57.361 CVE seguite
782 Sfruttate ora
186 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.361 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2025-53772 | HIGH 8.8 | microsoft web_deploy_4.0 Deserialization of untrusted data in Web Deploy allows an authorized attacker to execute code over a network. | 23,9% | — |
| CVE-2025-53727 | HIGH 8.8 | microsoft sql_server_2016 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | 1,1% | — |
| CVE-2025-53689 | HIGH 8.8 | apache jackrabbit Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an unsecured document build to load privileges. Users are recommended to upgrade to versions 2.20.17 (Java 8), 2.22.1 (Java 11) or 2.23.2 (Ja | 0,5% | — |
| CVE-2025-5349 | HIGH 8.8 | citrix netscaler_application_delivery_controller Improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway | 4,4% | — |
| CVE-2025-53192 | HIGH 8.8 | apache commons_ognl ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Expression/Command Delimiters vulnerability in Apache Commons OGNL. This issue affects Apache Commons OGNL: all versions. When using the API Ognl.getValue, the OGNL engine parses and evaluates the | 0,6% | — |
| CVE-2025-53145 | HIGH 8.8 | microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network. | 6,4% | — |
| CVE-2025-53144 | HIGH 8.8 | microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network. | 6,4% | — |
| CVE-2025-53143 | HIGH 8.8 | microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network. | 6,8% | — |
| CVE-2025-53131 | HIGH 8.8 | microsoft windows_10_1809 Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network. | 0,9% | — |
| CVE-2025-52841 | HIGH 8.8 | laundry_project laundry Cross-Site Request Forgery (CSRF) vulnerability in Laundry on Linux, MacOS allows to perform an Account Takeover. This issue affects Laundry: 2.3.0. | 0,2% | — |
| CVE-2025-52436 | HIGH 8.8 | fortinet fortisandbox An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all ver | 6,3% | — |
| CVE-2025-50163 | HIGH 8.8 | microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | 0,9% | — |
| CVE-2025-50151 | HIGH 8.8 | apache jena File access paths in configuration files uploaded by users with administrator access are not validated. This issue affects Apache Jena version up to 5.4.0. Users are recommended to upgrade to version 5.5.0, which does not allow arbitrary configuration upload | 1,0% | — |
| CVE-2025-49759 | HIGH 8.8 | microsoft sql_server_2016 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | 1,1% | — |
| CVE-2025-49758 | HIGH 8.8 | microsoft sql_server_2016 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | 0,9% | — |
| CVE-2025-49757 | HIGH 8.8 | microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | 1,0% | — |
| CVE-2025-49753 | HIGH 8.8 | microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | 0,8% | — |
| CVE-2025-49740 | HIGH 8.8 | microsoft windows_10_1507 Protection mechanism failure in Windows SmartScreen allows an unauthorized attacker to bypass a security feature over a network. | 0,8% | — |
| CVE-2025-49739 | HIGH 8.8 | microsoft visual_studio Improper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to elevate privileges over a network. | 0,8% | — |
| CVE-2025-49729 | HIGH 8.8 | microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | 0,6% | — |
| CVE-2025-49724 | HIGH 8.8 | microsoft windows_10_1809 Use after free in Windows Connected Devices Platform Service allows an unauthorized attacker to execute code over a network. | 7,8% | — |
| CVE-2025-49723 | HIGH 8.8 | microsoft windows_10_1809 Missing authorization in Windows StateRepository API allows an authorized attacker to perform tampering locally. | 0,3% | — |
| CVE-2025-49713 | HIGH 8.8 | microsoft edge_chromium Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0,7% | — |
| CVE-2025-49712 | HIGH 8.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 20,0% | — |
| CVE-2025-49704 | HIGH 8.8 | ransomware microsoft sharepoint_server Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 100,0% |