57.479 CVE seguite
782 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.479 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più alto |
|---|---|---|---|---|
| CVE-2025-58742 | MED 5.9 | milner imagedirector_capture Insufficiently Protected Credentials, Improper Restriction of Communication Channel to Intended Endpoints vulnerability in the Connection Settings dialog in Milner ImageDirector Capture on Windows allows Adversary in the Middle (AiTM) by modifying the 'Server' | 0,2% | — |
| CVE-2025-58740 | MED 5.5 | milner imagedirector_capture The use of a hard-coded encryption key in calls to the Password function in C2SGlobalSettings.dll in Milner ImageDirector Capture on Windows allows a local attacker to decrypt database credentials by reading the cryptographic key from the executable. This iss | 0,1% | — |
| CVE-2025-58739 | MED 6.5 | microsoft windows_10_1507 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network. | 0,8% | — |
| CVE-2025-58738 | HIGH 7.0 | microsoft windows_10_1507 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. | 0,3% | — |
| CVE-2025-58737 | HIGH 7.0 | microsoft windows_server_2012 Use after free in Windows Remote Desktop allows an unauthorized attacker to execute code locally. | 0,3% | — |
| CVE-2025-58736 | HIGH 7.0 | microsoft windows_10_1507 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. | 0,3% | — |
| CVE-2025-58735 | HIGH 7.0 | microsoft windows_10_1507 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2025-58734 | HIGH 7.0 | microsoft windows_10_1507 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. | 0,3% | — |
| CVE-2025-58733 | HIGH 7.0 | microsoft windows_10_1507 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. | 0,3% | — |
| CVE-2025-58732 | HIGH 7.0 | microsoft windows_10_1507 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2025-58731 | HIGH 7.0 | microsoft windows_11_22h2 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. | 0,3% | — |
| CVE-2025-58730 | HIGH 7.0 | microsoft windows_10_1507 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. | 0,3% | — |
| CVE-2025-58729 | MED 6.5 | microsoft windows_10_1507 Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network. | 1,0% | — |
| CVE-2025-58728 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-58727 | HIGH 7.0 | microsoft windows_10_21h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2025-58726 | HIGH 7.5 | microsoft windows_10_1507 Improper access control in Windows SMB Server allows an authorized attacker to elevate privileges over a network. | 1,0% | — |
| CVE-2025-58725 | HIGH 7.0 | microsoft windows_10_1507 Heap-based buffer overflow in Windows COM allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2025-58724 | HIGH 7.8 | microsoft azure_connected_machine_agent Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally. | 0,5% | — |
| CVE-2025-58722 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows DWM allows an authorized attacker to elevate privileges locally. | 2,1% | — |
| CVE-2025-58720 | HIGH 7.8 | microsoft windows_10_1809 Use of a cryptographic primitive with a risky implementation in Windows Cryptographic Services allows an authorized attacker to disclose information locally. | 0,2% | — |
| CVE-2025-58719 | MED 4.7 | microsoft windows_10_1607 Use after free in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-58718 | HIGH 8.8 | microsoft remote_desktop_client Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 0,6% | — |
| CVE-2025-58717 | MED 6.5 | microsoft windows_10_1507 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 0,9% | — |
| CVE-2025-58716 | HIGH 8.8 | microsoft windows_10_1507 Improper input validation in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-58715 | HIGH 8.8 | microsoft windows_10_1507 Integer overflow or wraparound in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally. | 0,4% | — |