57.924 CVE seguite
784 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.924 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più alto |
|---|---|---|---|---|
| CVE-2025-27819 | HIGH 7.5 | apache kafka In CVE-2023-25194, we announced the RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration in Kafka Connect API. But not only Kafka Connect API is vulnerable to this attack, the Apache Kafka brokers also have this vulnerability. To exploit th | 1,0% | — |
| CVE-2025-27818 | HIGH 8.8 | apache kafka A possible security vulnerability has been identified in Apache Kafka. This requires access to a alterConfig to the cluster resource, or Kafka Connect worker, and the ability to create/modify connectors on it with an arbitrary Kafka client SASL JAAS config and | 1,0% | — |
| CVE-2025-27817 | HIGH 7.5 | apache kafka A possible arbitrary file read and SSRF vulnerability has been identified in Apache Kafka Client. Apache Kafka Clients accept configuration data for setting the SASL/OAUTHBEARER connection with the brokers, including "sasl.oauthbearer.token.endpoint.url" and " | 68,8% | — |
| CVE-2025-27759 | MED 6.7 | fortinet fortiweb An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiWeb version 7.6.0 through 7.6.3, 7.4.0 through 7.4.7, 7.2.0 through 7.2.10 and before 7.0.10 allows an authenticated privilege | 0,4% | — |
| CVE-2025-27752 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 1,0% | — |
| CVE-2025-27751 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 2,5% | — |
| CVE-2025-27750 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0,9% | — |
| CVE-2025-27749 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 1,1% | — |
| CVE-2025-27748 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 1,1% | — |
| CVE-2025-27747 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0,8% | — |
| CVE-2025-27746 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 0,9% | — |
| CVE-2025-27745 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 1,1% | — |
| CVE-2025-27744 | HIGH 7.8 | microsoft office Improper access control in Microsoft Office allows an authorized attacker to elevate privileges locally. | 1,2% | — |
| CVE-2025-27743 | HIGH 7.8 | microsoft system_center_data_protection_manager Untrusted search path in System Center allows an authorized attacker to elevate privileges locally. | 0,9% | — |
| CVE-2025-27742 | MED 5.5 | microsoft windows_10_1507 Out-of-bounds read in Windows NTFS allows an unauthorized attacker to disclose information locally. | 0,9% | — |
| CVE-2025-27741 | HIGH 7.8 | microsoft windows_10_1507 Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally. | 0,8% | — |
| CVE-2025-27740 | HIGH 8.8 | microsoft windows_server_2008 Weak authentication in Windows Active Directory Certificate Services allows an authorized attacker to elevate privileges over a network. | 3,4% | — |
| CVE-2025-27739 | HIGH 7.8 | microsoft windows_10_1809 Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0,6% | — |
| CVE-2025-27738 | MED 6.5 | microsoft windows_10_1507 Improper access control in Windows Resilient File System (ReFS) allows an authorized attacker to disclose information over a network. | 3,4% | — |
| CVE-2025-27737 | HIGH 8.6 | microsoft windows_10_1507 Improper input validation in Windows Security Zone Mapping allows an unauthorized attacker to bypass a security feature locally. | 0,8% | — |
| CVE-2025-27736 | MED 5.5 | microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Power Dependency Coordinator allows an authorized attacker to disclose information locally. | 0,9% | — |
| CVE-2025-27735 | MED 6.0 | microsoft windows_10_1507 Insufficient verification of data authenticity in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally. | 0,4% | — |
| CVE-2025-27733 | HIGH 7.8 | microsoft windows_10_1507 Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally. | 0,7% | — |
| CVE-2025-27732 | HIGH 7.0 | microsoft windows_10_1507 Sensitive data storage in improperly locked memory in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2025-27731 | HIGH 7.8 | microsoft windows_10_1809 Improper input validation in OpenSSH for Windows allows an authorized attacker to elevate privileges locally. | 0,6% | — |