57.925 CVE seguite
784 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.925 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più alto |
|---|---|---|---|---|
| CVE-2025-24062 | HIGH 7.8 | microsoft windows_10_21h2 Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | 0,6% | — |
| CVE-2025-24061 | HIGH 7.8 | microsoft windows_10_1507 Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature locally. | 1,2% | — |
| CVE-2025-24060 | HIGH 7.8 | microsoft windows_10_1809 Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | 0,6% | — |
| CVE-2025-24059 | HIGH 7.8 | microsoft windows_10_1507 Incorrect conversion between numeric types in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | 0,5% | — |
| CVE-2025-24058 | HIGH 7.8 | microsoft windows_10_1809 Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | 0,6% | — |
| CVE-2025-24057 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | 1,0% | — |
| CVE-2025-24056 | HIGH 8.8 | microsoft windows_10_1507 Heap-based buffer overflow in Windows Telephony Server allows an unauthorized attacker to execute code over a network. | 1,5% | — |
| CVE-2025-24055 | MED 4.3 | microsoft windows_10_1507 Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to disclose information with a physical attack. | 0,9% | — |
| CVE-2025-24053 | HIGH 7.2 | microsoft dataverse Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network. | 0,7% | — |
| CVE-2025-24052 | HIGH 7.8 | microsoft windows_10_1507 Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an announcement of the upcoming removal of ltmdm64.sys driver. The driver has been removed in the October cumula | 2,4% | — |
| CVE-2025-24051 | HIGH 8.8 | microsoft windows_10_1507 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | 1,5% | — |
| CVE-2025-24050 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally. | 0,5% | — |
| CVE-2025-24049 | HIGH 8.4 | microsoft azure_command-line_interface Improper neutralization of special elements used in a command ('command injection') in Azure Command Line Integration (CLI) allows an unauthorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-24048 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally. | 0,5% | — |
| CVE-2025-24046 | HIGH 7.8 | microsoft windows_10_1507 Use after free in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally. | 0,5% | — |
| CVE-2025-24045 | HIGH 8.1 | microsoft windows_server_2012 Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. | 1,3% | — |
| CVE-2025-24044 | HIGH 7.8 | microsoft windows_10_1507 Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally. | 0,6% | — |
| CVE-2025-24043 | HIGH 7.5 | microsoft windbg Improper verification of cryptographic signature in .NET allows an authorized attacker to execute code over a network. | 0,9% | — |
| CVE-2025-24042 | HIGH 7.3 | microsoft visual_studio_code Visual Studio Code JS Debug Extension Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2025-24039 | HIGH 7.3 | microsoft visual_studio_code Visual Studio Code Elevation of Privilege Vulnerability | 0,8% | — |
| CVE-2025-24036 | HIGH 7.0 | microsoft autoupdate Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability | 0,4% | — |
| CVE-2025-24035 | HIGH 8.1 | microsoft windows_10_1507 Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. | 1,7% | — |
| CVE-2025-23419 | MED 4.3 | debian debian_linux When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication requirements on these servers. This vulnerability arises when TLS Session Tickets https://ngin | 2,8% | — |
| CVE-2025-23415 | LOW 3.1 | f5 big-ip_access_policy_manager An insufficient verification of data authenticity vulnerability exists in BIG-IP APM Access Policy endpoint inspection that may allow an attacker to bypass endpoint inspection checks for VPN connection initiated thru BIG-IP APM browser network access VPN clien | 0,1% | — |
| CVE-2025-23413 | MED 4.4 | f5 big-ip_next_central_manager When users log in through the webUI or API using local authentication, BIG-IP Next Central Manager may log sensitive information in the pgaudit log files. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0,2% | — |