EN
57.924 CVE seguite
784 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

57.924 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordinato dal più alto
CVE-2025-27163 MED 5.5 adobe acrobat Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR 0,4%
CVE-2025-27162 HIGH 7.8 adobe acrobat Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires 0,3%
CVE-2025-27161 HIGH 7.8 adobe acrobat Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage 0,3%
CVE-2025-27160 HIGH 7.8 adobe acrobat Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction i 0,4%
CVE-2025-27159 HIGH 7.8 adobe acrobat Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction i 0,4%
CVE-2025-27158 HIGH 7.8 adobe acrobat Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires 0,4%
CVE-2025-27091 HIGH 7.5 cisco openh264 OpenH264 is a free license codec library which supports H.264 encoding and decoding. A vulnerability in the decoding functions of OpenH264 codec library could allow a remote, unauthenticated attacker to trigger a heap overflow. This vulnerability is due to a r 0,7%
CVE-2025-27018 MED 6.3 apache apache-airflow-providers-mysql Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow MySQL Provider. When user triggered a DAG with dump_sql or load_sql functions they could pass a table parameter from a UI, that could cause SQ 0,9%
CVE-2025-27017 MED 6.5 apache nifi Apache NiFi 1.13.0 through 2.2.0 includes the username and password used to authenticate with MongoDB in the NiFi provenance events that MongoDB components generate during processing. An authorized user with read access to the provenance events of those proces 1,2%
CVE-2025-26866 HIGH 8.8 apache hugegraph A remote code execution vulnerability exists where a malicious Raft node can exploit insecure Hessian deserialization within the PD store. The fix enforces IP-based authentication to restrict cluster membership and implements a strict class whitelist to harden 0,9%
CVE-2025-26865 LOW 3.5 apache ofbiz Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz. This issue affects Apache OFBiz: from 18.12.17 before 18.12.18.   It's a regression between 18.12.17 and 18.12.18. In case you use something like that, which 0,7%
CVE-2025-26864 HIGH 7.5 apache iotdb Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in the OpenIdAuthorizer of Apache IoTDB. This issue affects Apache IoTDB: from 0.10.0 through 1.3.3, from 2.0.1-beta before 2.0.2. User 0,7%
CVE-2025-26796 MED 5.4 apache oozie ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Oozie. This issue affects Apache Oozie: all versions. As this project is retired, we do not plan to release a version 0,5%
CVE-2025-26795 HIGH 7.5 apache iotdb Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in Apache IoTDB JDBC driver. This issue affects iotdb-jdbc: from 0.10.0 through 1.3.3, from 2.0.1-beta before 2.0.2. Users are recommen 0,7%
CVE-2025-26688 HIGH 7.8 microsoft windows_10_1507 Stack-based buffer overflow in Microsoft Virtual Hard Drive allows an authorized attacker to elevate privileges locally. 0,6%
CVE-2025-26687 HIGH 7.5 microsoft 365_copilot Use after free in Windows Win32K - GRFX allows an unauthorized attacker to elevate privileges over a network. 1,1%
CVE-2025-26686 HIGH 7.5 microsoft windows_10_1507 Sensitive data storage in improperly locked memory in Windows TCP/IP allows an unauthorized attacker to execute code over a network. 1,5%
CVE-2025-26685 MED 6.5 microsoft defender_for_identity Improper authentication in Microsoft Defender for Identity allows an unauthorized attacker to perform spoofing over an adjacent network. 0,7%
CVE-2025-26684 MED 6.7 microsoft defender_for_endpoint External control of file name or path in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally. 0,4%
CVE-2025-26683 HIGH 8.1 microsoft azure_playwright Improper authorization in Azure Playwright allows an unauthorized attacker to elevate privileges over a network. 0,7%
CVE-2025-26682 HIGH 7.5 microsoft asp.net_core Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. 1,7%
CVE-2025-26681 MED 6.7 microsoft windows_10_21h2 Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. 0,6%
CVE-2025-26680 HIGH 7.5 microsoft windows_server_2012 Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network. 2,0%
CVE-2025-26679 HIGH 7.8 microsoft windows_10_1507 Use after free in RPC Endpoint Mapper Service allows an authorized attacker to elevate privileges locally. 0,6%
CVE-2025-26678 HIGH 8.4 microsoft windows_10_1809 Improper access control in Windows Defender Application Control (WDAC) allows an unauthorized attacker to bypass a security feature locally. 0,5%