56.832 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.832 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2025-55248 | MED 4.8 | microsoft .net Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network. | 0,7% | — |
| CVE-2025-55247 | HIGH 7.3 | microsoft .net Improper link resolution before file access ('link following') in .NET allows an authorized attacker to elevate privileges locally. | 0,6% | — |
| CVE-2025-55245 | HIGH 7.8 | microsoft xbox_gaming_services Improper link resolution before file access ('link following') in Xbox allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-55244 | CRIT 9.0 | microsoft azure_ai_bot_service Azure Bot Service Elevation of Privilege Vulnerability | 0,6% | — |
| CVE-2025-55243 | HIGH 7.5 | microsoft officeplus Exposure of sensitive information to an unauthorized actor in Microsoft Office Plus allows an unauthorized attacker to perform spoofing over a network. | 1,1% | — |
| CVE-2025-55242 | MED 6.5 | microsoft xbox_gaming_services Exposure of sensitive information to an unauthorized actor in Xbox allows an unauthorized attacker to disclose information over a network. | 0,8% | — |
| CVE-2025-55241 | CRIT 10.0 | microsoft entra_id Azure Entra ID Elevation of Privilege Vulnerability | 1,6% | — |
| CVE-2025-55240 | HIGH 7.3 | microsoft visual_studio_2017 Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2025-55238 | HIGH 7.5 | microsoft dynamics_365 Dynamics 365 FastTrack Implementation Assets Information Disclosure Vulnerability | 0,8% | — |
| CVE-2025-55236 | HIGH 7.3 | microsoft windows_10_1809 Time-of-check time-of-use (toctou) race condition in Graphics Kernel allows an authorized attacker to execute code locally. | 0,4% | — |
| CVE-2025-55234 | HIGH 8.8 | microsoft windows_10_1507 SMB Server might be susceptible to relay attacks depending on the configuration. An attacker who successfully exploited these vulnerabilities could perform relay attacks and make the users subject to elevation of privilege attacks. The SMB Server already suppo | 20,1% | — |
| CVE-2025-55233 | HIGH 7.8 | microsoft windows_10_1809 Out-of-bounds read in Windows Projected File System allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-55232 | CRIT 9.8 | microsoft hpc_pack Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an unauthorized attacker to execute code over a network. | 2,1% | — |
| CVE-2025-55231 | HIGH 7.5 | microsoft windows_server_2012 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Storage allows an unauthorized attacker to execute code over a network. | 0,5% | — |
| CVE-2025-55230 | HIGH 7.8 | microsoft windows_10_1507 Untrusted pointer dereference in Windows MBT Transport driver allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2025-55229 | MED 5.3 | microsoft windows_10_1507 Improper verification of cryptographic signature in Windows Certificates allows an unauthorized attacker to perform spoofing over a network. | 0,5% | — |
| CVE-2025-55228 | HIGH 7.8 | microsoft windows_10_21h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to execute code locally. | 0,3% | — |
| CVE-2025-55227 | HIGH 8.8 | microsoft sql_server_2016 Improper neutralization of special elements used in a command ('command injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | 1,3% | — |
| CVE-2025-55226 | MED 6.7 | microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to execute code locally. | 0,5% | — |
| CVE-2025-55225 | MED 6.5 | microsoft windows_server_2008 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 1,2% | — |
| CVE-2025-55224 | HIGH 7.8 | microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to execute code locally. | 0,3% | — |
| CVE-2025-55223 | HIGH 7.0 | microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2025-55111 | MED 5.5 | bmc control-m\/agent Certain files with overly permissive permissions were identified in the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions as well as in newer versions which were upgraded from an affected version. These files | 0,1% | — |
| CVE-2025-55077 | HIGH 7.4 | tylertech erp_pro_9 Tyler Technologies ERP Pro 9 SaaS allows an authenticated user to escape the application and execute limited operating system commands within the remote Microsoft Windows environment with the privileges of the authenticated user. Tyler Technologies deployed ha | 0,2% | — |
| CVE-2025-55039 | MED 6.5 | apache spark This issue affects Apache Spark versions before 3.4.4, 3.5.2 and 4.0.0. Apache Spark versions before 4.0.0, 3.5.2 and 3.4.4 use an insecure default network encryption cipher for RPC communication between nodes. When spark.network.crypto.enabled is set to | 0,2% | — |