56.832 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.832 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più alto |
|---|---|---|---|---|
| CVE-2025-64298 | HIGH 8.4 | mirion biodose\/nmis NMIS/BioDose V22.02 and previous version installations where the embedded Microsoft SQLServer Express is used are exposed in the Windows share accessed by clients in networked installs. By default, this directory has insecure directory paths that allow access | 0,2% | — |
| CVE-2025-64157 | MED 6.7 | fortinet fortios A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0 all versions allows an authenticated admin to execute unauthorized code or commands via s | 1,4% | — |
| CVE-2025-64156 | HIGH 7.2 | fortinet fortivoice An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7, FortiVoice 6.4 all versions, FortiVoice 6.0 all versions may allow an authenticate | 0,3% | — |
| CVE-2025-64155 | CRIT 9.8 | fortinet fortisiem An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4, FortiSIEM 7.1.0 through 7.1.8, FortiSIEM 7.0.0 through 7.0.4, FortiSIEM 6.7.0 through 6.7.10 | 43,2% | — |
| CVE-2025-64153 | HIGH 7.2 | fortinet fortiextender_firmware A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiExtender 7.6.0 through 7.6.3, FortiExtender 7.4.0 through 7.4.7, FortiExtender 7.2 all versions, FortiExtender 7.0 all versions may allow an authentic | 1,7% | — |
| CVE-2025-63372 | MED 4.3 | articentgroup zip_rar_extractor_tool Articentgroup Zip Rar Extractor Tool 1.345.93.0 is vulnerable to Directory Traversal. The vulnerability resides in the ZIP file processing component, specifically in the functionality responsible for extracting and handling ZIP archive contents. | 0,4% | — |
| CVE-2025-62826 | LOW 3.1 | fortinet fortios An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiProxy 7.6.0 through 7.6.4, FortiPro | 0,4% | — |
| CVE-2025-62821 | CRIT 9.1 | microsoft heif_image_extension Microsoft HEIF Image Extensions 1.2.22.0 has an out-of-bounds read because CHEIFItemInfoEntry_GetDataSize can return success while leaving the reported data size as 0. This causes a caller to make a 1-byte allocation. Later, CopyPixels computes copy_size = str | 1,1% | — |
| CVE-2025-62728 | MED 5.4 | apache hive SQL injection vulnerability in Hive Metastore Server (HMS) when processing delete column statistics requests via the Thrift APIs. The vulnerability is only exploitable by trusted/authorized users/applications that are allowed to call directly the Thrift APIs. | 0,4% | — |
| CVE-2025-62687 | MED 6.5 | secuavail logstare_collector Cross-site request forgery vulnerability exists in LogStare Collector. If a user views a crafted page while logged, unintended operations may be performed. | 0,1% | — |
| CVE-2025-62676 | HIGH 7.1 | fortinet forticlient An Improper Link Resolution Before File Access ('Link Following') vulnerability [CWE-59] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.4, FortiClientWindows 7.2.0 through 7.2.12, FortiClientWindows 7.0 all versions may allow a local low-privil | 0,2% | — |
| CVE-2025-62675 | LOW 3.4 | fortinet fortios An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiProxy 7.6.0 through 7.6.4, FortiPro | 0,3% | — |
| CVE-2025-62631 | MED 5.6 | fortinet fortios An insufficient session expiration vulnerability [CWE-613] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions allows attacker to maintain access to network resources via an active SSLVPN sessio | 0,3% | — |
| CVE-2025-62573 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2025-62572 | HIGH 7.8 | microsoft windows_11_24h2 Out-of-bounds read in Application Information Services allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-62571 | HIGH 7.8 | microsoft windows_10_1607 Improper input validation in Windows Installer allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-62570 | HIGH 7.1 | microsoft windows_11_24h2 Improper access control in Windows Camera Frame Server Monitor allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2025-62569 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2025-62567 | MED 5.3 | microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Windows Hyper-V allows an authorized attacker to deny service over a network. | 1,0% | — |
| CVE-2025-62565 | HIGH 7.3 | microsoft windows_10_1607 Use after free in Windows Shell allows an authorized attacker to elevate privileges locally. | 0,6% | — |
| CVE-2025-62564 | HIGH 7.8 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0,5% | — |
| CVE-2025-62563 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0,6% | — |
| CVE-2025-62562 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code locally. | 0,8% | — |
| CVE-2025-62561 | HIGH 7.8 | microsoft 365_apps Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0,5% | — |
| CVE-2025-62560 | HIGH 7.8 | microsoft 365_apps Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0,5% | — |