EN
56.831 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia

CVE Tracker

56.831 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordinato dal più alto
CVE-2025-64670 MED 6.5 microsoft windows_10_21h2 Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker to disclose information over a network. 1,0%
CVE-2025-64669 HIGH 7.8 microsoft windows_admin_center Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges locally. 0,5%
CVE-2025-64667 MED 5.3 microsoft exchange_server User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. 0,8%
CVE-2025-64666 HIGH 7.5 microsoft exchange_server Improper input validation in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. 1,0%
CVE-2025-64663 CRIT 9.9 microsoft azure_language Custom Question Answering Elevation of Privilege Vulnerability 0,7%
CVE-2025-64661 HIGH 7.8 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate privileges locally. 0,2%
CVE-2025-64660 HIGH 8.0 microsoft visual_studio_code Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to execute code over a network. 0,6%
CVE-2025-64658 HIGH 7.5 microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2025-64657 CRIT 9.8 microsoft azure_application_gateway Stack-based buffer overflow in Azure Application Gateway allows an unauthorized attacker to elevate privileges over a network. 0,6%
CVE-2025-64656 CRIT 9.4 microsoft azure_application_gateway Out-of-bounds read in Application Gateway allows an unauthorized attacker to elevate privileges over a network. 0,6%
CVE-2025-64655 HIGH 8.8 microsoft dynamics_omnichannel_sdk_storage_containers Improper authorization in Dynamics OmniChannel SDK Storage Containers allows an unauthorized attacker to elevate privileges over a network. 0,5%
CVE-2025-64649 MED 5.9 ibm concert IBM Concert 1.0.0 through 2.3.1 could allow a remote attacker to perform unauthorized actions using man in the middle techniques due to improper certificate validation.
CVE-2025-64531 HIGH 7.8 adobe substance_3d_stager Substance3D - Stager versions 3.1.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a m 0,2%
CVE-2025-64471 MED 4.9 fortinet fortiweb A use of password hash instead of password for authentication vulnerability [CWE-836] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0 0,3%
CVE-2025-64447 HIGH 8.1 fortinet fortiweb A reliance on cookies without validation and integrity checking vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an unaut 8,4%
CVE-2025-64408 MED 6.3 apache causeway Apache Causeway faces Java deserialization vulnerabilities that allow remote code execution (RCE) through user-controllable URL parameters. These vulnerabilities affect all applications using Causeway's ViewModel functionality and can be exploited by authentic 10,8%
CVE-2025-64407 MED 5.3 apache openoffice Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document that would cause external links to be loaded without prompt. Such links could also be used to transmit system inf 0,5%
CVE-2025-64406 MED 4.3 apache openoffice An out-of-bounds Write vulnerability in Apache OpenOffice could allow an attacker to craft a document that would crash the program, or otherwise corrupt other memory areas. This issue affects Apache OpenOffice: through 4.1.15. Users are recommended to upgrad 0,5%
CVE-2025-64405 HIGH 7.5 apache openoffice Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document that would cause external links to be loaded without prompt. In the affected versions of Apache OpenOffice, Calc 1,4%
CVE-2025-64404 HIGH 7.5 apache openoffice Apache OpenOffice documents can contain links to other files. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document that would cause external links to be loaded without prompt. In the affected versions of Apache Op 1,2%
CVE-2025-64403 HIGH 8.1 apache openoffice Apache OpenOffice Calc spreadsheet can contain links to other files, in the form of "external data sources". A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document that would cause such links to be loaded without pr 1,2%
CVE-2025-64402 MED 6.5 apache openoffice Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document that would cause external links to be loaded without prompt. In the affected versions of Apache OpenOffice, docum 0,5%
CVE-2025-64401 HIGH 7.5 apache openoffice Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document that would cause external links to be loaded without prompt. In the affected versions of Apache OpenOffice, docum 0,9%
CVE-2025-64299 LOW 2.7 secuavail logstare_collector LogStare Collector improperly handles the password hash data. An administrative user may obtain the other users' password hashes. 0,3%
CVE-2025-64298 HIGH 8.4 mirion biodose\/nmis NMIS/BioDose V22.02 and previous version installations where the embedded Microsoft SQLServer Express is used are exposed in the Windows share accessed by clients in networked installs. By default, this directory has insecure directory paths that allow access 0,2%