EN
56.831 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia

CVE Tracker

56.831 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordinato dal più alto
CVE-2025-65082 MED 6.5 apache http_server Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. This issue affects A 0,8%
CVE-2025-6505 HIGH 8.1 progress hybrid_data_pipeline Unauthorized access and impersonation can occur in versions 4.6.2.3226 and below of Progress Software's Hybrid Data Pipeline Server on Linux. This vulnerability allows attackers to combine credentials from different sources, potentially leading to client imper 0,3%
CVE-2025-65046 LOW 3.1 microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability 0,3%
CVE-2025-65041 CRIT 10.0 microsoft partner_center Improper authorization in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network. 0,8%
CVE-2025-6504 HIGH 8.4 progress hybrid_data_pipeline In HDP Server versions below 4.6.2.2978 on Linux, unauthorized access could occur via IP spoofing using the X-Forwarded-For header.  Since XFF is a client-controlled header, it could be spoofed, allowing unauthorized access if the spoofed IP matched a whiteli 0,2%
CVE-2025-65037 CRIT 10.0 microsoft azure_container_apps Improper control of generation of code ('code injection') in Azure Container Apps allows an unauthorized attacker to execute code over a network. 1,0%
CVE-2025-64899 HIGH 7.8 adobe acrobat Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure 0,5%
CVE-2025-64894 MED 5.5 adobe dng_software_development_kit DNG SDK versions 1.7.0 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could lead to application denial-of-service. An attacker could exploit this issue to cause the application to crash or become unresponsive. Exploitation of 0,2%
CVE-2025-64893 HIGH 7.1 adobe dng_software_development_kit DNG SDK versions 1.7.0 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure or application denial of service. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploi 0,2%
CVE-2025-64787 LOW 3.3 adobe acrobat Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Improper Verification of Cryptographic Signature vulnerability that could result in a Security feature bypass. An attacker could leverag 0,4%
CVE-2025-64786 LOW 3.3 adobe acrobat Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Improper Verification of Cryptographic Signature vulnerability that could result in a Security feature bypass. An attacker could leverag 0,4%
CVE-2025-64785 HIGH 7.8 adobe acrobat Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the context of the current user. If the appl 0,5%
CVE-2025-64784 HIGH 7.1 adobe dng_software_development_kit DNG SDK versions 1.7.0 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead to memory exposure or application denial of service. An attacker could leverage this vulnerability to disclose sensitive memory information. Exploitat 0,2%
CVE-2025-64783 HIGH 7.8 adobe dng_software_development_kit DNG SDK versions 1.7.0 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open 0,2%
CVE-2025-64775 HIGH 7.5 apache struts Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. This issue affects Apache Struts: from 2.0.0 through 6.7.0, from 7.0.0 through 7.0.3. Users are recommended to upgrade to version 6.8.0 or 7.1 1,5%
CVE-2025-64695 HIGH 7.8 secuavail logstare_collector Uncontrolled search path element issue exists in the installer of LogStare Collector (for Windows). If exploited, arbitrary code may be executed with the privilege of the user invoking the installer. 0,1%
CVE-2025-64680 HIGH 7.8 microsoft windows_10_1507 Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. 0,4%
CVE-2025-64679 HIGH 7.8 microsoft windows_10_1507 Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. 0,5%
CVE-2025-64678 HIGH 8.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. 1,0%
CVE-2025-64677 HIGH 8.2 microsoft office_out-of-box_experience Improper neutralization of input during web page generation ('cross-site scripting') in Office Out-of-Box Experience allows an unauthorized attacker to perform spoofing over a network. 0,5%
CVE-2025-64676 HIGH 7.2 microsoft purview '.../...//' in Microsoft Purview allows an authorized attacker to execute code over a network. 1,0%
CVE-2025-64675 HIGH 8.3 microsoft azure_cosmos_db Improper neutralization of input during web page generation ('cross-site scripting') in Azure Cosmos DB allows an unauthorized attacker to perform spoofing over a network. 0,7%
CVE-2025-64673 HIGH 7.8 microsoft windows_10_1809 Improper access control in Storvsp.sys Driver allows an authorized attacker to elevate privileges locally. 0,4%
CVE-2025-64672 HIGH 8.8 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 1,0%
CVE-2025-64671 HIGH 8.4 microsoft github_copilot Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to execute code locally. 0,4%