56.855 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.855 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2025-50163 | HIGH 8.8 | microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | 0,9% | — |
| CVE-2025-50162 | HIGH 8.0 | microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. | 0,8% | — |
| CVE-2025-50161 | HIGH 7.3 | microsoft windows_10_1507 Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | 0,6% | — |
| CVE-2025-50160 | HIGH 8.0 | microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. | 0,8% | — |
| CVE-2025-50159 | HIGH 7.3 | microsoft windows_10_1507 Use after free in Remote Access Point-to-Point Protocol (PPP) EAP-TLS allows an authorized attacker to elevate privileges locally. | 0,6% | — |
| CVE-2025-50158 | HIGH 7.0 | microsoft windows_10_1507 Time-of-check time-of-use (toctou) race condition in Windows NTFS allows an unauthorized attacker to disclose information locally. | 0,4% | — |
| CVE-2025-50157 | MED 5.7 | microsoft windows_server_2008 Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network. | 1,1% | — |
| CVE-2025-50156 | MED 5.7 | microsoft windows_server_2008 Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network. | 1,1% | — |
| CVE-2025-50155 | HIGH 7.8 | microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-50154 | MED 6.5 | microsoft windows_10_1507 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network. | 25,6% | — |
| CVE-2025-50153 | HIGH 7.8 | microsoft windows_10_1507 Use after free in Desktop Windows Manager allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-50152 | HIGH 7.8 | microsoft windows_10_1507 Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-50151 | HIGH 8.8 | apache jena File access paths in configuration files uploaded by users with administrator access are not validated. This issue affects Apache Jena version up to 5.4.0. Users are recommended to upgrade to version 5.5.0, which does not allow arbitrary configuration upload | 1,0% | — |
| CVE-2025-49813 | HIGH 7.2 | fortinet fortiadc An improper neutralization of special elements used in an OS Command ("OS Command Injection") vulnerability [CWE-78] in Fortinet FortiADC version 7.2.0 and before 7.1.1 allows a remote and authenticated attacker with low privilege to execute unauthorized code | 1,1% | — |
| CVE-2025-49812 | HIGH 7.4 | apache http_server In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows a man-in-the-middle attacker to hijack an HTTP session via a TLS upgrade. Only configurations using "SSLEngine optional" to enable TLS upg | 0,5% | — |
| CVE-2025-49784 | MED 6.0 | fortinet fortianalyzer An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyze | 0,4% | — |
| CVE-2025-49763 | HIGH 7.5 | apache traffic_server ESI plugin does not have the limit for maximum inclusion depth, and that allows excessive memory consumption if malicious instructions are inserted. Users can use a new setting for the plugin (--max-inclusion-depth) to limit it. This issue affects Apache Traf | 0,7% | — |
| CVE-2025-49762 | HIGH 7.0 | microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2025-49761 | HIGH 7.8 | microsoft windows_10_1507 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-49760 | LOW 3.5 | microsoft windows_10_1507 External control of file name or path in Windows Storage allows an authorized attacker to perform spoofing over a network. | 1,3% | — |
| CVE-2025-49759 | HIGH 8.8 | microsoft sql_server_2016 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | 1,1% | — |
| CVE-2025-49758 | HIGH 8.8 | microsoft sql_server_2016 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | 0,9% | — |
| CVE-2025-49757 | HIGH 8.8 | microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | 1,0% | — |
| CVE-2025-49756 | LOW 3.3 | microsoft 365_apps Use of a broken or risky cryptographic algorithm in Office Developer Platform allows an authorized attacker to bypass a security feature locally. | 0,2% | — |
| CVE-2025-49755 | MED 4.3 | microsoft edge User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network. | 0,5% | — |