56.742 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.742 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2025-61622 | CRIT 9.8 | apache fory Deserialization of untrusted data in python in pyfory versions 0.12.0 through 0.12.2, or the legacy pyfury versions from 0.1.0 through 0.10.3: allows arbitrary code execution. An application is vulnerable if it reads pyfory serialized data from untrusted sourc | 41,3% | — |
| CVE-2025-60724 | CRIT 9.8 | microsoft 365_copilot Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. | 5,9% | — |
| CVE-2025-60021 | CRIT 9.8 | apache brpc Remote command injection vulnerability in heap profiler builtin service in Apache bRPC ((all versions < 1.15.0)) on all platforms allows attacker to inject remote command. Root Cause: The bRPC heap profiler built-in service (/pprof/heap) does not validate t | 24,8% | — |
| CVE-2025-59719 | CRIT 9.8 | fortinet fortiweb An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9 may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML | 29,5% | — |
| CVE-2025-59718 | CRIT 9.8 | fortinet fortios A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, | 68,7% | |
| CVE-2025-59390 | CRIT 9.8 | apache druid Apache Druid’s Kerberos authenticator uses a weak fallback secret when the `druid.auth.authenticator.kerberos.cookieSignatureSecret` configuration is not explicitly set. In this case, the secret is generated using `ThreadLocalRandom`, which is not a crypto-gr | 0,6% | — |
| CVE-2025-59287 | CRIT 9.8 | microsoft windows_server_2012 Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network. | 100,0% | |
| CVE-2025-59246 | CRIT 9.8 | microsoft entra_id Azure Entra ID Elevation of Privilege Vulnerability | 7,2% | — |
| CVE-2025-59245 | CRIT 9.8 | microsoft sharepoint_online Microsoft SharePoint Online Elevation of Privilege Vulnerability | 1,1% | — |
| CVE-2025-59059 | CRIT 9.8 | apache ranger Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions <= 2.7.0. Users are recommended to upgrade to version 2.8.0, which fixes this issue. | 1,2% | — |
| CVE-2025-55232 | CRIT 9.8 | microsoft hpc_pack Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an unauthorized attacker to execute code over a network. | 2,1% | — |
| CVE-2025-54947 | CRIT 9.8 | apache streampark In Apache StreamPark versions 2.0.0 through 2.1.7, a security vulnerability involving a hard-coded encryption key exists. This vulnerability occurs because the system uses a fixed, immutable key for encryption instead of dynamically generating or securely conf | 0,5% | — |
| CVE-2025-54539 | CRIT 9.8 | apache activemq_nms_amqp A Deserialization of Untrusted Data vulnerability exists in the Apache ActiveMQ NMS AMQP Client. This issue affects all versions of Apache ActiveMQ NMS AMQP up to and including 2.3.0, when establishing connections to untrusted AMQP servers. Malicious servers | 2,1% | — |
| CVE-2025-54466 | CRIT 9.8 | apache ofbiz Improper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum plugin. This issue affects Apache OFBiz: before 24.09.02 only when the scrum plugin is used. Even unauthenticated attackers can exploit th | 15,0% | — |
| CVE-2025-53770 | CRIT 9.8 | ransomware microsoft sharepoint_server Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a co | 100,0% | |
| CVE-2025-53766 | CRIT 9.8 | microsoft 365_copilot Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network. | 7,1% | — |
| CVE-2025-53763 | CRIT 9.8 | microsoft purview_data_governance Improper access control in Azure Databricks allows an unauthorized attacker to elevate privileges over a network. | 0,7% | — |
| CVE-2025-53606 | CRIT 9.8 | apache seata Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incubating): 2.4.0. Users are recommended to upgrade to version 2.5.0, which fixes the issue. | 0,6% | — |
| CVE-2025-53521 | CRIT 9.8 | f5 big-ip_access_policy_manager When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 2,2% | |
| CVE-2025-50213 | CRIT 9.8 | apache apache-airflow-providers-snowflake Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) vulnerability in Apache Airflow Providers Snowflake. This issue affects Apache Airflow Providers Snowflake: before 6.4.0. Sanitation of table and stage parameters were ad | 0,6% | — |
| CVE-2025-50165 | CRIT 9.8 | microsoft windows_11_24h2 Untrusted pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. | 9,5% | — |
| CVE-2025-49220 | CRIT 9.8 | trendmicro apex_central An insecure deserialization operation in Trend Micro Apex Central below version 8.0.7007 could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49219 but is in a different method. | 2,0% | — |
| CVE-2025-49219 | CRIT 9.8 | trendmicro apex_central An insecure deserialization operation in Trend Micro Apex Central below versions 8.0.7007 could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49220 but is in a different method | 1,4% | — |
| CVE-2025-49217 | CRIT 9.8 | trendmicro trend_micro_endpoint_encryption An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49213 but is in a different method | 1,1% | — |
| CVE-2025-49216 | CRIT 9.8 | trendmicro trend_micro_endpoint_encryption An authentication bypass vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to access key methods as an admin user and modify product configurations on affected installations. | 0,5% | — |