57.921 CVE seguite
783 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.921 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più alto |
|---|---|---|---|---|
| CVE-2025-33067 | HIGH 8.4 | microsoft windows_10_1507 Improper privilege management in Windows Kernel allows an unauthorized attacker to elevate privileges locally. | 0,5% | — |
| CVE-2025-33066 | HIGH 8.8 | microsoft windows_10_1507 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | 1,1% | — |
| CVE-2025-33065 | MED 5.5 | microsoft windows_10_1507 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | 0,6% | — |
| CVE-2025-33064 | HIGH 8.8 | microsoft windows_10_1507 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. | 1,3% | — |
| CVE-2025-33063 | MED 5.5 | microsoft windows_10_1809 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | 0,6% | — |
| CVE-2025-33062 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | 0,6% | — |
| CVE-2025-33061 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | 0,6% | — |
| CVE-2025-33060 | MED 5.5 | microsoft windows_10_1507 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | 0,6% | — |
| CVE-2025-33059 | MED 5.5 | microsoft windows_10_1507 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | 0,6% | — |
| CVE-2025-33058 | MED 5.5 | microsoft windows_10_1507 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | 0,6% | — |
| CVE-2025-33057 | MED 6.5 | microsoft windows_10_1507 Null pointer dereference in Windows Local Security Authority (LSA) allows an authorized attacker to deny service over a network. | 1,7% | — |
| CVE-2025-33056 | HIGH 7.5 | microsoft windows_10_1507 Improper access control in Microsoft Local Security Authority Server (lsasrv) allows an unauthorized attacker to deny service over a network. | 1,7% | — |
| CVE-2025-33055 | MED 5.5 | microsoft windows_10_1507 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | 0,6% | — |
| CVE-2025-33054 | HIGH 8.1 | microsoft windows_11_22h2 Insufficient UI warning of dangerous operations in Remote Desktop Client allows an unauthorized attacker to perform spoofing over a network. | 0,9% | — |
| CVE-2025-33052 | MED 5.5 | microsoft windows_10_1809 Use of uninitialized resource in Windows DWM Core Library allows an authorized attacker to disclose information locally. | 0,6% | — |
| CVE-2025-33051 | HIGH 7.5 | microsoft exchange_server Exposure of sensitive information to an unauthorized actor in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network. | 1,2% | — |
| CVE-2025-33050 | HIGH 7.5 | microsoft windows_server_2016 Protection mechanism failure in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | 1,8% | — |
| CVE-2025-33042 | HIGH 7.3 | apache avro Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas. This issue affects Apache Avro Java SDK: all versions through 1.11.4 and version 1.12.0. Users are r | 0,6% | — |
| CVE-2025-33014 | MED 5.4 | ibm sterling_b2b_integrator IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.4 uses a web link with untrusted references to an external site. A remote attacker could exploit this vulnerability to expose sensitive information or p | 0,2% | — |
| CVE-2025-32932 | MED 6.5 | fortinet fortisoar An Improper neutralization of input during web page generation ('cross-site scripting') vulnerability [CWE-79] in FortiSOAR version 7.6.1 and below, version 7.5.1 and below, 7.4 all versions, 7.3 all versions, 7.2 all versions, 7.0 all versions, 6.4 all versio | 0,2% | — |
| CVE-2025-32915 | MED 5.5 | checkmk checkmk Packages downloaded by Checkmk's automatic agent updates on Linux and Solaris have incorrect permissions in Checkmk < 2.4.0p1, < 2.3.0p32, < 2.2.0p42 and <= 2.1.0p49 (EOL). This allows a local attacker to read sensitive data. | 0,1% | — |
| CVE-2025-32897 | CRIT 9.8 | apache seata Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This security vulnerability is the same as CVE-2024-47552, but the version range described in the CVE-2024-47552 definition is too narrow. This issue affects Apache Seata (incubatin | 1,7% | — |
| CVE-2025-32896 | MED 6.5 | apache seatunnel # Summary Unauthorized users can perform Arbitrary File Read and Deserialization attack by submit job using restful api-v1. # Details Unauthorized users can access `/hazelcast/rest/maps/submit-job` to submit job. An attacker can set extra params in mysql url | 1,1% | — |
| CVE-2025-32766 | MED 6.4 | fortinet fortiweb A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiWeb CLI version 7.6.0 through 7.6.3 and before 7.4.8 allows a privileged attacker to execute arbitrary code or commands via crafted CLI commands | 0,1% | — |
| CVE-2025-32726 | MED 6.8 | microsoft visual_studio_code Improper access control in Visual Studio Code allows an authorized attacker to elevate privileges locally. | 0,5% | — |