EN
57.399 CVE seguite
782 Sfruttate ora
186 Usate dai ransomware
Ultima sincronia

CVE Tracker

57.399 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordinato dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2025-33064 HIGH 8.8 microsoft windows_10_1507 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. 1,2%
CVE-2025-33053 HIGH 8.8 microsoft windows_10_1507 External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network. 85,4%
CVE-2025-30473 HIGH 8.8 apache airflow_common_sql_provider Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow Common SQL Provider. When using the partition clause in SQLTableCheckOperator as parameter (which was a recommended pattern), Authenticated UI 0,9%
CVE-2025-29967 HIGH 8.8 microsoft windows_10_1507 Heap-based buffer overflow in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network. 1,3%
CVE-2025-29966 HIGH 8.8 microsoft remote_desktop Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code over a network. 1,4%
CVE-2025-29964 HIGH 8.8 microsoft windows_10_1809 Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network. 1,0%
CVE-2025-29963 HIGH 8.8 microsoft windows_10_1809 Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network. 1,0%
CVE-2025-29962 HIGH 8.8 microsoft windows_10_1507 Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network. 14,3%
CVE-2025-29840 HIGH 8.8 microsoft windows_10_1507 Stack-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network. 1,0%
CVE-2025-29794 HIGH 8.8 microsoft sharepoint_enterprise_server Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 5,1%
CVE-2025-27818 HIGH 8.8 apache kafka A possible security vulnerability has been identified in Apache Kafka. This requires access to a alterConfig to the cluster resource, or Kafka Connect worker, and the ability to create/modify connectors on it with an arbitrary Kafka client SASL JAAS config and 1,0%
CVE-2025-27740 HIGH 8.8 microsoft windows_server_2008 Weak authentication in Windows Active Directory Certificate Services allows an authorized attacker to elevate privileges over a network. 3,4%
CVE-2025-27696 HIGH 8.8 apache superset Incorrect Authorization vulnerability in Apache Superset allows ownership takeover of dashboards, charts or datasets by authenticated users with read permissions. This issue affects Apache Superset: through 4.1.1. Users are recommended to upgrade to version 1,2%
CVE-2025-27481 HIGH 8.8 microsoft windows_10_1507 Stack-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network. 1,2%
CVE-2025-27477 HIGH 8.8 microsoft windows_10_1507 Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network. 1,5%
CVE-2025-26866 HIGH 8.8 apache hugegraph A remote code execution vulnerability exists where a malicious Raft node can exploit insecure Hessian deserialization within the PD store. The fix enforces IP-based authentication to restrict cluster membership and implements a strict class whitelist to harden 0,9%
CVE-2025-26669 HIGH 8.8 microsoft windows_10_1507 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. 1,5%
CVE-2025-26647 HIGH 8.8 microsoft windows_server_2008 Improper input validation in Windows Kerberos allows an authorized attacker to elevate privileges over a network. 2,2%
CVE-2025-26645 HIGH 8.8 microsoft remote_desktop_client Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network. 3,4%
CVE-2025-26467 HIGH 8.8 apache cassandra Privilege Defined With Unsafe Actions vulnerability in Apache Cassandra. An user with MODIFY permission ON ALL KEYSPACES can escalate privileges to superuser within a targeted Cassandra cluster via unsafe actions to a system resource. Operators granting data M 0,5%
CVE-2025-25000 HIGH 8.8 microsoft edge_chromium Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. 1,0%
CVE-2025-24999 HIGH 8.8 microsoft sql_server_2016 Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network. 1,7%
CVE-2025-24859 HIGH 8.8 apache roller A session management vulnerability exists in Apache Roller before version 6.1.5 where active user sessions are not properly invalidated after password changes. When a user's password is changed, either by the user themselves or by an administrator, existing se 1,1%
CVE-2025-24404 HIGH 8.8 apache hertzbeat XML Injection RCE by parse http sitemap xml response vulnerability in Apache HertzBeat. The attacker needs to have an authenticated account with access, and add monitor parsed by xml, returned special content can trigger the XML parsing vulnerabili 0,5%
CVE-2025-24056 HIGH 8.8 microsoft windows_10_1507 Heap-based buffer overflow in Windows Telephony Server allows an unauthorized attacker to execute code over a network. 1,7%