57.361 CVE seguite
782 Sfruttate ora
186 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.361 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2025-59499 | HIGH 8.8 | microsoft sql_server_2016 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | 1,1% | — |
| CVE-2025-59295 | HIGH 8.8 | microsoft windows_10_1507 Heap-based buffer overflow in Internet Explorer allows an unauthorized attacker to execute code over a network. | 1,8% | — |
| CVE-2025-59249 | HIGH 8.8 | microsoft exchange_server Weak authentication in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | 0,8% | — |
| CVE-2025-59247 | HIGH 8.8 | microsoft azure_playfab Azure PlayFab Elevation of Privilege Vulnerability | 1,4% | — |
| CVE-2025-59237 | HIGH 8.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 2,3% | — |
| CVE-2025-59228 | HIGH 8.8 | microsoft sharepoint_server Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 1,3% | — |
| CVE-2025-59213 | HIGH 8.8 | microsoft configuration_manager_2403 Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an unauthorized attacker to elevate privileges over an adjacent network. | 0,3% | — |
| CVE-2025-58718 | HIGH 8.8 | microsoft remote_desktop_client Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 0,6% | — |
| CVE-2025-58716 | HIGH 8.8 | microsoft windows_10_1507 Improper input validation in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-58715 | HIGH 8.8 | microsoft windows_10_1507 Integer overflow or wraparound in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-58692 | HIGH 8.8 | fortinet fortivoice An improper neutralization of special elements used in an SQL Command ("SQL Injection") vulnerability [CWE-89] vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7 allows an authenticated attacker to execute unauthorized cod | 0,3% | — |
| CVE-2025-57780 | HIGH 8.8 | f5 f5os-a A vulnerability exists in F5OS-A and F5OS-C system that may allow an authenticated attacker with local access to escalate their privileges. A successful exploit may allow the attacker to cross a security boundary. Note: Software versions which have reached E | 0,2% | — |
| CVE-2025-55319 | HIGH 8.8 | microsoft visual_studio_code Ai command injection in Agentic AI and Visual Studio Code allows an unauthorized attacker to execute code over a network. | 0,9% | — |
| CVE-2025-55234 | HIGH 8.8 | microsoft windows_10_1507 SMB Server might be susceptible to relay attacks depending on the configuration. An attacker who successfully exploited these vulnerabilities could perform relay attacks and make the users subject to elevation of privilege attacks. The SMB Server already suppo | 20,1% | — |
| CVE-2025-55227 | HIGH 8.8 | microsoft sql_server_2016 Improper neutralization of special elements used in a command ('command injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | 1,3% | — |
| CVE-2025-54920 | HIGH 8.8 | apache spark This issue affects Apache Spark: before 3.5.7 and 4.0.1. Users are recommended to upgrade to version 3.5.7 or 4.0.1 and above, which fixes the issue. Summary Apache Spark 3.5.4 and earlier versions contain a code execution vulnerability in the Spark Hist | 5,3% | — |
| CVE-2025-54918 | HIGH 8.8 | microsoft windows_10_1507 Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network. | 19,4% | — |
| CVE-2025-54897 | HIGH 8.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 19,1% | — |
| CVE-2025-54286 | HIGH 8.8 | canonical lxd Cross-Site Request Forgery (CSRF) in LXD-UI in Canonical LXD versions >= 5.0 on Linux allows an attacker to create and start container instances without user consent via crafted HTML form submissions exploiting client certificate authentication. | 0,1% | — |
| CVE-2025-5419 | HIGH 8.8 | google chrome Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 7,8% | |
| CVE-2025-54113 | HIGH 8.8 | microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | 0,9% | — |
| CVE-2025-54110 | HIGH 8.8 | microsoft windows_10_1507 Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally. | 4,1% | — |
| CVE-2025-54106 | HIGH 8.8 | microsoft windows_server_2012 Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | 1,4% | — |
| CVE-2025-53844 | HIGH 8.8 | fortinet fortios A out-of-bounds write vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11 allows attacker to execute unauthorized code or commands via specially crafted packets. | 0,6% | — |
| CVE-2025-53778 | HIGH 8.8 | microsoft windows_10_1507 Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network. | 38,9% | — |