57.924 CVE seguite
784 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.924 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più alto |
|---|---|---|---|---|
| CVE-2025-25247 | MED 6.1 | apache felix_webconsole Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix Webconsole. This issue affects Apache Felix Webconsole 4.x up to 4.9.8 and 5.x up to 5.0.8. Users are recommended to upgrade to version 4.9.10 | 0,7% | — |
| CVE-2025-25193 | MED 5.5 | netty netty Netty, an asynchronous, event-driven network application framework, has a vulnerability in versions up to and including 4.1.118.Final. An unsafe reading of environment file could potentially cause a denial of service in Netty. When loaded on an Windows applica | 0,4% | — |
| CVE-2025-25069 | MED 6.5 | apache kvrocks A Cross-Protocol Scripting vulnerability is found in Apache Kvrocks. Since Kvrocks didn't detect if "Host:" or "POST" appears in RESP requests, a valid HTTP request can also be sent to Kvrocks as a valid RESP request and trigger some database operations, whi | 0,8% | — |
| CVE-2025-25045 | MED 4.3 | ibm infosphere_information_server IBM InfoSphere Information 11.7 Server authenticated user to obtain sensitive information when a detailed technical error message is returned in a request. This information could be used in further attacks against the system. | 0,3% | — |
| CVE-2025-25008 | HIGH 7.1 | microsoft windows_server_2016 Improper link resolution before file access ('link following') in Microsoft Windows allows an authorized attacker to elevate privileges locally. | 0,6% | — |
| CVE-2025-25007 | MED 5.3 | microsoft exchange_server Improper validation of syntactic correctness of input in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | 0,8% | — |
| CVE-2025-25006 | MED 5.3 | microsoft exchange_server Improper handling of additional special element in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | 0,9% | — |
| CVE-2025-25005 | MED 6.5 | microsoft exchange_server Improper input validation in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network. | 1,4% | — |
| CVE-2025-25004 | HIGH 7.3 | microsoft powershell Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-25003 | HIGH 7.3 | microsoft visual_studio_2019 Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-25002 | MED 6.8 | microsoft azure_local_cluster Insertion of sensitive information into log file in Azure Local Cluster allows an authorized attacker to disclose information over an adjacent network. | 1,1% | — |
| CVE-2025-25001 | MED 4.3 | microsoft edge Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | 0,8% | — |
| CVE-2025-25000 | HIGH 8.8 | microsoft edge_chromium Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 1,0% | — |
| CVE-2025-24999 | HIGH 8.8 | microsoft sql_server_2016 Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network. | 1,7% | — |
| CVE-2025-24998 | HIGH 7.3 | microsoft visual_studio_2017 Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-24997 | MED 4.4 | microsoft windows_10_21h2 Null pointer dereference in Windows Kernel Memory allows an authorized attacker to deny service locally. | 0,6% | — |
| CVE-2025-24996 | MED 6.5 | microsoft windows_10_1507 External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. | 1,3% | — |
| CVE-2025-24995 | HIGH 7.8 | microsoft windows_10_1507 Heap-based buffer overflow in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally. | 0,6% | — |
| CVE-2025-24994 | HIGH 7.3 | microsoft windows_11_22h2 Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally. | 1,2% | — |
| CVE-2025-24992 | MED 5.5 | microsoft windows_10_1507 Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally. | 1,0% | — |
| CVE-2025-24988 | MED 6.6 | microsoft windows_10_1507 Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack. | 0,7% | — |
| CVE-2025-24987 | MED 6.6 | microsoft windows_10_1507 Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack. | 0,7% | — |
| CVE-2025-24986 | MED 6.5 | microsoft azure_promptflow_core Improper isolation or compartmentalization in Azure PromptFlow allows an unauthorized attacker to execute code over a network. | 0,5% | — |
| CVE-2025-24917 | HIGH 7.8 | tenable nessus_network_monitor In Tenable Network Monitor versions prior to 6.5.1 on a Windows host, it was found that a non-administrative user could stage files in a local directory to run arbitrary code with SYSTEM privileges, potentially leading to local privilege escalation. | 0,2% | — |
| CVE-2025-24916 | HIGH 7.0 | tenable nessus_network_monitor When installing Tenable Network Monitor to a non-default location on a Windows host, Tenable Network Monitor versions prior to 6.5.1 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secure | 0,1% | — |