56.831 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.831 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2025-59962 | MED 5.3 | juniper junos An Access of Uninitialized Pointer vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved with BGP sharding configured allows an attacker triggering indirect next-hop updates, along with timing outside the attacker | 0,2% | — |
| CVE-2025-59961 | MED 5.5 | juniper junos An Incorrect Permission Assignment for Critical Resource vulnerability in the Juniper DHCP daemon (jdhcpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged user to write to the Unix socket used to manage the jdhcpd process, resu | 0,1% | — |
| CVE-2025-59960 | HIGH 7.4 | juniper junos An Improper Check for Unusual or Exceptional Conditions vulnerability in the Juniper DHCP service (jdhcpd) of Juniper Networks Junos OS and Junos OS Evolved allows a DHCP client in one subnet to exhaust the address pools of other subnets, leading to a Denial o | 0,3% | — |
| CVE-2025-59959 | MED 5.5 | juniper junos An Untrusted Pointer Dereference vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with low privileges to cause a Denial-of-Service (DoS). When the command 'show route < | 0,1% | — |
| CVE-2025-59958 | MED 6.5 | juniper junos_os_evolved An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated, network-based attacker to cause impact to confidentiality and availability | 0,3% | — |
| CVE-2025-59957 | MED 6.8 | juniper junos An Origin Validation Error vulnerability in an insufficient protected file of Juniper Networks Junos OS on EX4600 Series and QFX5000 Series allows an unauthenticated attacker with physical access to the device to create a backdoor which allows complete control | 0,2% | — |
| CVE-2025-59923 | LOW 2.7 | fortinet fortiauthenticator An improper access control vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may allow an authenticated attacker with at least read-on | 0,2% | — |
| CVE-2025-59922 | HIGH 7.2 | fortinet forticlientems An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.4, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2.0 through 7.2.10, FortiClientEMS | 7,1% | — |
| CVE-2025-59921 | MED 6.5 | fortinet fortiadc An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiADC version 7.4.0, version 7.2.3 and below, version 7.1.4 and below, 7.0 all versions, 6.2 all versions may allow an authenticated attacker to obtain sensiti | 0,3% | — |
| CVE-2025-59810 | MED 6.5 | fortinet fortisoar An improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7.5.1, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.2, FortiSOAR on-premise 7.5.0 | 0,3% | — |
| CVE-2025-59809 | MED 4.3 | fortinet fortisoar A server-side request forgery (ssrf) vulnerability [CWE-918] vulnerability in Fortinet FortiSOAR PaaS 7.6.4, FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on- | 0,2% | — |
| CVE-2025-59808 | MED 6.8 | fortinet fortisoar An unverified password change vulnerability [CWE-620] vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7.5.1, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.2, | 0,2% | — |
| CVE-2025-59803 | MED 5.3 | foxit pdf_editor Foxit PDF Editor and Reader before 2025.2.1 allow signature spoofing via triggers. An attacker can embed triggers (e.g., JavaScript) in a PDF document that execute during the signing process. When a signer reviews the document, the content appears normal. Howe | 0,2% | — |
| CVE-2025-59802 | HIGH 7.5 | foxit pdf_editor Foxit PDF Editor and Reader before 2025.2.1 allow signature spoofing via OCG. When Optional Content Groups (OCG) are supported, the state property of an OCG is runtime-only and not included in the digital signature computation buffer. An attacker can leverage | 0,3% | — |
| CVE-2025-59792 | MED 5.3 | apache kvrocks Reveals plaintext credentials in the MONITOR command vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 1.0.0 through 2.13.0. Users are recommended to upgrade to version 2.14.0, which fixes the issue. | 0,3% | — |
| CVE-2025-59790 | MED 5.4 | apache kvrocks Improper Privilege Management vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from v2.9.0 through v2.13.0. Users are recommended to upgrade to version 2.14.0, which fixes the issue. | 0,4% | — |
| CVE-2025-59789 | HIGH 7.5 | apache brpc Uncontrolled recursion in the json2pb component in Apache bRPC (version < 1.15.0) on all platforms allows remote attackers to make the server crash via sending deep recursive json data. Root Cause: The bRPC json2pb component uses rapidjson to parse json data | 1,6% | — |
| CVE-2025-59781 | HIGH 7.5 | f5 big-ip_access_policy_manager When DNS cache is configured on a BIG-IP or BIG-IP Next CNF virtual server, undisclosed DNS queries can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0,3% | — |
| CVE-2025-59778 | HIGH 7.5 | f5 f5os-c When the Allowed IP Addresses feature is configured on the F5OS-C partition control plane, undisclosed traffic can cause multiple containers to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0,3% | — |
| CVE-2025-59775 | HIGH 7.5 | apache http_server Server-Side Request Forgery (SSRF) vulnerability in Apache HTTP Server on Windows with AllowEncodedSlashes On and MergeSlashes Off allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content Users are recomme | 0,8% | — |
| CVE-2025-59719 | CRIT 9.8 | fortinet fortiweb An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9 may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML | 29,5% | — |
| CVE-2025-59669 | MED 5.3 | fortinet fortiweb A use of hard-coded credentials vulnerability in Fortinet FortiWeb 7.6.0, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow an authenticated attacker with shell access to the device to connect to redis service and access | 0,1% | — |
| CVE-2025-59517 | HIGH 7.8 | microsoft windows_10_1607 Improper access control in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally. | 2,4% | — |
| CVE-2025-59516 | HIGH 7.8 | microsoft windows_10_1809 Missing authentication for critical function in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally. | 2,3% | — |
| CVE-2025-59515 | HIGH 7.0 | microsoft windows_10_1809 Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally. | 0,3% | — |