EN
58.507 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.507 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2026-50690 MED 5.5 microsoft windows_10_1607 Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally. 0,4% —
CVE-2026-50455 MED 5.5 microsoft windows_10_1607 Use of uninitialized resource in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally. 0,4% —
CVE-2026-50437 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. 0,4% —
CVE-2026-50401 MED 5.5 microsoft windows_10_1809 Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to disclose information locally. 0,4% —
CVE-2026-50383 MED 6.1 microsoft windows_10_1809 Buffer over-read in Windows Print Spooler Components allows an authorized attacker to disclose information locally. 0,4% —
CVE-2026-50341 MED 5.5 microsoft windows_10_1607 Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally. 0,4% —
CVE-2026-58614 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature locally. 0,4% —
CVE-2026-54997 MED 5.5 microsoft windows_10_1607 Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally. 0,4% —
CVE-2026-50381 MED 5.5 microsoft windows_10_21h2 Access of resource using incompatible type ('type confusion') in Composite Image File System Driver allows an authorized attacker to disclose information locally. 0,4% —
CVE-2026-50300 MED 5.5 microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information locally. 0,4% —
CVE-2026-49801 MED 5.5 microsoft windows_10_1607 Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally. 0,4% —
CVE-2026-40422 MED 5.5 microsoft windows_10_1607 Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally. 0,4% —
CVE-2026-48566 MED 5.5 microsoft windows_11_24h2 Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. 0,4% —
CVE-2026-45634 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows DHCP Server allows an authorized attacker to disclose information locally. 0,4% —
CVE-2026-45604 MED 5.5 microsoft windows_11_23h2 Out-of-bounds read in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally. 0,4% —
CVE-2026-44814 MED 5.5 microsoft windows_11_26h1 Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. 0,4% —
CVE-2026-42969 MED 5.5 microsoft windows_10_1607 Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally. 0,4% —
CVE-2026-42968 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows Telephony Service allows an authorized attacker to disclose information locally. 0,4% —
CVE-2026-41954 MED 4.9 f5 big-ip_access_policy_manager Sensitive information disclosure vulnerability exists in the undisclosed iControl REST endpoint and TMOS Shell (tmsh) command which may allow an authenticated attacker with resource administrator role privileges to view sensitive information.  Note: Software v 0,4% —
CVE-2026-35419 MED 5.5 microsoft windows_11_24h2 Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. 0,4% —
CVE-2026-7899 HIGH 8.8 google chrome Out of bounds read and write in V8 in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) 0,4% —
CVE-2025-62570 HIGH 7.1 microsoft windows_11_24h2 Improper access control in Windows Camera Frame Server Monitor allows an authorized attacker to disclose information locally. 0,4% —
CVE-2025-39758 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Fix the sendmsg byte count in siw_tcp_sendpages Ever since commit c2ff29e99a76 ("siw: Inline do_tcp_sendpages()"), we have been doing this: static int siw_tcp_sendpages(struct soc 0,4% —
CVE-2025-21159 HIGH 7.8 adobe illustrator Illustrator versions 29.1, 28.7.3 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a mal 0,4% —
CVE-2024-4454 HIGH 7.8 withsecure client_security WithSecure Elements Endpoint Protection Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of WithSecure Elements Endpoint Protection. User interaction on the part 0,4% —