56.832 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.832 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più alto |
|---|---|---|---|---|
| CVE-2025-60709 | HIGH 7.8 | microsoft windows_10_1607 Out-of-bounds read in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | 0,5% | — |
| CVE-2025-60708 | MED 6.5 | microsoft windows_10_1607 Untrusted pointer dereference in Storvsp.sys Driver allows an authorized attacker to deny service locally. | 0,5% | — |
| CVE-2025-60707 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Multimedia Class Scheduler Service (MMCSS) allows an authorized attacker to elevate privileges locally. | 0,5% | — |
| CVE-2025-60706 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Hyper-V allows an authorized attacker to disclose information locally. | 0,5% | — |
| CVE-2025-60705 | HIGH 7.8 | microsoft windows_10_1607 Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally. | 2,4% | — |
| CVE-2025-60704 | HIGH 7.5 | microsoft windows_10_1607 Missing cryptographic step in Windows Kerberos allows an unauthorized attacker to elevate privileges over a network. | 0,5% | — |
| CVE-2025-60703 | HIGH 7.8 | microsoft windows_10_1607 Untrusted pointer dereference in Windows Remote Desktop allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-60024 | HIGH 8.8 | fortinet fortivoice Multiple Improper Limitations of a Pathname to a Restricted Directory ('Path Traversal') vulnerabilities [CWE-22] vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7 may allow a privileged authenticated attacker to write ar | 0,4% | — |
| CVE-2025-60021 | CRIT 9.8 | apache brpc Remote command injection vulnerability in heap profiler builtin service in Apache bRPC ((all versions < 1.15.0)) on all platforms allows attacker to inject remote command. Root Cause: The bRPC heap profiler built-in service (/pprof/heap) does not validate t | 24,8% | — |
| CVE-2025-60016 | HIGH 7.5 | f5 big-ip_next_cloud-native_network_functions When Diffie-Hellman (DH) group Elliptic Curve Cryptography (ECC) Brainpool curves are configured in an SSL profile's Cipher Rule or Cipher Group, and that profile is applied to a virtual server, undisclosed traffic can cause the Traffic Management Microkernel | 0,4% | — |
| CVE-2025-60015 | MED 5.7 | f5 f5os-a An out-of-bounds write vulnerability exists in F5OS-A and F5OS-C that could lead to memory corruption. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0,2% | — |
| CVE-2025-60013 | MED 4.6 | f5 f5os-a When a highly-privileged, authenticated attacker attempts to initialize the rSeries FIPS module using a password with special shell metacharacters, arbitrary system commands may be executed, and the FIPS hardware security module (HSM) may fail to initialize. A | 0,2% | — |
| CVE-2025-60012 | MED 6.3 | apache livy Malicious configuration can lead to unauthorized file access in Apache Livy. This issue affects Apache Livy 0.7.0 and 0.8.0 when connecting to Apache Spark 3.1 or later. A request that includes a Spark configuration value supported from Apache Spark version | 0,5% | — |
| CVE-2025-60011 | MED 5.8 | juniper junos An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause an availability impact for downstream device | 0,4% | — |
| CVE-2025-60010 | MED 5.4 | juniper junos A password aging vulnerability in the RADIUS client of Juniper Networks Junos OS and Junos OS Evolved allows an authenticated, network-based attacker to access the device without enforcing the required password change. Affected devices allow logins by users f | 0,2% | — |
| CVE-2025-60009 | MED 6.1 | juniper junos_space An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the CLI Configlet page that, when visited by another user, enables the attacke | 0,2% | — |
| CVE-2025-60007 | MED 5.5 | juniper junos A NULL Pointer Dereference vulnerability in the chassis daemon (chassisd) of Juniper Networks Junos OS on MX, SRX and EX Series allows a local attacker with low privileges to cause a Denial-of-Service (DoS). When a user executes the 'show chassis' command wi | 0,1% | — |
| CVE-2025-60006 | MED 5.3 | juniper junos_os_evolved Multiple instances of an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the CLI of Juniper Networks Junos OS Evolved could be used to elevate privileges and/or execute unauthorized commands. When | 1,0% | — |
| CVE-2025-60004 | HIGH 7.5 | juniper junos An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial-Of-Service (DoS). When an affected | 0,4% | — |
| CVE-2025-60003 | HIGH 7.5 | juniper junos A Buffer Over-read vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). When an affected device receives a BGP update with a | 0,4% | — |
| CVE-2025-60002 | MED 6.1 | juniper junos_space An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Template Definitions page that, when visited by another user, enables the atta | 0,2% | — |
| CVE-2025-60001 | MED 6.1 | juniper junos_space An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Generate Report page that, when visited by another user, enables the attacker | 0,2% | — |
| CVE-2025-60000 | MED 6.1 | juniper junos_space An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Generate Report page that, when visited by another user, enables the attacker | 0,2% | — |
| CVE-2025-59999 | MED 6.1 | juniper junos_space An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the API Access Profiles page that, when visited by another user, enables the attac | 0,2% | — |
| CVE-2025-59998 | MED 6.1 | juniper junos_space An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Archive Log screen that, when visited by another user, enables the attacker to | 0,2% | — |