Database CVE
Archivio delle vulnerabilità note (CVE) con punteggio CVSS, gravità, prodotti e vendor coinvolti. Filtra per anno e severità, collegato ai nostri articoli.
- CVE-2026-32194Critica9.8
Neutralizzazione impropria di elementi speciali utilizzati in un comando ('command injection') in Microsoft Bing Images consente a un attaccante non autorizzato di eseguire codice su una rete.
- CVE-2026-32191Critica9.8
Neutralizzazione impropria di elementi speciali utilizzati in un comando del sistema operativo ('os command injection') in Microsoft Bing Images consente a un attaccante non autorizzato di eseguire codice tramite rete.
- CVE-2026-3910Alta8.8
Implementazione inappropriata in V8 in Google Chrome prima di 146.0.7680.75 ha consentito a un attaccante remoto di eseguire codice arbitrario all'interno di una sandbox tramite una pagina HTML appositamente creata. (Gravità di sicurezza di Chromium: Alta)
- CVE-2026-3909Alta8.8
Scrittura out of bounds in Skia in Google Chrome precedente alla 146.0.7680.75 ha consentito a un attaccante remoto di eseguire un accesso alla memoria out of bounds tramite una pagina HTML appositamente creata. (Gravità di sicurezza di Chromium: Alta)
- CVE-2025-67038Critica9.8
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authentication fails. The username is directly concatenated with the command without any sanitization. This allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.
- CVE-2026-3545Critica9.6
Convalida dei dati insufficiente in Navigation in Google Chrome prima di 145.0.7632.159 ha consentito a un attaccante remoto di eseguire potenzialmente un sandbox escape tramite una pagina HTML appositamente creata. (Gravità di sicurezza di Chromium: Alta)
- CVE-2026-20131Critica10.0
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream. An attacker could exploit this vulnerability by sending a crafted serialized Java object to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root. Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.
- CVE-2026-20079Critica10.0
Una vulnerabilità nell'interfaccia web di Cisco Secure Firewall Management Center (FMC) Software potrebbe consentire a un attaccante remoto non autenticato di aggirare l'autenticazione ed eseguire file di script su un dispositivo interessato per ottenere l'accesso root al sistema operativo sottostante. Questa vulnerabilità è dovuta a un processo di sistema improprio creato al momento dell'avvio. Un attaccante potrebbe sfruttare questa vulnerabilità inviando richieste HTTP appositamente create a un dispositivo interessato. Uno sfruttamento riuscito potrebbe consentire all'attaccante di eseguire una varietà di script e comandi che consentono l'accesso root al dispositivo.
- CVE-2026-21385Alta7.8
Memory corruption while using alignments for memory allocation.
- CVE-2026-22719Alta8.1
VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress. To remediate CVE-2026-22719, apply the patches listed in the 'Fixed Version' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001 Workarounds for CVE-2026-22719 are documented in the 'Workarounds' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001
- CVE-2026-20133Media6.5
A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system. This vulnerability is due to insufficient file system restrictions. An authenticated attacker with netadmin privileges could exploit this vulnerability by accessing the vshell of an affected system. A successful exploit could allow the attacker to read sensitive information on the underlying operating system.
- CVE-2026-20128Alta7.5
A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain DCA user privileges on an affected system. This vulnerability is due to the presence of a credential file for the DCA user on an affected system. An attacker could exploit this vulnerability by sending a crafted HTTP request and reading the file that contains the DCA password from that affected system. A successful exploit could allow the attacker to access another affected system and gain DCA user privileges. Note: Cisco Catalyst SD-WAN Manager releases 20.18 and later are not affected by this vulnerability.
- CVE-2026-20127Critica10.0
A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to an affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric.
- CVE-2026-20122Media5.4
A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local file system. To exploit this vulnerability, the attacker must have valid read-only credentials with API access on the affected system. This vulnerability is due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on the affected system and gain vmanage user privileges.
- CVE-2026-22769Critica10.0
Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. This is considered critical as an unauthenticated remote attacker with knowledge of the hardcoded credential could potentially exploit this vulnerability leading to unauthorized access to the underlying operating system and root-level persistence. Dell recommends that customers upgrade or apply one of the remediations as soon as possible.
- CVE-2026-2441Alta8.8
Use after free in CSS in Google Chrome prima della versione 145.0.7632.75 ha permesso a un attaccante remoto di eseguire codice arbitrario all'interno di una sandbox tramite una pagina HTML appositamente creata. (Gravità di sicurezza di Chromium: Alta)
- CVE-2026-25108Alta8.8
FileZen contains an OS command injection vulnerability. When FileZen Antivirus Check Option is enabled, a logged-in user may send a specially crafted HTTP request to execute an arbitrary OS command.
- CVE-2025-9293Alta8.1
Una vulnerabilità nella logica di convalida dei certificati potrebbe consentire alle applicazioni di accettare identità server non attendibili o convalidate in modo improprio durante la comunicazione TLS. Un attaccante in una posizione di rete privilegiata potrebbe essere in grado di intercettare o modificare il traffico se riesce a posizionarsi all'interno del canale di comunicazione. Lo sfruttamento riuscito potrebbe compromettere la riservatezza, l'integrità e la disponibilità dei dati dell'applicazione.
- CVE-2026-20700Alta7.8
Un problema di danneggiamento della memoria è stato risolto migliorando la gestione dello stato. Questo problema è stato corretto in iOS 26.3 e iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. Un attaccante con capacità di scrittura in memoria potrebbe essere in grado di eseguire codice arbitrario. Apple è a conoscenza di una segnalazione secondo cui questo problema potrebbe essere stato sfruttato in un attacco estremamente sofisticato contro specifici individui presi di mira su versioni di iOS precedenti a iOS 26. CVE-2025-14174 e CVE-2025-43529 sono stati emessi anche in risposta a questa segnalazione.
- CVE-2026-21533Alta7.8
Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.
This product uses the NVD API but is not endorsed or certified by the NVD.