56.855 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.855 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2025-53784 | HIGH 8.4 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0,5% | — |
| CVE-2025-53783 | HIGH 7.5 | microsoft dynamics_365_guides Heap-based buffer overflow in Microsoft Teams allows an unauthorized attacker to execute code over a network. | 0,8% | — |
| CVE-2025-53782 | HIGH 8.4 | microsoft exchange_server Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2025-53781 | HIGH 7.7 | microsoft dcadsv5-series_azure_vm_firmware Exposure of sensitive information to an unauthorized actor in Azure Virtual Machines allows an authorized attacker to disclose information over a network. | 1,1% | — |
| CVE-2025-53779 | HIGH 7.2 | microsoft windows_server_2025 Relative path traversal in Windows Kerberos allows an authorized attacker to elevate privileges over a network. | 2,6% | — |
| CVE-2025-53778 | HIGH 8.8 | microsoft windows_10_1507 Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network. | 38,2% | — |
| CVE-2025-53774 | MED 6.5 | microsoft 365_copilot_chat Microsoft 365 Copilot BizChat Information Disclosure Vulnerability | 0,6% | — |
| CVE-2025-53773 | HIGH 7.8 | microsoft visual_studio_2022 Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to execute code locally. | 2,6% | — |
| CVE-2025-53772 | HIGH 8.8 | microsoft web_deploy_4.0 Deserialization of untrusted data in Web Deploy allows an authorized attacker to execute code over a network. | 22,4% | — |
| CVE-2025-53771 | MED 6.5 | microsoft sharepoint_server Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | 99,9% | — |
| CVE-2025-53769 | MED 5.5 | microsoft windows_security_app External control of file name or path in Windows Security App allows an authorized attacker to perform spoofing locally. | 0,4% | — |
| CVE-2025-53768 | HIGH 7.8 | microsoft windows_10_1507 Use after free in Xbox allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2025-53767 | CRIT 10.0 | microsoft azure_openai Azure OpenAI Elevation of Privilege Vulnerability | 1,1% | — |
| CVE-2025-53766 | CRIT 9.8 | microsoft 365_copilot Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network. | 7,1% | — |
| CVE-2025-53765 | MED 4.4 | microsoft azure_app_service_on_azure_stack Exposure of private personal information to an unauthorized actor in Azure Stack allows an authorized attacker to disclose information locally. | 0,5% | — |
| CVE-2025-53763 | CRIT 9.8 | microsoft purview_data_governance Improper access control in Azure Databricks allows an unauthorized attacker to elevate privileges over a network. | 0,7% | — |
| CVE-2025-53762 | HIGH 8.7 | microsoft purview Permissive list of allowed inputs in Microsoft Purview allows an authorized attacker to elevate privileges over a network. | 0,7% | — |
| CVE-2025-53761 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. | 0,5% | — |
| CVE-2025-53760 | HIGH 7.1 | microsoft sharepoint_server Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | 11,9% | — |
| CVE-2025-53759 | HIGH 7.8 | microsoft 365_apps Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0,5% | — |
| CVE-2025-53744 | HIGH 7.2 | fortinet fortios An incorrect privilege assignment vulnerability [CWE-266] in FortiOS Security Fabric version 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2 all versions, 7.0 all versions, 6.4 all versions, may allow a remote authenticated attacker with high privileges to escal | 0,6% | — |
| CVE-2025-53741 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0,5% | — |
| CVE-2025-53740 | HIGH 8.4 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 0,5% | — |
| CVE-2025-53739 | HIGH 7.8 | microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0,6% | — |
| CVE-2025-53738 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0,5% | — |