EN
56.571 CVE seguite
773 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia

CVE Tracker

56.571 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordinato dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2026-42898 CRIT 9.9 microsoft dynamics_365 Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network. 1,2%
CVE-2026-42823 CRIT 9.9 microsoft azure_logic_apps Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network. 0,6%
CVE-2026-42812 CRIT 9.9 apache polaris In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table and which table version to read. `write.metadata.path` is an optional table property that tells Polaris where to write those metadata fil 0,4%
CVE-2026-42811 CRIT 9.9 apache polaris In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials that only work for one table's files, but a crafted namespace or table name can cause those credentials to work across the configured bucket instead. Apache Polaris builds Google 0,4%
CVE-2026-42810 CRIT 9.9 apache polaris Apache Polaris accepts literal `*` characters in namespace and table names. When it later builds temporary S3 access policies for delegated table access, those same characters appear to be reused unescaped in S3 IAM resource patterns and `s3:prefix` conditions 0,4%
CVE-2026-42809 CRIT 9.9 apache polaris Apache Polaris can issue broad temporary ("vended") storage credentials during staged table creation before the effective table location has been validated or durably reserved. Those temporary credentials are meant to limit the scope of accessible table data 0,4%
CVE-2026-40453 CRIT 9.9 apache camel The fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant header names such as 'CAmelExecCommandExecutable' are filtered out alongside 'CamelExecCommandExecutable'. The same setLowerCase(true) call was not applied to 1,6%
CVE-2026-40411 CRIT 9.9 microsoft azure_virtual_network_gateway Improper input validation in Azure Virtual Network Gateway allows an authorized attacker to execute code over a network. 0,5%
CVE-2026-33109 CRIT 9.9 microsoft azure_managed_instance_for_apache_cassandra Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network. 0,7%
CVE-2026-2749 CRIT 9.9 centreon open_tickets Vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centroen Open Ticket modules).This issue affects Centreon Open Tickets on Central Server: from all before 25.10.3, 24.10.8, 24.04.7. 0,5%
CVE-2026-26137 CRIT 9.9 microsoft 365_copilot_chat Server-side request forgery (ssrf) in Microsoft Exchange allows an authorized attacker to elevate privileges over a network. 0,5%
CVE-2026-26030 CRIT 9.9 microsoft semantic_kernel Semantic Kernel, Microsoft's semantic kernel Python SDK, has a remote code execution vulnerability in versions prior to 1.39.4, specifically within the `InMemoryVectorStore` filter functionality. The problem has been fixed in version `python-1.39.4`. Users sho 3,7%
CVE-2026-24304 CRIT 9.9 microsoft azure_resource_manager Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network. 0,6%
CVE-2026-21515 CRIT 9.9 microsoft azure_iot_central Exposure of sensitive information to an unauthorized actor in Azure IOT Central allows an authorized attacker to elevate privileges over a network. 0,7%
CVE-2026-20186 CRIT 9.9 cisco identity_services_engine A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have at least Read On 6,3%
CVE-2026-20180 CRIT 9.9 cisco identity_services_engine A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have at least Read On 6,4%
CVE-2026-20147 CRIT 9.9 cisco identity_services_engine A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrative cred 11,7%
CVE-2026-0284 CRIT 9.9 paloaltonetworks pan-os An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to inject malicious XML content, potentially leading to information disclosure or corrupt 0,3%
CVE-2025-64663 CRIT 9.9 microsoft azure_language Custom Question Answering Elevation of Privilege Vulnerability 0,7%
CVE-2025-55315 CRIT 9.9 microsoft asp.net_core Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network. 65,8%
CVE-2025-49747 CRIT 9.9 microsoft azure_machine_learning Missing authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network. 0,7%
CVE-2025-49746 CRIT 9.9 microsoft azure_machine_learning Improper authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network. 0,7%
CVE-2025-49708 CRIT 9.9 microsoft windows_10_1809 Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges over a network. 1,2%
CVE-2025-30390 CRIT 9.9 microsoft azure_machine_learning Improper authorization in Azure allows an authorized attacker to elevate privileges over a network. 0,9%
CVE-2025-29972 CRIT 9.9 microsoft azure_storage_resource_provider Server-side request forgery (ssrf) in Azure Storage Resource Provider allows an authorized attacker to perform spoofing over a network. 3,2%