58.306 CVE seguite
790 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.306 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-72954 | HIGH 7.5 | microsoft windows_10_1607 Use after free in Windows Deployment Services allows an authorized attacker to execute code over a network. | 0,6% | — |
| CVE-2026-56192 | MED 5.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | 0,6% | — |
| CVE-2026-55142 | MED 5.5 | microsoft 365_apps Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | 0,6% | — |
| CVE-2026-55124 | MED 5.5 | microsoft 365_apps Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | 0,6% | — |
| CVE-2026-55050 | MED 5.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | 0,6% | — |
| CVE-2026-55047 | MED 5.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | 0,6% | — |
| CVE-2026-55028 | MED 5.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | 0,6% | — |
| CVE-2026-55027 | MED 5.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | 0,6% | — |
| CVE-2026-55023 | MED 5.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | 0,6% | — |
| CVE-2025-59258 | MED 6.2 | microsoft windows_server_2012 Insertion of sensitive information into log file in Active Directory Federation Services allows an unauthorized attacker to disclose information locally. | 0,6% | — |
| CVE-2025-49729 | HIGH 8.8 | microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | 0,6% | — |
| CVE-2025-27728 | HIGH 7.8 | microsoft windows_11_24h2 Out-of-bounds read in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. | 0,6% | — |
| CVE-2025-27490 | HIGH 7.8 | microsoft windows_10_21h2 Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. | 0,6% | — |
| CVE-2025-24074 | HIGH 7.8 | microsoft windows_10_1809 Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | 0,6% | — |
| CVE-2025-24073 | HIGH 7.8 | microsoft windows_10_1507 Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | 0,6% | — |
| CVE-2025-24062 | HIGH 7.8 | microsoft windows_10_21h2 Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | 0,6% | — |
| CVE-2025-24060 | HIGH 7.8 | microsoft windows_10_1809 Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | 0,6% | — |
| CVE-2025-24058 | HIGH 7.8 | microsoft windows_10_1809 Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | 0,6% | — |
| CVE-2024-38016 | HIGH 7.8 | microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability | 0,6% | — |
| CVE-2022-41083 | HIGH 7.8 | microsoft jupyter Visual Studio Code Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2022-37999 | HIGH 7.8 | microsoft windows_10 Windows Group Policy Preference Client Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2022-37994 | HIGH 7.8 | microsoft windows_10 Windows Group Policy Preference Client Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2022-37993 | HIGH 7.8 | microsoft windows_10 Windows Group Policy Preference Client Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2021-41032 | MED 6.3 | fortinet fortios An improper access control vulnerability [CWE-284] in FortiOS versions 6.4.8 and prior and 7.0.3 and prior may allow an authenticated attacker with a restricted user profile to gather sensitive information and modify the SSL-VPN tunnel status of other VDOMs us | 0,6% | — |
| CVE-2021-26608 | HIGH 8.8 | handysoft hshell An arbitrary file download and execution vulnerability was found in the HShell.dll of handysoft Co., Ltd groupware ActiveX module. This issue is due to missing support for integrity check of download URL or downloaded file hash. | 0,6% | — |