57.490 CVE seguite
782 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.490 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2025-49784 | MED 6.0 | fortinet fortianalyzer An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyze | 0,4% | — |
| CVE-2025-49763 | HIGH 7.5 | apache traffic_server ESI plugin does not have the limit for maximum inclusion depth, and that allows excessive memory consumption if malicious instructions are inserted. Users can use a new setting for the plugin (--max-inclusion-depth) to limit it. This issue affects Apache Traf | 0,7% | — |
| CVE-2025-49762 | HIGH 7.0 | microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2025-49761 | HIGH 7.8 | microsoft windows_10_1507 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-49760 | LOW 3.5 | microsoft windows_10_1507 External control of file name or path in Windows Storage allows an authorized attacker to perform spoofing over a network. | 1,3% | — |
| CVE-2025-49759 | HIGH 8.8 | microsoft sql_server_2016 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | 1,1% | — |
| CVE-2025-49758 | HIGH 8.8 | microsoft sql_server_2016 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | 0,9% | — |
| CVE-2025-49757 | HIGH 8.8 | microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | 1,0% | — |
| CVE-2025-49756 | LOW 3.3 | microsoft 365_apps Use of a broken or risky cryptographic algorithm in Office Developer Platform allows an authorized attacker to bypass a security feature locally. | 0,2% | — |
| CVE-2025-49755 | MED 4.3 | microsoft edge User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network. | 0,5% | — |
| CVE-2025-49753 | HIGH 8.8 | microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | 0,8% | — |
| CVE-2025-49752 | CRIT 10.0 | microsoft azure_bastion_developer Azure Bastion Elevation of Privilege Vulnerability | 0,9% | — |
| CVE-2025-49751 | MED 6.8 | microsoft windows_10_1607 Missing synchronization in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network. | 0,5% | — |
| CVE-2025-49747 | CRIT 9.9 | microsoft azure_machine_learning Missing authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network. | 0,7% | — |
| CVE-2025-49746 | CRIT 9.9 | microsoft azure_machine_learning Improper authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network. | 0,7% | — |
| CVE-2025-49745 | MED 5.4 | microsoft dynamics_365 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to perform spoofing over a network. | 0,5% | — |
| CVE-2025-49744 | HIGH 7.0 | microsoft windows_10_1507 Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | 0,7% | — |
| CVE-2025-49743 | MED 6.7 | microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | 0,5% | — |
| CVE-2025-49742 | HIGH 7.8 | microsoft windows_10_1507 Integer overflow or wraparound in Microsoft Graphics Component allows an authorized attacker to execute code locally. | 0,3% | — |
| CVE-2025-49741 | HIGH 7.4 | microsoft edge_chromium No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | 3,5% | — |
| CVE-2025-49740 | HIGH 8.8 | microsoft windows_10_1507 Protection mechanism failure in Windows SmartScreen allows an unauthorized attacker to bypass a security feature over a network. | 0,8% | — |
| CVE-2025-49739 | HIGH 8.8 | microsoft visual_studio Improper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to elevate privileges over a network. | 0,8% | — |
| CVE-2025-49738 | HIGH 7.8 | microsoft pc_manager Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2025-49737 | HIGH 7.0 | microsoft teams Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Teams allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2025-49736 | MED 4.3 | microsoft edge The ui performs the wrong action in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network. | 0,5% | — |