56.571 CVE seguite
773 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.571 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-42898 | CRIT 9.9 | microsoft dynamics_365 Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network. | 1,2% | — |
| CVE-2026-42823 | CRIT 9.9 | microsoft azure_logic_apps Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network. | 0,6% | — |
| CVE-2026-42812 | CRIT 9.9 | apache polaris In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table and which table version to read. `write.metadata.path` is an optional table property that tells Polaris where to write those metadata fil | 0,4% | — |
| CVE-2026-42811 | CRIT 9.9 | apache polaris In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials that only work for one table's files, but a crafted namespace or table name can cause those credentials to work across the configured bucket instead. Apache Polaris builds Google | 0,4% | — |
| CVE-2026-42810 | CRIT 9.9 | apache polaris Apache Polaris accepts literal `*` characters in namespace and table names. When it later builds temporary S3 access policies for delegated table access, those same characters appear to be reused unescaped in S3 IAM resource patterns and `s3:prefix` conditions | 0,4% | — |
| CVE-2026-42809 | CRIT 9.9 | apache polaris Apache Polaris can issue broad temporary ("vended") storage credentials during staged table creation before the effective table location has been validated or durably reserved. Those temporary credentials are meant to limit the scope of accessible table data | 0,4% | — |
| CVE-2026-40453 | CRIT 9.9 | apache camel The fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant header names such as 'CAmelExecCommandExecutable' are filtered out alongside 'CamelExecCommandExecutable'. The same setLowerCase(true) call was not applied to | 1,6% | — |
| CVE-2026-40411 | CRIT 9.9 | microsoft azure_virtual_network_gateway Improper input validation in Azure Virtual Network Gateway allows an authorized attacker to execute code over a network. | 0,5% | — |
| CVE-2026-33109 | CRIT 9.9 | microsoft azure_managed_instance_for_apache_cassandra Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network. | 0,7% | — |
| CVE-2026-2749 | CRIT 9.9 | centreon open_tickets Vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centroen Open Ticket modules).This issue affects Centreon Open Tickets on Central Server: from all before 25.10.3, 24.10.8, 24.04.7. | 0,5% | — |
| CVE-2026-26137 | CRIT 9.9 | microsoft 365_copilot_chat Server-side request forgery (ssrf) in Microsoft Exchange allows an authorized attacker to elevate privileges over a network. | 0,5% | — |
| CVE-2026-26030 | CRIT 9.9 | microsoft semantic_kernel Semantic Kernel, Microsoft's semantic kernel Python SDK, has a remote code execution vulnerability in versions prior to 1.39.4, specifically within the `InMemoryVectorStore` filter functionality. The problem has been fixed in version `python-1.39.4`. Users sho | 3,7% | — |
| CVE-2026-24304 | CRIT 9.9 | microsoft azure_resource_manager Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network. | 0,6% | — |
| CVE-2026-21515 | CRIT 9.9 | microsoft azure_iot_central Exposure of sensitive information to an unauthorized actor in Azure IOT Central allows an authorized attacker to elevate privileges over a network. | 0,7% | — |
| CVE-2026-20186 | CRIT 9.9 | cisco identity_services_engine A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have at least Read On | 6,3% | — |
| CVE-2026-20180 | CRIT 9.9 | cisco identity_services_engine A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have at least Read On | 6,4% | — |
| CVE-2026-20147 | CRIT 9.9 | cisco identity_services_engine A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrative cred | 11,7% | — |
| CVE-2026-0284 | CRIT 9.9 | paloaltonetworks pan-os An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to inject malicious XML content, potentially leading to information disclosure or corrupt | 0,3% | — |
| CVE-2025-64663 | CRIT 9.9 | microsoft azure_language Custom Question Answering Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2025-55315 | CRIT 9.9 | microsoft asp.net_core Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network. | 65,8% | — |
| CVE-2025-49747 | CRIT 9.9 | microsoft azure_machine_learning Missing authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network. | 0,7% | — |
| CVE-2025-49746 | CRIT 9.9 | microsoft azure_machine_learning Improper authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network. | 0,7% | — |
| CVE-2025-49708 | CRIT 9.9 | microsoft windows_10_1809 Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges over a network. | 1,2% | — |
| CVE-2025-30390 | CRIT 9.9 | microsoft azure_machine_learning Improper authorization in Azure allows an authorized attacker to elevate privileges over a network. | 0,9% | — |
| CVE-2025-29972 | CRIT 9.9 | microsoft azure_storage_resource_provider Server-side request forgery (ssrf) in Azure Storage Resource Provider allows an authorized attacker to perform spoofing over a network. | 3,2% | — |