EN
56.855 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia

CVE Tracker

56.855 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordinato dal più alto
CVE-2025-47733 CRIT 9.1 microsoft power_apps Server-Side Request Forgery (SSRF) in Microsoft Power Apps allows an unauthorized attacker to disclose information over a network 1,8%
CVE-2025-47732 HIGH 8.7 microsoft dataverse Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network. 3,5%
CVE-2025-47713 HIGH 8.8 apache cloudstack A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Domain Admin user in the ROOT domain can reset the password of user-accounts of Admin role type. This operation is not appropriately restricte 0,5%
CVE-2025-47436 CRIT 9.8 apache orc Heap-based Buffer Overflow vulnerability in Apache ORC. A vulnerability has been identified in the ORC C++ LZO decompression logic, where specially crafted malformed ORC files can cause the decompressor to allocate a 250-byte buffer but then attempts to copy 0,5%
CVE-2025-47411 HIGH 8.1 apache streampipes A user with a legitimate non-administrator account can exploit a vulnerability in the user ID creation mechanism in Apache StreamPipes that allows them to swap the username of an existing user with that of an administrator.  This vulnerability allows an attac 15,0%
CVE-2025-47410 HIGH 8.8 apache geode Apache Geode is vulnerable to CSRF attacks through GET requests to the Management and Monitoring REST API that could allow an attacker who has tricked a user into giving up their Geode session credentials to submit malicious commands on the target system on be 0,3%
CVE-2025-47295 LOW 3.7 fortinet fortios A buffer over-read in Fortinet FortiOS versions 7.4.0 through 7.4.3, versions 7.2.0 through 7.2.7, and versions 7.0.0 through 7.0.14 may allow a remote unauthenticated attacker to crash the FGFM daemon via a specially crafted request, under rare conditions tha 0,7%
CVE-2025-47294 MED 5.3 fortinet fortios A integer overflow or wraparound in Fortinet FortiOS versions 7.2.0 through 7.2.7, versions 7.0.0 through 7.0.14 may allow a remote unauthenticated attacker to crash the csfd daemon via a specially crafted request. 0,8%
CVE-2025-47182 MED 5.6 microsoft edge_chromium Improper input validation in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally. 0,3%
CVE-2025-47181 HIGH 8.8 microsoft edge_update Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally. 0,6%
CVE-2025-47179 MED 6.7 microsoft configuration_manager_2403 Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges locally. 0,3%
CVE-2025-47178 HIGH 8.0 microsoft configuration_manager_2503 Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an authorized attacker to execute code over an adjacent network. 2,9%
CVE-2025-47176 HIGH 7.8 microsoft 365_apps '.../...//' in Microsoft Office Outlook allows an authorized attacker to execute code locally. 0,7%
CVE-2025-47175 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. 2,2%
CVE-2025-47174 HIGH 7.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0,5%
CVE-2025-47173 HIGH 7.8 microsoft 365_apps Improper input validation in Microsoft Office allows an unauthorized attacker to execute code locally. 0,5%
CVE-2025-47172 HIGH 8.8 microsoft sharepoint_enterprise_server Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 1,6%
CVE-2025-47171 MED 6.7 microsoft 365_apps Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally. 1,5%
CVE-2025-47170 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0,6%
CVE-2025-47169 HIGH 7.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0,6%
CVE-2025-47168 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0,6%
CVE-2025-47167 HIGH 8.4 microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. 0,6%
CVE-2025-47166 HIGH 8.8 microsoft sharepoint_enterprise_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 15,2%
CVE-2025-47165 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 2,0%
CVE-2025-47164 HIGH 8.4 microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 0,6%