EN
57.924 CVE seguite
784 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

57.924 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordinato dal più alto
CVE-2025-25247 MED 6.1 apache felix_webconsole Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix Webconsole. This issue affects Apache Felix Webconsole 4.x up to 4.9.8 and 5.x up to 5.0.8. Users are recommended to upgrade to version 4.9.10 0,7%
CVE-2025-25193 MED 5.5 netty netty Netty, an asynchronous, event-driven network application framework, has a vulnerability in versions up to and including 4.1.118.Final. An unsafe reading of environment file could potentially cause a denial of service in Netty. When loaded on an Windows applica 0,4%
CVE-2025-25069 MED 6.5 apache kvrocks A Cross-Protocol Scripting vulnerability is found in Apache Kvrocks. Since Kvrocks didn't detect if "Host:" or "POST" appears in RESP requests, a valid HTTP request can also be sent to Kvrocks as a valid RESP request and trigger some database operations, whi 0,8%
CVE-2025-25045 MED 4.3 ibm infosphere_information_server IBM InfoSphere Information 11.7 Server authenticated user to obtain sensitive information when a detailed technical error message is returned in a request. This information could be used in further attacks against the system. 0,3%
CVE-2025-25008 HIGH 7.1 microsoft windows_server_2016 Improper link resolution before file access ('link following') in Microsoft Windows allows an authorized attacker to elevate privileges locally. 0,6%
CVE-2025-25007 MED 5.3 microsoft exchange_server Improper validation of syntactic correctness of input in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. 0,8%
CVE-2025-25006 MED 5.3 microsoft exchange_server Improper handling of additional special element in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. 0,9%
CVE-2025-25005 MED 6.5 microsoft exchange_server Improper input validation in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network. 1,4%
CVE-2025-25004 HIGH 7.3 microsoft powershell Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges locally. 0,4%
CVE-2025-25003 HIGH 7.3 microsoft visual_studio_2019 Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally. 0,4%
CVE-2025-25002 MED 6.8 microsoft azure_local_cluster Insertion of sensitive information into log file in Azure Local Cluster allows an authorized attacker to disclose information over an adjacent network. 1,1%
CVE-2025-25001 MED 4.3 microsoft edge Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. 0,8%
CVE-2025-25000 HIGH 8.8 microsoft edge_chromium Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. 1,0%
CVE-2025-24999 HIGH 8.8 microsoft sql_server_2016 Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network. 1,7%
CVE-2025-24998 HIGH 7.3 microsoft visual_studio_2017 Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally. 0,4%
CVE-2025-24997 MED 4.4 microsoft windows_10_21h2 Null pointer dereference in Windows Kernel Memory allows an authorized attacker to deny service locally. 0,6%
CVE-2025-24996 MED 6.5 microsoft windows_10_1507 External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. 1,3%
CVE-2025-24995 HIGH 7.8 microsoft windows_10_1507 Heap-based buffer overflow in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally. 0,6%
CVE-2025-24994 HIGH 7.3 microsoft windows_11_22h2 Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally. 1,2%
CVE-2025-24992 MED 5.5 microsoft windows_10_1507 Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally. 1,0%
CVE-2025-24988 MED 6.6 microsoft windows_10_1507 Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack. 0,7%
CVE-2025-24987 MED 6.6 microsoft windows_10_1507 Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack. 0,7%
CVE-2025-24986 MED 6.5 microsoft azure_promptflow_core Improper isolation or compartmentalization in Azure PromptFlow allows an unauthorized attacker to execute code over a network. 0,5%
CVE-2025-24917 HIGH 7.8 tenable nessus_network_monitor In Tenable Network Monitor versions prior to 6.5.1 on a Windows host, it was found that a non-administrative user could stage files in a local directory to run arbitrary code with SYSTEM privileges, potentially leading to local privilege escalation. 0,2%
CVE-2025-24916 HIGH 7.0 tenable nessus_network_monitor When installing Tenable Network Monitor to a non-default location on a Windows host, Tenable Network Monitor versions prior to 6.5.1 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secure 0,1%