58.254 CVE seguite
789 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.254 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2025-49526 | HIGH 7.8 | adobe illustrator Illustrator versions 28.7.6, 29.5.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must op | 0,2% | — |
| CVE-2025-49385 | HIGH 7.8 | trendmicro maximum_security_2022 Trend Micro Security 17.8 (Consumer) is vulnerable to a link following local privilege escalation vulnerability that could allow a local attacker to unintentionally delete privileged Trend Micro files including its own. | 0,2% | — |
| CVE-2025-49384 | HIGH 7.8 | trendmicro maximum_security_2022 Trend Micro Security 17.8 (Consumer) is vulnerable to a link following local privilege escalation vulnerability that could allow a local attacker to unintentionally delete privileged Trend Micro files including its own. | 0,2% | — |
| CVE-2025-48820 | HIGH 7.8 | microsoft windows_10_1507 Improper link resolution before file access ('link following') in Windows AppX Deployment Service allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-48816 | HIGH 7.8 | microsoft windows_10_1507 Integer overflow or wraparound in HID class driver allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-48815 | HIGH 7.8 | microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows SSDP Service allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-48806 | HIGH 7.8 | microsoft windows_10_1507 Use after free in Microsoft MPEG-2 Video Extension allows an authorized attacker to execute code locally. | 0,4% | — |
| CVE-2025-48805 | HIGH 7.8 | microsoft windows_10_1507 Heap-based buffer overflow in Microsoft MPEG-2 Video Extension allows an authorized attacker to execute code locally. | 0,4% | — |
| CVE-2025-48799 | HIGH 7.8 | microsoft windows_10_1607 Improper link resolution before file access ('link following') in Windows Update Service allows an authorized attacker to elevate privileges locally. | 1,1% | — |
| CVE-2025-4879 | HIGH 7.8 | citrix workspace Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows | 0,1% | — |
| CVE-2025-48000 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2025-47996 | HIGH 7.8 | microsoft windows_10_1507 Integer underflow (wrap or wraparound) in Windows MBT Transport driver allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-47994 | HIGH 7.8 | microsoft 365_apps Deserialization of untrusted data in Microsoft Office allows an unauthorized attacker to elevate privileges locally. | 2,8% | — |
| CVE-2025-47993 | HIGH 7.8 | microsoft windows_11_24h2 Improper access control in Microsoft PC Manager allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2025-47991 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2025-47987 | HIGH 7.8 | microsoft windows_10_1507 Heap-based buffer overflow in Windows Cred SSProvider Protocol allows an authorized attacker to elevate privileges locally. | 1,7% | — |
| CVE-2025-47985 | HIGH 7.8 | microsoft windows_10_1507 Untrusted pointer dereference in Windows Event Tracing allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-47982 | HIGH 7.8 | microsoft windows_10_1607 Improper input validation in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-47976 | HIGH 7.8 | microsoft windows_10_1507 Use after free in Windows SSDP Service allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-47973 | HIGH 7.8 | microsoft windows_10_1507 Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally. | 0,5% | — |
| CVE-2025-47971 | HIGH 7.8 | microsoft windows_10_1507 Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally. | 0,5% | — |
| CVE-2025-47968 | HIGH 7.8 | microsoft autoupdate Improper input validation in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-47962 | HIGH 7.8 | microsoft windows_software_development_kit Improper access control in Windows SDK allows an authorized attacker to elevate privileges locally. | 1,6% | — |
| CVE-2025-47955 | HIGH 7.8 | microsoft windows_10_1507 Improper privilege management in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. | 0,9% | — |
| CVE-2025-47761 | HIGH 7.8 | fortinet forticlient An Exposed IOCTL with Insufficient Access Control vulnerability [CWE-782] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.9 may allow an authenticated local user to execute unauthorized code via fortips dr | 0,2% | — |