EN
56.832 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia

CVE Tracker

56.832 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordinato dal più basso
CVE-2025-55036 HIGH 7.5 f5 big-ip_ssl_orchestrator When BIG-IP SSL Orchestrator explicit forward proxy is configured on a virtual server and the proxy connect feature is enabled, undisclosed traffic may cause memory corruption.  Note: Software versions which have reached End of Technical Support (EoTS) are not 0,3%
CVE-2025-55018 MED 5.8 fortinet fortios An inconsistent interpretation of http requests ('http request smuggling') vulnerability in Fortinet FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4.3 through 6.4.16 may allow an unauthenticated atta 0,4%
CVE-2025-54988 HIGH 8.4 apache tika Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through and including 3.2.1 on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF. An attacker may be able to read sensitiv 15,0%
CVE-2025-54981 HIGH 7.5 apache streampark Weak Encryption Algorithm in StreamPark, The use of an AES cipher in ECB mode and a weak random number generator for encrypting sensitive data, including JWT tokens, may have risked exposing sensitive authentication data This issue affects Apache StreamPark: 0,2%
CVE-2025-54973 MED 5.3 fortinet fortianalyzer A concurrent execution using shared resource with improper synchronization ('Race Condition') vulnerability [CWE-362] in Fortinet FortiAnalyzer version 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10 and before 7.0.13 allows an attacker to attem 0,3%
CVE-2025-54972 MED 4.3 fortinet fortimail An improper neutralization of crlf sequences ('crlf injection') vulnerability in Fortinet FortiMail 7.6.0 through 7.6.3, FortiMail 7.4.0 through 7.4.5, FortiMail 7.2 all versions, FortiMail 7.0 all versions may allow an attacker to inject headers in the respon 0,2%
CVE-2025-54971 MED 4.3 fortinet fortiadc An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiADC 7.4.0, FortiADC 7.2 all versions, FortiADC 7.1 all versions, FortiADC 7.0 all versions, FortiADC 6.2 all versions may allow an admin with read-only permission to 0,2%
CVE-2025-54947 CRIT 9.8 apache streampark In Apache StreamPark versions 2.0.0 through 2.1.7, a security vulnerability involving a hard-coded encryption key exists. This vulnerability occurs because the system uses a fixed, immutable key for encryption instead of dynamically generating or securely conf 0,5%
CVE-2025-54941 MED 4.6 apache airflow An example dag `example_dag_decorator` had non-validated parameter that allowed the UI user to redirect the example to a malicious server and execute code on worker. This however required that the example dags are enabled in production (not default) or the exa 0,5%
CVE-2025-54920 HIGH 8.8 apache spark This issue affects Apache Spark: before 3.5.7 and 4.0.1. Users are recommended to upgrade to version 3.5.7 or 4.0.1 and above, which fixes the issue. Summary Apache Spark 3.5.4 and earlier versions contain a code execution vulnerability in the Spark Hist 5,3%
CVE-2025-54919 HIGH 7.5 microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to execute code locally. 0,4%
CVE-2025-54918 HIGH 8.8 microsoft windows_10_1507 Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network. 19,4%
CVE-2025-54917 MED 4.3 microsoft windows_10_1507 Protection mechanism failure in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network. 0,9%
CVE-2025-54916 HIGH 7.8 microsoft windows_10_1507 Stack-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. 2,3%
CVE-2025-54915 MED 6.7 microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally. 0,5%
CVE-2025-54914 CRIT 10.0 microsoft azure_networking Azure Networking Elevation of Privilege Vulnerability 2,4%
CVE-2025-54913 HIGH 7.8 microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows UI XAML Maps MapControlSettings allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2025-54912 HIGH 7.8 microsoft windows_10_1507 Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally. 0,5%
CVE-2025-54911 HIGH 7.3 microsoft windows_10_1507 Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally. 0,6%
CVE-2025-54910 HIGH 8.4 microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. 0,6%
CVE-2025-54908 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. 0,6%
CVE-2025-54907 HIGH 7.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office Visio allows an unauthorized attacker to execute code locally. 0,5%
CVE-2025-54906 HIGH 7.8 microsoft 365_apps Free of memory not on the heap in Microsoft Office allows an unauthorized attacker to execute code locally. 0,7%
CVE-2025-54905 HIGH 7.1 microsoft 365_apps Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to disclose information locally. 0,6%
CVE-2025-54904 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0,6%