56.807 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.807 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2025-61787 | HIGH 8.1 | deno deno Deno is a JavaScript, TypeScript, and WebAssembly runtime. Versions prior to 2.5.3 and 2.2.15 are vulnerable to Command Line Injection attacks on Windows when batch files are executed. In Windows, ``CreateProcess()`` always implicitly spawns ``cmd.exe`` if a b | 2,1% | — |
| CVE-2025-61735 | HIGH 7.3 | apache kylin Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin. This issue affects Apache Kylin: from 4.0.0 through 5.0.2. You are fine as long as the Kylin's system and project admin access is well protected. Users are recommended to upgrade to version 5. | 0,5% | — |
| CVE-2025-61734 | HIGH 7.5 | apache kylin Files or Directories Accessible to External Parties vulnerability in Apache Kylin. You are fine as long as the Kylin's system and project admin access is well protected. This issue affects Apache Kylin: from 4.0.0 through 5.0.2. Users are recommended to upg | 18,4% | — |
| CVE-2025-61733 | HIGH 7.5 | apache kylin Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Kylin. This issue affects Apache Kylin: from 4.0.0 through 5.0.2. Users are recommended to upgrade to version 5.0.3, which fixes the issue. | 1,2% | — |
| CVE-2025-61713 | MED 4.2 | fortinet fortipam A Cleartext Storage of Sensitive Information in Memory vulnerability [CWE-316] in Fortinet FortiPAM 1.6.0, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all v | 0,1% | — |
| CVE-2025-61624 | MED 6.0 | fortinet fortios An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPA | 0,5% | — |
| CVE-2025-61623 | MED 6.5 | apache ofbiz Reflected cross-site scripting vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.03. Users are recommended to upgrade to version 24.09.03, which fixes the issue. | 0,8% | — |
| CVE-2025-61622 | CRIT 9.8 | apache fory Deserialization of untrusted data in python in pyfory versions 0.12.0 through 0.12.2, or the legacy pyfury versions from 0.1.0 through 0.10.3: allows arbitrary code execution. An application is vulnerable if it reads pyfory serialized data from untrusted sourc | 41,3% | — |
| CVE-2025-61581 | HIGH 7.5 | apache traffic_control ** UNSUPPORTED WHEN ASSIGNED ** Inefficient Regular Expression Complexity vulnerability in Apache Traffic Control. This issue affects Apache Traffic Control: all versions. People with access to the management interface of the Traffic Router component could s | 0,7% | — |
| CVE-2025-60728 | MED 4.3 | microsoft 365_apps Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. | 0,7% | — |
| CVE-2025-60727 | HIGH 7.8 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0,6% | — |
| CVE-2025-60726 | HIGH 7.1 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | 0,6% | — |
| CVE-2025-60724 | CRIT 9.8 | microsoft 365_copilot Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. | 5,9% | — |
| CVE-2025-60723 | MED 6.3 | microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an authorized attacker to deny service over a network. | 0,8% | — |
| CVE-2025-60722 | MED 6.5 | microsoft onedrive Improper limitation of a pathname to a restricted directory ('path traversal') in OneDrive for Android allows an authorized attacker to elevate privileges over a network. | 0,8% | — |
| CVE-2025-60721 | HIGH 7.8 | microsoft windows_11_24h2 Privilege context switching error in Windows Administrator Protection allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-60720 | HIGH 7.8 | microsoft windows_10_1607 Buffer over-read in Windows TDX.sys allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-60719 | HIGH 7.0 | microsoft windows_10_1607 Untrusted pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 1,8% | — |
| CVE-2025-60718 | HIGH 7.8 | microsoft windows_11_24h2 Untrusted search path in Windows Administrator Protection allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-60717 | HIGH 7.0 | microsoft windows_10_1809 Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2025-60716 | HIGH 7.0 | microsoft windows_10_1809 Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-60715 | HIGH 8.0 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. | 0,8% | — |
| CVE-2025-60714 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows OLE allows an unauthorized attacker to execute code locally. | 0,6% | — |
| CVE-2025-60713 | HIGH 7.8 | microsoft windows_server_2016 Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-60711 | MED 6.3 | microsoft edge_chromium Protection mechanism failure in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0,4% | — |