 5.6 | microsoft windows_10_1607 No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally. | 0,3% | — |
| CVE-2026-5913 | HIGH 8.1 | google chrome Out of bounds read in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Low) | 0,2% | — |
| CVE-2026-59128 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-59127 | HIGH 7.8 | microsoft windows_10_1607 Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-59126 | HIGH 7.0 | microsoft windows_10_21h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event Logging Service allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-59125 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-59124 | CRIT 9.8 | microsoft windows_app Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network. | 1,7% | — |
| CVE-2026-59122 | HIGH 7.0 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-5912 | HIGH 8.8 | google chrome Integer overflow in WebRTC in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Low) | 0,2% | — |
| CVE-2026-59119 | HIGH 7.3 | microsoft powershell Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2026-59118 | CRIT 9.3 | microsoft power_apps Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network. | 0,4% | — |
| CVE-2026-59117 | HIGH 7.5 | microsoft terminal Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code over a network. | 0,4% | — |
| CVE-2026-59115 | CRIT 9.9 | microsoft entra_provisioning_service '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. | 0,6% | — |
| CVE-2026-59113 | HIGH 8.8 | microsoft visual_studio_code Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network. | 0,7% | — |
| CVE-2026-5911 | MED 4.3 | google chrome Policy bypass in ServiceWorkers in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low) | 0,2% | — |