58.254 CVE seguite
789 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.254 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2025-59230 | HIGH 7.8 | microsoft windows_10_1507 Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. | 2,7% | |
| CVE-2025-59227 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 0,5% | — |
| CVE-2025-59226 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2025-59225 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2025-59224 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2025-59223 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2025-59222 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0,5% | — |
| CVE-2025-59207 | HIGH 7.8 | microsoft windows_10_1809 Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-59201 | HIGH 7.8 | microsoft windows_10_1507 Improper access control in Network Connection Status Indicator (NCSI) allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-59199 | HIGH 7.8 | microsoft windows_10_1809 Improper access control in Software Protection Platform (SPP) allows an authorized attacker to elevate privileges locally. | 4,2% | — |
| CVE-2025-59192 | HIGH 7.8 | microsoft windows_10_1507 Buffer over-read in Storport.sys Driver allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2025-59191 | HIGH 7.8 | microsoft windows_10_1809 Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2025-59187 | HIGH 7.8 | microsoft windows_10_1507 Improper input validation in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2025-58728 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-58724 | HIGH 7.8 | microsoft azure_connected_machine_agent Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally. | 0,6% | — |
| CVE-2025-58722 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows DWM allows an authorized attacker to elevate privileges locally. | 2,3% | — |
| CVE-2025-58720 | HIGH 7.8 | microsoft windows_10_1809 Use of a cryptographic primitive with a risky implementation in Windows Cryptographic Services allows an authorized attacker to disclose information locally. | 0,2% | — |
| CVE-2025-58714 | HIGH 7.8 | microsoft windows_10_1507 Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2025-58097 | HIGH 7.8 | secuavail logstare_collector The installation directory of LogStare Collector is configured with incorrect access permissions. A non-administrative user may manipulate files within the installation directory and execute arbitrary code with the administrative privilege. | 0,1% | — |
| CVE-2025-57836 | HIGH 7.8 | samsung magician An issue was discovered in Samsung Magician 6.3.0 through 8.3.2 on Windows. The installer creates a temporary folder with weak permissions during installation, allowing a non-admin user to perform DLL hijacking and escalate privileges. | 0,1% | — |
| CVE-2025-57741 | HIGH 7.8 | fortinet forticlient An Incorrect Permission Assignment for Critical Resource vulnerability [CWE-732] in FortiClientMac 7.4.0 through 7.4.3, 7.2.0 through 7.2.11, 7.0 all versions may allow a local attacker to run arbitrary code or commands via LaunchDaemon hijacking. | 0,1% | — |
| CVE-2025-55701 | HIGH 7.8 | microsoft windows_10_1507 Improper validation of specified type of input in Microsoft Windows allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-55697 | HIGH 7.8 | microsoft windows_server_2022_23h2 Heap-based buffer overflow in Azure Local allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-55696 | HIGH 7.8 | microsoft windows_10_1809 Time-of-check time-of-use (toctou) race condition in NtQueryInformation Token function (ntifs.h) allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2025-55694 | HIGH 7.8 | microsoft windows_11_24h2 Improper access control in Windows Error Reporting allows an authorized attacker to elevate privileges locally. | 3,0% | — |