57.924 CVE seguite
784 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.924 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più alto |
|---|---|---|---|---|
| CVE-2025-29837 | MED 5.5 | microsoft windows_10_1507 Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to disclose information locally. | 0,6% | — |
| CVE-2025-29836 | MED 6.5 | microsoft windows_10_1507 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 1,3% | — |
| CVE-2025-29835 | MED 6.5 | microsoft windows_10_1507 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 1,3% | — |
| CVE-2025-29834 | HIGH 7.5 | microsoft edge_chromium Out-of-bounds read in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0,6% | — |
| CVE-2025-29833 | HIGH 7.7 | microsoft windows_10_1507 Time-of-check time-of-use (toctou) race condition in Windows Virtual Machine Bus allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2025-29832 | MED 6.5 | microsoft windows_10_1507 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 1,3% | — |
| CVE-2025-29831 | HIGH 7.5 | microsoft windows_server_2008 Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network. | 1,0% | — |
| CVE-2025-29830 | MED 6.5 | microsoft windows_10_1507 Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 1,3% | — |
| CVE-2025-29829 | MED 5.5 | microsoft windows_10_1507 Use of uninitialized resource in Windows Trusted Runtime Interface Driver allows an authorized attacker to disclose information locally. | 0,5% | — |
| CVE-2025-29828 | HIGH 8.1 | microsoft windows_11_22h2 Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to execute code over a network. | 1,3% | — |
| CVE-2025-29827 | CRIT 9.9 | microsoft azure_automation Improper authorization in Azure Automation allows an authorized attacker to elevate privileges over a network. | 1,6% | — |
| CVE-2025-29826 | HIGH 7.3 | microsoft dataverse Improper handling of insufficient permissions or privileges in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network. | 0,8% | — |
| CVE-2025-29825 | MED 6.5 | microsoft edge_chromium User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | 0,8% | — |
| CVE-2025-29823 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0,7% | — |
| CVE-2025-29822 | HIGH 7.8 | microsoft office Incomplete list of disallowed inputs in Microsoft Office OneNote allows an unauthorized attacker to bypass a security feature locally. | 0,8% | — |
| CVE-2025-29821 | MED 5.5 | microsoft dynamics_365_business_central_2023 Improper input validation in Dynamics Business Central allows an authorized attacker to disclose information locally. | 0,7% | — |
| CVE-2025-29820 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0,8% | — |
| CVE-2025-29819 | MED 6.2 | microsoft windows_admin_center External control of file name or path in Azure Portal Windows Admin Center allows an unauthorized attacker to disclose information locally. | 1,1% | — |
| CVE-2025-29817 | MED 5.7 | microsoft power_automate_for_desktop Uncontrolled search path element in Power Automate allows an authorized attacker to disclose information over a network. | 0,9% | — |
| CVE-2025-29816 | HIGH 7.5 | microsoft 365_apps Improper input validation in Microsoft Office Word allows an unauthorized attacker to bypass a security feature over a network. | 0,5% | — |
| CVE-2025-29815 | HIGH 7.6 | microsoft edge_chromium Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network. | 0,8% | — |
| CVE-2025-29814 | CRIT 9.3 | microsoft partner_center Improper authorization in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network. | 2,2% | — |
| CVE-2025-29813 | CRIT 10.0 | microsoft azure_devops Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network. | 1,7% | — |
| CVE-2025-29812 | HIGH 7.8 | microsoft windows_11_22h2 Untrusted pointer dereference in Windows Kernel Memory allows an authorized attacker to elevate privileges locally. | 0,9% | — |
| CVE-2025-29811 | HIGH 7.8 | microsoft windows_11_22h2 Improper input validation in Windows Mobile Broadband allows an authorized attacker to elevate privileges locally. | 0,6% | — |