EN
57.361 CVE seguite
782 Sfruttate ora
186 Usate dai ransomware
Ultima sincronia

CVE Tracker

57.361 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordinato dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2025-53772 HIGH 8.8 microsoft web_deploy_4.0 Deserialization of untrusted data in Web Deploy allows an authorized attacker to execute code over a network. 23,9%
CVE-2025-53727 HIGH 8.8 microsoft sql_server_2016 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. 1,1%
CVE-2025-53689 HIGH 8.8 apache jackrabbit Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an unsecured document build to load privileges. Users are recommended to upgrade to versions 2.20.17 (Java 8), 2.22.1 (Java 11) or 2.23.2 (Ja 0,5%
CVE-2025-5349 HIGH 8.8 citrix netscaler_application_delivery_controller Improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway 4,4%
CVE-2025-53192 HIGH 8.8 apache commons_ognl ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Expression/Command Delimiters vulnerability in Apache Commons OGNL. This issue affects Apache Commons OGNL: all versions. When using the API Ognl.getValue​, the OGNL engine parses and evaluates the 0,6%
CVE-2025-53145 HIGH 8.8 microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network. 6,4%
CVE-2025-53144 HIGH 8.8 microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network. 6,4%
CVE-2025-53143 HIGH 8.8 microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network. 6,8%
CVE-2025-53131 HIGH 8.8 microsoft windows_10_1809 Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network. 0,9%
CVE-2025-52841 HIGH 8.8 laundry_project laundry Cross-Site Request Forgery (CSRF) vulnerability in Laundry on Linux, MacOS allows to perform an Account Takeover. This issue affects Laundry: 2.3.0. 0,2%
CVE-2025-52436 HIGH 8.8 fortinet fortisandbox An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all ver 6,3%
CVE-2025-50163 HIGH 8.8 microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. 0,9%
CVE-2025-50151 HIGH 8.8 apache jena File access paths in configuration files uploaded by users with administrator access are not validated. This issue affects Apache Jena version up to 5.4.0. Users are recommended to upgrade to version 5.5.0, which does not allow arbitrary configuration upload 1,0%
CVE-2025-49759 HIGH 8.8 microsoft sql_server_2016 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. 1,1%
CVE-2025-49758 HIGH 8.8 microsoft sql_server_2016 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. 0,9%
CVE-2025-49757 HIGH 8.8 microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. 1,0%
CVE-2025-49753 HIGH 8.8 microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. 0,8%
CVE-2025-49740 HIGH 8.8 microsoft windows_10_1507 Protection mechanism failure in Windows SmartScreen allows an unauthorized attacker to bypass a security feature over a network. 0,8%
CVE-2025-49739 HIGH 8.8 microsoft visual_studio Improper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to elevate privileges over a network. 0,8%
CVE-2025-49729 HIGH 8.8 microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. 0,6%
CVE-2025-49724 HIGH 8.8 microsoft windows_10_1809 Use after free in Windows Connected Devices Platform Service allows an unauthorized attacker to execute code over a network. 7,8%
CVE-2025-49723 HIGH 8.8 microsoft windows_10_1809 Missing authorization in Windows StateRepository API allows an authorized attacker to perform tampering locally. 0,3%
CVE-2025-49713 HIGH 8.8 microsoft edge_chromium Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. 0,7%
CVE-2025-49712 HIGH 8.8 microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 20,0%
CVE-2025-49704 HIGH 8.8 ransomware microsoft sharepoint_server Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 100,0%