Database CVE
Archivio delle vulnerabilità note (CVE) con punteggio CVSS, gravità, prodotti e vendor coinvolti. Filtra per anno e severità, collegato ai nostri articoli.
- CVE-2026-21525Media6.2
Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally.
- CVE-2026-21519Alta7.8
Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
- CVE-2026-21514Alta7.8
Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally.
- CVE-2026-21513Alta8.8
Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.
- CVE-2026-21510Alta8.8
Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.
- CVE-2026-1603Alta8.6
An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data.
- CVE-2025-68686Media5.9
Una vulnerabilità di esposizione di informazioni sensibili a un attore non autorizzato [CWE-200] in Fortinet FortiOS dalla 7.6.0 alla 7.6.1, FortiOS dalla 7.4.0 alla 7.4.6, FortiOS 7.2 tutte le versioni, FortiOS 7.0 tutte le versioni, FortiOS 6.4 tutte le versioni potrebbe consentire a un attaccante remoto non autenticato di aggirare la patch sviluppata per il meccanismo di persistenza tramite symbolic link osservato in alcuni casi post-exploit, tramite richieste HTTP appositamente create. Un attaccante dovrebbe prima aver compromesso il prodotto tramite un'altra vulnerabilità, a livello di filesystem.
- CVE-2026-25939Critica9.1
FUXA è un software di visualizzazione dei processi basato sul web (SCADA/HMI/Dashboard). Dalla 1.2.8 alla versione 1.2.10, una vulnerabilità di bypass dell'autorizzazione in FUXA consente a un attaccante remoto non autenticato di creare e modificare scheduler arbitrari, esponendo gli ambienti ICS/SCADA connessi ad azioni successive. Il problema è stato corretto in FUXA versione 1.2.11.
- CVE-2026-25895Critica9.8
FUXA è un software di visualizzazione dei processi basato sul web (SCADA/HMI/Dashboard). Una vulnerabilità di path traversal in FUXA consente a un attaccante remoto non autenticato di scrivere file arbitrari in posizioni arbitrarie sul filesystem del server. Questo interessa FUXA fino alla versione 1.2.9. Questo problema è stato corretto nella versione 1.2.10 di FUXA.
- CVE-2026-1731Critica9.8
BeyondTrust Remote Support (RS) e alcune versioni precedenti di Privileged Remote Access (PRA) contengono una vulnerabilità critica di remote code execution pre-autenticazione. Inviando richieste appositamente create, un attaccante remoto non autenticato potrebbe essere in grado di eseguire comandi del sistema operativo nel contesto dell'utente del sito.
- CVE-2026-25725Critica10.0
Claude Code è uno strumento di programmazione agentico. Prima della versione 2.1.2, il meccanismo di sandboxing bubblewrap di Claude Code non proteggeva correttamente il file di configurazione .claude/settings.json quando non esisteva all'avvio. Mentre la directory padre era montata come scrivibile e .claude/settings.local.json era protetto esplicitamente con vincoli di sola lettura, settings.json non era protetto se mancante. Ciò consentiva al codice malevolo in esecuzione all'interno della sandbox di creare questo file e iniettare hook persistenti (come comandi SessionStart) che sarebbero stati eseguiti con privilegi host al riavvio di Claude Code. Questo problema è stato corretto nella versione 2.1.2.
- CVE-2026-21643Critica9.8
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
- CVE-2025-69981Critica9.8
FUXA v1.2.7 contiene una vulnerabilità di Unrestricted File Upload nell'endpoint API `/api/upload`. L'endpoint è privo di meccanismi di autenticazione, consentendo ad attaccanti remoti non autenticati di caricare file arbitrari. Ciò può essere sfruttato per sovrascrivere file di sistema critici (come il database utenti SQLite) per ottenere l'accesso amministrativo, o per caricare script malevoli per eseguire codice arbitrario.
- CVE-2025-15556Alta7.5
Notepad++ versions prior to 8.8.9, when using the WinGUp updater, contain an update integrity verification vulnerability where downloaded update metadata and installers are not cryptographically verified. An attacker able to intercept or redirect update traffic can cause the updater to download and execute an attacker-controlled installer, resulting in arbitrary code execution with the privileges of the user.
- CVE-2026-1340Critica9.8
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
- CVE-2026-1281Critica9.8
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
- CVE-2025-40551Critica9.8
SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication.
- CVE-2025-40536Alta8.1
SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated attacker to gain access to certain restricted functionality.
- CVE-2026-24858Critica9.8
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9, FortiManager 7.2.0 through 7.2.11, FortiManager 7.0.0 through 7.0.15, FortiNAC-F 7.6.3 through 7.6.5, FortiOS 7.6.0 through 7.6.5, FortiOS 7.4.0 through 7.4.10, FortiOS 7.2.0 through 7.2.12, FortiOS 7.0.0 through 7.0.18, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4.0 through 7.4.12, FortiProxy 7.2.0 through 7.2.15, FortiProxy 7.0.0 through 7.0.22, FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.
- CVE-2026-21509Alta7.8
Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.
This product uses the NVD API but is not endorsed or certified by the NVD.