EN
56.580 CVE seguite
773 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia

CVE Tracker

56.580 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordinato dal più basso
CVE-2026-56139 MED 5.3 apache camel Generation of Error Message Containing Sensitive Information vulnerability in Apache Camel Undertow Component. The camel-undertow HTTP server consumer exposes a muteException option that controls what is returned to the client when a route processing error oc 0,5%
CVE-2026-55994 HIGH 7.5 apache camel Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel in Iggy component. The camel-iggy consumer mapped the user-headers of inbound Iggy messages into the Camel 0,6%
CVE-2026-55993 HIGH 7.5 apache camel Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel in Atmosphere Websocket Component. The camel-atmosphere-websocket consumer mapped inbound WebSocket query p 0,8%
CVE-2026-55971 CRIT 9.8 apache thrift Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. 1,0%
CVE-2026-55970 MED 6.5 apache thrift Buffer Over-read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. 0,8%
CVE-2026-55969 HIGH 7.5 apache thrift Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi and Haxe bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. 1,1%
CVE-2026-55968 HIGH 7.5 apache thrift Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Node.js bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the iss 1,1%
CVE-2026-55957 HIGH 7.3 apache tomcat Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authenticate binds using GSSAPI allowed attackers to authenticate without provided the correct password. This issue affects Apache Tomcat: from 11.0.0- 2,9%
CVE-2026-55956 MED 6.5 apache tomcat Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of the constraint. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22 1,5%
CVE-2026-55955 MED 6.5 apache tomcat Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.13 through 9. 0,5%
CVE-2026-55949 HIGH 7.8 microsoft 365_apps Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0,3%
CVE-2026-55948 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0,3%
CVE-2026-55947 HIGH 7.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0,3%
CVE-2026-55945 MED 4.2 microsoft edge_chromium Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to disclose information locally. 0,1%
CVE-2026-55944 CRIT 9.8 microsoft dynamics_nav Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network. 1,3%
CVE-2026-55899 HIGH 7.8 microsoft 365_apps Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0,3%
CVE-2026-55898 MED 6.1 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 0,3%
CVE-2026-55814 HIGH 7.5 apache ranger Missing Authentication in Apache Ranger Download APIs on versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue. 0,5%
CVE-2026-55799 CRIT 9.8 apache ranger Remote Code Execution Vulnerability in GraalScriptEngineCreator in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue. 0,9%
CVE-2026-55723 HIGH 8.3 f5 nginx_ingress_controller When NGINX Ingress Controller is configured with Custom Resource Definitions (CRDs) or Ingress annotations, an injection vulnerability exists in the configuration generator of NGINX Ingress Controller. Multiple user-controllable fields are written into the gen 0,3%
CVE-2026-55276 CRIT 9.1 apache tomcat Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisation constraints were not included when the effective web.xml was logged. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, 0,5%
CVE-2026-55145 MED 6.3 microsoft copilot Improper neutralization of special elements used in a command ('command injection') in Outlook Copilot allows an authorized attacker to perform tampering over a network. 0,4%
CVE-2026-55144 HIGH 7.1 microsoft windows_11_24h2 Missing cryptographic step in Windows CryptoAPI allows an authorized attacker to perform tampering locally. 0,2%
CVE-2026-55142 MED 5.5 microsoft 365_apps Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to disclose information locally. 0,4%
CVE-2026-55141 HIGH 7.8 microsoft 365_apps Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0,3%