56.580 CVE seguite
773 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.580 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2026-56649 | MED 5.9 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Network File System allows an unauthorized attacker to execute code over a network. | 0,7% | — |
| CVE-2026-56648 | HIGH 7.5 | microsoft windows_10_1607 Time-of-check time-of-use (toctou) race condition in Windows Network File System allows an authorized attacker to elevate privileges over a network. | 0,5% | — |
| CVE-2026-56647 | HIGH 8.8 | microsoft windows_10_1607 Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized attacker to elevate privileges over a network. | 0,9% | — |
| CVE-2026-56646 | MED 6.5 | microsoft edge_chromium Exposure of sensitive information to an unauthorized actor in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | 0,7% | — |
| CVE-2026-56645 | HIGH 8.8 | microsoft edge_chromium Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0,6% | — |
| CVE-2026-56644 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-56643 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-56642 | HIGH 8.8 | microsoft fabric_data_warehouse Stack-based buffer overflow in Microsoft Fabric Data Warehouse allows an authorized attacker to execute code over a network. | 0,9% | — |
| CVE-2026-56624 | HIGH 7.3 | apache mina_sshd Improper certificate validation in Apache MINA SSHD (server-side). Apache MINA SSHD is a Java library for client-side and server-side SSH. Server-side OpenSSH user certificate validation during user authentication in an Apache MINA SSHD server did not chec | 0,2% | — |
| CVE-2026-56623 | HIGH 7.1 | apache mina_sshd Path traversal on Windows in Apache MINA SSHD component sshd-git. Apache MINA SSHD is a Java library for client-side and server-side SSH. A git server implemented with Apache MINA SSHD component sshd-git and running on Windows could allow an authenticated | 0,6% | — |
| CVE-2026-56452 | HIGH 7.5 | apache mina_sshd Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH. The implementation of receiving files or directories via SCP did not validate filenames in SCP "C" or "D" commands. A mali | 0,6% | — |
| CVE-2026-56434 | MED 6.5 | f5 nginx_gateway_fabric NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side Includes (SSI), proxy_pass, and proxy_buffering off directives are configured. With this configuration, an unauthenticate | 0,4% | — |
| CVE-2026-56287 | HIGH 8.1 | apache fineract A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/v1/clients) in versions up to and including 1.14.0. The orderBy and sortOrder request parameters are concatenated into a SQL query without sufficient validation | 0,5% | — |
| CVE-2026-56197 | HIGH 8.8 | microsoft windows_admin_center Improper neutralization of special elements used in a command ('command injection') in Windows Admin Center allows an authorized attacker to execute code over a network. | 0,9% | — |
| CVE-2026-56196 | HIGH 8.8 | microsoft windows_admin_center Relative path traversal in Windows Admin Center allows an authorized attacker to execute code over a network. | 1,0% | — |
| CVE-2026-56195 | MED 5.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-56194 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over a network. | 0,9% | — |
| CVE-2026-56193 | HIGH 7.1 | microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-56192 | MED 5.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-56191 | CRIT 10.0 | microsoft exchange_online Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network. | 0,7% | — |
| CVE-2026-56190 | CRIT 9.8 | microsoft windows_10_1607 Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network. | 1,1% | — |
| CVE-2026-56189 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2026-56188 | CRIT 9.8 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized attacker to execute code over a network. | 0,9% | — |
| CVE-2026-56187 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-56186 | HIGH 8.1 | microsoft windows_10_1607 Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network. | 1,1% | — |