56.831 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.831 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più alto |
|---|---|---|---|---|
| CVE-2025-64670 | MED 6.5 | microsoft windows_10_21h2 Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker to disclose information over a network. | 1,0% | — |
| CVE-2025-64669 | HIGH 7.8 | microsoft windows_admin_center Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges locally. | 0,5% | — |
| CVE-2025-64667 | MED 5.3 | microsoft exchange_server User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | 0,8% | — |
| CVE-2025-64666 | HIGH 7.5 | microsoft exchange_server Improper input validation in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | 1,0% | — |
| CVE-2025-64663 | CRIT 9.9 | microsoft azure_language Custom Question Answering Elevation of Privilege Vulnerability | 0,7% | — |
| CVE-2025-64661 | HIGH 7.8 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2025-64660 | HIGH 8.0 | microsoft visual_studio_code Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to execute code over a network. | 0,6% | — |
| CVE-2025-64658 | HIGH 7.5 | microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2025-64657 | CRIT 9.8 | microsoft azure_application_gateway Stack-based buffer overflow in Azure Application Gateway allows an unauthorized attacker to elevate privileges over a network. | 0,6% | — |
| CVE-2025-64656 | CRIT 9.4 | microsoft azure_application_gateway Out-of-bounds read in Application Gateway allows an unauthorized attacker to elevate privileges over a network. | 0,6% | — |
| CVE-2025-64655 | HIGH 8.8 | microsoft dynamics_omnichannel_sdk_storage_containers Improper authorization in Dynamics OmniChannel SDK Storage Containers allows an unauthorized attacker to elevate privileges over a network. | 0,5% | — |
| CVE-2025-64649 | MED 5.9 | ibm concert IBM Concert 1.0.0 through 2.3.1 could allow a remote attacker to perform unauthorized actions using man in the middle techniques due to improper certificate validation. | — | — |
| CVE-2025-64531 | HIGH 7.8 | adobe substance_3d_stager Substance3D - Stager versions 3.1.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a m | 0,2% | — |
| CVE-2025-64471 | MED 4.9 | fortinet fortiweb A use of password hash instead of password for authentication vulnerability [CWE-836] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0 | 0,3% | — |
| CVE-2025-64447 | HIGH 8.1 | fortinet fortiweb A reliance on cookies without validation and integrity checking vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an unaut | 8,4% | — |
| CVE-2025-64408 | MED 6.3 | apache causeway Apache Causeway faces Java deserialization vulnerabilities that allow remote code execution (RCE) through user-controllable URL parameters. These vulnerabilities affect all applications using Causeway's ViewModel functionality and can be exploited by authentic | 10,8% | — |
| CVE-2025-64407 | MED 5.3 | apache openoffice Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document that would cause external links to be loaded without prompt. Such links could also be used to transmit system inf | 0,5% | — |
| CVE-2025-64406 | MED 4.3 | apache openoffice An out-of-bounds Write vulnerability in Apache OpenOffice could allow an attacker to craft a document that would crash the program, or otherwise corrupt other memory areas. This issue affects Apache OpenOffice: through 4.1.15. Users are recommended to upgrad | 0,5% | — |
| CVE-2025-64405 | HIGH 7.5 | apache openoffice Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document that would cause external links to be loaded without prompt. In the affected versions of Apache OpenOffice, Calc | 1,4% | — |
| CVE-2025-64404 | HIGH 7.5 | apache openoffice Apache OpenOffice documents can contain links to other files. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document that would cause external links to be loaded without prompt. In the affected versions of Apache Op | 1,2% | — |
| CVE-2025-64403 | HIGH 8.1 | apache openoffice Apache OpenOffice Calc spreadsheet can contain links to other files, in the form of "external data sources". A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document that would cause such links to be loaded without pr | 1,2% | — |
| CVE-2025-64402 | MED 6.5 | apache openoffice Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document that would cause external links to be loaded without prompt. In the affected versions of Apache OpenOffice, docum | 0,5% | — |
| CVE-2025-64401 | HIGH 7.5 | apache openoffice Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document that would cause external links to be loaded without prompt. In the affected versions of Apache OpenOffice, docum | 0,9% | — |
| CVE-2025-64299 | LOW 2.7 | secuavail logstare_collector LogStare Collector improperly handles the password hash data. An administrative user may obtain the other users' password hashes. | 0,3% | — |
| CVE-2025-64298 | HIGH 8.4 | mirion biodose\/nmis NMIS/BioDose V22.02 and previous version installations where the embedded Microsoft SQLServer Express is used are exposed in the Windows share accessed by clients in networked installs. By default, this directory has insecure directory paths that allow access | 0,2% | — |