56.807 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.807 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2025-62458 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | 0,7% | — |
| CVE-2025-62457 | HIGH 7.8 | microsoft windows_10_1809 Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-62456 | HIGH 8.8 | microsoft windows_11_23h2 Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code over a network. | 1,1% | — |
| CVE-2025-62455 | HIGH 7.8 | microsoft windows_10_1607 Improper input validation in Windows Message Queuing allows an authorized attacker to elevate privileges locally. | 0,5% | — |
| CVE-2025-62454 | HIGH 7.8 | microsoft windows_10_1809 Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. | 2,3% | — |
| CVE-2025-62453 | MED 5.0 | microsoft visual_studio_code Improper validation of generative ai output in GitHub Copilot and Visual Studio Code allows an authorized attacker to bypass a security feature locally. | 0,4% | — |
| CVE-2025-62452 | HIGH 8.0 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. | 0,8% | — |
| CVE-2025-62449 | MED 6.8 | microsoft github_copilot_chat Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code CoPilot Chat Extension allows an authorized attacker to bypass a security feature locally. | 0,5% | — |
| CVE-2025-62402 | MED 5.4 | apache airflow API users via `/api/v2/dagReports` could perform Dag code execution in the context of the api-server if the api-server was deployed in the environment where Dag files were available. | 0,5% | — |
| CVE-2025-62235 | HIGH 8.1 | apache nimble Authentication Bypass by Spoofing vulnerability in Apache NimBLE. Receiving specially crafted Security Request could lead to removal of original bond and re-bond with impostor. This issue affects Apache NimBLE: through 1.8.0. Users are recommended to upgrade | 0,4% | — |
| CVE-2025-62233 | MED 6.3 | apache dolphinscheduler Deserialization of Untrusted Data vulnerability in Apache DolphinScheduler RPC module. This issue affects Apache DolphinScheduler: Version >= 3.2.0 and < 3.3.1. Attackers who can access the Master or Worker nodes can compromise the system by creating a Sta | 0,5% | — |
| CVE-2025-62232 | HIGH 7.5 | apache apisix Sensitive data exposure via logging in basic-auth leads to plaintext usernames and passwords written to error logs and forwarded to log sinks when log level is INFO/DEBUG. This creates a high risk of credential compromise through log access. It has been fixed | 0,4% | — |
| CVE-2025-62228 | HIGH 8.8 | apache flink_cdc Apache Flink CDC version 3.4.0 was vulnerable to a SQL injection via maliciously crafted identifiers eg. crafted database name or crafted table name. Even through only the logged-in database user can trigger the attack, we recommend users update Flink CDC vers | 0,4% | — |
| CVE-2025-62224 | MED 5.5 | microsoft edge User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an authorized attacker to perform spoofing over a network. | 0,3% | — |
| CVE-2025-62223 | MED 4.3 | microsoft edge_chromium User interface (ui) misrepresentation of critical information in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network. | 0,4% | — |
| CVE-2025-62222 | HIGH 8.8 | microsoft github_copilot_chat Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to execute code over a network. | 0,7% | — |
| CVE-2025-62220 | HIGH 8.8 | microsoft windows_subsystem_for_linux Heap-based buffer overflow in Windows Subsystem for Linux GUI allows an unauthorized attacker to execute code over a network. | 0,7% | — |
| CVE-2025-62219 | HIGH 7.0 | microsoft windows_10_1607 Double free in Microsoft Wireless Provisioning System allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2025-62218 | HIGH 7.0 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Wireless Provisioning System allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2025-62217 | HIGH 7.0 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2025-62216 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2025-62214 | MED 6.7 | microsoft visual_studio_2022 Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code locally. | 1,0% | — |
| CVE-2025-62213 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 1,6% | — |
| CVE-2025-62211 | HIGH 8.7 | microsoft dynamics_365 Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over a network. | 0,6% | — |
| CVE-2025-62210 | HIGH 8.7 | microsoft dynamics_365 Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over a network. | 0,6% | — |