EN
57.361 CVE seguite
782 Sfruttate ora
186 Usate dai ransomware
Ultima sincronia

CVE Tracker

57.361 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordinato dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2025-59499 HIGH 8.8 microsoft sql_server_2016 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. 1,1%
CVE-2025-59295 HIGH 8.8 microsoft windows_10_1507 Heap-based buffer overflow in Internet Explorer allows an unauthorized attacker to execute code over a network. 1,8%
CVE-2025-59249 HIGH 8.8 microsoft exchange_server Weak authentication in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. 0,8%
CVE-2025-59247 HIGH 8.8 microsoft azure_playfab Azure PlayFab Elevation of Privilege Vulnerability 1,4%
CVE-2025-59237 HIGH 8.8 microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 2,3%
CVE-2025-59228 HIGH 8.8 microsoft sharepoint_server Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 1,3%
CVE-2025-59213 HIGH 8.8 microsoft configuration_manager_2403 Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an unauthorized attacker to elevate privileges over an adjacent network. 0,3%
CVE-2025-58718 HIGH 8.8 microsoft remote_desktop_client Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. 0,6%
CVE-2025-58716 HIGH 8.8 microsoft windows_10_1507 Improper input validation in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally. 0,4%
CVE-2025-58715 HIGH 8.8 microsoft windows_10_1507 Integer overflow or wraparound in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally. 0,4%
CVE-2025-58692 HIGH 8.8 fortinet fortivoice An improper neutralization of special elements used in an SQL Command ("SQL Injection") vulnerability [CWE-89] vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7 allows an authenticated attacker to execute unauthorized cod 0,3%
CVE-2025-57780 HIGH 8.8 f5 f5os-a A vulnerability exists in F5OS-A and F5OS-C system that may allow an authenticated attacker with local access to escalate their privileges.  A successful exploit may allow the attacker to cross a security boundary.  Note: Software versions which have reached E 0,2%
CVE-2025-55319 HIGH 8.8 microsoft visual_studio_code Ai command injection in Agentic AI and Visual Studio Code allows an unauthorized attacker to execute code over a network. 0,9%
CVE-2025-55234 HIGH 8.8 microsoft windows_10_1507 SMB Server might be susceptible to relay attacks depending on the configuration. An attacker who successfully exploited these vulnerabilities could perform relay attacks and make the users subject to elevation of privilege attacks. The SMB Server already suppo 20,1%
CVE-2025-55227 HIGH 8.8 microsoft sql_server_2016 Improper neutralization of special elements used in a command ('command injection') in SQL Server allows an authorized attacker to elevate privileges over a network. 1,3%
CVE-2025-54920 HIGH 8.8 apache spark This issue affects Apache Spark: before 3.5.7 and 4.0.1. Users are recommended to upgrade to version 3.5.7 or 4.0.1 and above, which fixes the issue. Summary Apache Spark 3.5.4 and earlier versions contain a code execution vulnerability in the Spark Hist 5,3%
CVE-2025-54918 HIGH 8.8 microsoft windows_10_1507 Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network. 19,4%
CVE-2025-54897 HIGH 8.8 microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 19,1%
CVE-2025-54286 HIGH 8.8 canonical lxd Cross-Site Request Forgery (CSRF) in LXD-UI in Canonical LXD versions >= 5.0 on Linux allows an attacker to create and start container instances without user consent via crafted HTML form submissions exploiting client certificate authentication. 0,1%
CVE-2025-5419 HIGH 8.8 google chrome Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) 7,8%
CVE-2025-54113 HIGH 8.8 microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. 0,9%
CVE-2025-54110 HIGH 8.8 microsoft windows_10_1507 Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally. 4,1%
CVE-2025-54106 HIGH 8.8 microsoft windows_server_2012 Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. 1,4%
CVE-2025-53844 HIGH 8.8 fortinet fortios A out-of-bounds write vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11 allows attacker to execute unauthorized code or commands via specially crafted packets. 0,6%
CVE-2025-53778 HIGH 8.8 microsoft windows_10_1507 Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network. 38,9%