56.832 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.832 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2025-55688 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2025-55687 | HIGH 7.4 | microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Resilient File System (ReFS) allows an unauthorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2025-55686 | HIGH 7.0 | microsoft windows_10_21h2 Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2025-55685 | HIGH 7.0 | microsoft windows_10_21h2 Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2025-55684 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2025-55683 | MED 5.5 | microsoft windows_server_2016 Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally. | 0,5% | — |
| CVE-2025-55682 | MED 6.1 | microsoft windows_11_24h2 Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. | 0,5% | — |
| CVE-2025-55681 | HIGH 7.0 | microsoft windows_10_1809 Out-of-bounds read in Windows DWM allows an authorized attacker to elevate privileges locally. | 5,2% | — |
| CVE-2025-55680 | HIGH 7.8 | microsoft windows_10_1809 Time-of-check time-of-use (toctou) race condition in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-55679 | MED 5.1 | microsoft windows_10_1809 Improper input validation in Windows Kernel allows an unauthorized attacker to disclose information locally. | 0,4% | — |
| CVE-2025-55678 | HIGH 7.0 | microsoft windows_10_1507 Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2025-55677 | HIGH 7.8 | microsoft windows_11_24h2 Untrusted pointer dereference in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-55676 | MED 5.5 | microsoft windows_11_24h2 Generation of error message containing sensitive information in Windows USB Video Driver allows an authorized attacker to disclose information locally. | 0,6% | — |
| CVE-2025-55675 | MED 6.5 | apache superset Apache Superset contains an improper access control vulnerability in its /explore endpoint. A missing authorization check allows an authenticated user to discover metadata about datasources they do not have permission to access. By iterating through the dataso | 0,5% | — |
| CVE-2025-55674 | MED 6.5 | apache superset A bypass of the DISALLOWED_SQL_FUNCTIONS security feature in Apache Superset allows for the execution of blocked SQL functions. An attacker can use a special inline block to circumvent the denylist. This allows a user with SQL Lab access to execute functions t | 0,7% | — |
| CVE-2025-55673 | MED 4.3 | apache superset When a guest user accesses a chart in Apache Superset, the API response from the /chart/data endpoint includes a query field in its payload. This field contains the underlying query, which improperly discloses database schema information, such as table names, | 0,6% | — |
| CVE-2025-55672 | MED 5.4 | apache superset A stored Cross-Site Scripting (XSS) vulnerability exists in Apache Superset's chart visualization. An authenticated user with permissions to edit charts can inject a malicious payload into a column's label. The payload is not properly sanitized and gets execut | 0,7% | — |
| CVE-2025-55670 | MED 6.5 | f5 big-ip_next_cloud-native_network_functions On BIG-IP Next CNF, BIG-IP Next SPK, and BIG-IP Next for Kubernetes systems, repeated undisclosed API calls can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not eva | 0,3% | — |
| CVE-2025-55669 | HIGH 7.5 | f5 big-ip_application_security_manager When the BIG-IP Advanced WAF and ASM security policy and a server-side HTTP/2 profile are configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Te | 0,4% | — |
| CVE-2025-55668 | MED 6.5 | apache tomcat Session Fixation vulnerability in Apache Tomcat via rewrite valve. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. Older, EOL versions may also be affected. Users are recommended | 0,8% | — |
| CVE-2025-55526 | CRIT 9.1 | n8n fastapi n8n-workflows Main Commit ee25413 allows attackers to execute a directory traversal via the download_workflow function within api_server.py | 0,8% | — |
| CVE-2025-55340 | HIGH 7.0 | microsoft windows_10_21h2 Improper authentication in Windows Remote Desktop Protocol allows an authorized attacker to bypass a security feature locally. | 0,3% | — |
| CVE-2025-55339 | HIGH 7.8 | microsoft windows_11_22h2 Out-of-bounds read in Windows NDIS allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-55338 | MED 6.1 | microsoft windows_10_1507 Missing Ability to Patch ROM Code in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. | 3,0% | — |
| CVE-2025-55337 | MED 6.1 | microsoft windows_11_24h2 Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. | 0,5% | — |