EN
56.832 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia

CVE Tracker

56.832 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordinato dal più alto
CVE-2025-62458 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. 0,7%
CVE-2025-62457 HIGH 7.8 microsoft windows_10_1809 Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. 0,4%
CVE-2025-62456 HIGH 8.8 microsoft windows_11_23h2 Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code over a network. 1,1%
CVE-2025-62455 HIGH 7.8 microsoft windows_10_1607 Improper input validation in Windows Message Queuing allows an authorized attacker to elevate privileges locally. 0,5%
CVE-2025-62454 HIGH 7.8 microsoft windows_10_1809 Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. 2,3%
CVE-2025-62453 MED 5.0 microsoft visual_studio_code Improper validation of generative ai output in GitHub Copilot and Visual Studio Code allows an authorized attacker to bypass a security feature locally. 0,4%
CVE-2025-62452 HIGH 8.0 microsoft windows_10_1607 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. 0,8%
CVE-2025-62449 MED 6.8 microsoft github_copilot_chat Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code CoPilot Chat Extension allows an authorized attacker to bypass a security feature locally. 0,5%
CVE-2025-62402 MED 5.4 apache airflow API users via `/api/v2/dagReports` could perform Dag code execution in the context of the api-server if the api-server was deployed in the environment where Dag files were available. 0,5%
CVE-2025-62235 HIGH 8.1 apache nimble Authentication Bypass by Spoofing vulnerability in Apache NimBLE. Receiving specially crafted Security Request could lead to removal of original bond and re-bond with impostor. This issue affects Apache NimBLE: through 1.8.0. Users are recommended to upgrade 0,4%
CVE-2025-62233 MED 6.3 apache dolphinscheduler Deserialization of Untrusted Data vulnerability in Apache DolphinScheduler RPC module. This issue affects Apache DolphinScheduler:  Version >= 3.2.0 and < 3.3.1. Attackers who can access the Master or Worker nodes can compromise the system by creating a Sta 0,5%
CVE-2025-62232 HIGH 7.5 apache apisix Sensitive data exposure via logging in basic-auth leads to plaintext usernames and passwords written to error logs and forwarded to log sinks when log level is INFO/DEBUG. This creates a high risk of credential compromise through log access. It has been fixed 0,4%
CVE-2025-62228 HIGH 8.8 apache flink_cdc Apache Flink CDC version 3.4.0 was vulnerable to a SQL injection via maliciously crafted identifiers eg. crafted database name or crafted table name. Even through only the logged-in database user can trigger the attack, we recommend users update Flink CDC vers 0,4%
CVE-2025-62224 MED 5.5 microsoft edge User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an authorized attacker to perform spoofing over a network. 0,3%
CVE-2025-62223 MED 4.3 microsoft edge_chromium User interface (ui) misrepresentation of critical information in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network. 0,4%
CVE-2025-62222 HIGH 8.8 microsoft github_copilot_chat Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to execute code over a network. 0,7%
CVE-2025-62220 HIGH 8.8 microsoft windows_subsystem_for_linux Heap-based buffer overflow in Windows Subsystem for Linux GUI allows an unauthorized attacker to execute code over a network. 0,7%
CVE-2025-62219 HIGH 7.0 microsoft windows_10_1607 Double free in Microsoft Wireless Provisioning System allows an authorized attacker to elevate privileges locally. 0,2%
CVE-2025-62218 HIGH 7.0 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Wireless Provisioning System allows an authorized attacker to elevate privileges locally. 0,2%
CVE-2025-62217 HIGH 7.0 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2025-62216 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 0,4%
CVE-2025-62214 MED 6.7 microsoft visual_studio_2022 Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code locally. 1,0%
CVE-2025-62213 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 1,6%
CVE-2025-62211 HIGH 8.7 microsoft dynamics_365 Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over a network. 0,6%
CVE-2025-62210 HIGH 8.7 microsoft dynamics_365 Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over a network. 0,6%