56.855 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.855 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2025-48809 | MED 5.5 | microsoft windows_11_24h2 Processor optimization removal or modification of security-critical code in Windows Kernel allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2025-48808 | MED 5.5 | microsoft windows_10_1507 Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally. | 0,5% | — |
| CVE-2025-48807 | MED 6.7 | microsoft windows_10_1607 Improper restriction of communication channel to intended endpoints in Windows Hyper-V allows an authorized attacker to execute code locally. | 0,5% | — |
| CVE-2025-48806 | HIGH 7.8 | microsoft windows_10_1507 Use after free in Microsoft MPEG-2 Video Extension allows an authorized attacker to execute code locally. | 0,4% | — |
| CVE-2025-48805 | HIGH 7.8 | microsoft windows_10_1507 Heap-based buffer overflow in Microsoft MPEG-2 Video Extension allows an authorized attacker to execute code locally. | 0,4% | — |
| CVE-2025-48804 | MED 6.8 | microsoft windows_10_1507 Acceptance of extraneous untrusted data with trusted data in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. | 0,6% | — |
| CVE-2025-48803 | MED 6.7 | microsoft windows_10_1507 Missing support for integrity check in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2025-48802 | MED 6.5 | microsoft windows_11_22h2 Improper certificate validation in Windows SMB allows an authorized attacker to perform spoofing over a network. | 0,8% | — |
| CVE-2025-48800 | MED 6.8 | microsoft windows_10_1507 Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. | 0,6% | — |
| CVE-2025-48799 | HIGH 7.8 | microsoft windows_10_1607 Improper link resolution before file access ('link following') in Windows Update Service allows an authorized attacker to elevate privileges locally. | 1,0% | — |
| CVE-2025-48795 | MED 5.6 | apache cxf Apache CXF stores large stream based messages as temporary files on the local filesystem. A bug was introduced which means that the entire temporary file is read into memory and then logged. An attacker might be able to exploit this to cause a denial of servic | 0,7% | — |
| CVE-2025-4879 | HIGH 7.8 | citrix workspace Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows | 0,1% | — |
| CVE-2025-48769 | HIGH 8.1 | apache nuttx Use After Free vulnerability was discovered in fs/vfs/fs_rename code of the Apache NuttX RTOS, that due recursive implementation and single buffer use by two different pointer variables allowed arbitrary user provided size buffer reallocation and write to the | 1,5% | — |
| CVE-2025-48768 | MED 6.5 | apache nuttx Release of Invalid Pointer or Reference vulnerability was discovered in fs/inode/fs_inoderemove code of the Apache NuttX RTOS that allowed root filesystem inode removal leading to a debug assert trigger (that is disabled by default), NULL pointer dereference ( | 0,8% | — |
| CVE-2025-48734 | HIGH 8.8 | apache commons_beanutils Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However th | 1,7% | — |
| CVE-2025-48500 | HIGH 7.3 | f5 big-ip_access_policy_manager A missing file integrity check vulnerability exists on MacOS F5 VPN browser client installer that may allow a local, authenticated attacker with access to the local file system to replace it with a malicious package installer. Note: Software versions which ha | 0,1% | — |
| CVE-2025-48459 | MED 5.3 | apache iotdb Deserialization of Untrusted Data vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 2.0.5. Users are recommended to upgrade to version 2.0.5, which fixes the issue. | 0,5% | — |
| CVE-2025-48431 | HIGH 7.5 | apache thrift Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. Description: Specially crafted request | 1,1% | — |
| CVE-2025-48418 | MED 6.7 | fortinet fortianalyzer A hidden functionality vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2.0 through 7.2.10, FortiAnalyzer 7.0.0 through 7.0.14, FortiAnalyzer 6.4 all versions, FortiAnalyzer Cloud 7.6.2, FortiAnaly | 0,5% | — |
| CVE-2025-48392 | HIGH 7.5 | apache iotdb A vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.3.3 through 1.3.4, from 2.0.1-beta through 2.0.4. Users are recommended to upgrade to version 2.0.5, which fixes the issue. | 0,6% | — |
| CVE-2025-48208 | HIGH 8.8 | apache hertzbeat Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache HertzBeat . The attacker needs to have an authenticated account with access, and the attack can only be triggered by crafting custom comman | 0,6% | — |
| CVE-2025-48008 | HIGH 7.5 | f5 big-ip_access_policy_manager When a TCP profile with Multipath TCP (MPTCP) enabled is configured on a virtual server, undisclosed traffic along with conditions beyond the attacker's control can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which hav | 0,4% | — |
| CVE-2025-48004 | HIGH 7.4 | microsoft windows_11_22h2 Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally. | 1,8% | — |
| CVE-2025-48003 | MED 6.8 | microsoft windows_10_1809 Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. | 0,6% | — |
| CVE-2025-48002 | MED 5.7 | microsoft windows_11_24h2 Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to disclose information over an adjacent network. | 0,6% | — |