56.959 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.959 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2025-30640 | HIGH 7.8 | trendmicro deep_security_agent A link following vulnerability in Trend Micro Deep Security 20.0 agents could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system | 0,2% | — |
| CVE-2025-30474 | MED 5.0 | apache commons_vfs Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Commons VFS. The FtpFileObject class can throw an exception when a file is not found, revealing the original URI in its message, which may include a password. The fix is to mas | 0,9% | — |
| CVE-2025-30473 | HIGH 8.8 | apache airflow_common_sql_provider Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow Common SQL Provider. When using the partition clause in SQLTableCheckOperator as parameter (which was a recommended pattern), Authenticated UI | 0,9% | — |
| CVE-2025-30416 | CRIT 10.0 | acronis cyber_protect Sensitive data disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis Cyber Protect 15 (Linux, Windows) before build 41800. | 0,5% | — |
| CVE-2025-30413 | MED 4.4 | acronis agent Credentials are not deleted from Acronis Agent after plan revocation. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 40497, Acronis Cyber Protect 17 (Linux, macOS, Windows) before build 41186. | 0,2% | — |
| CVE-2025-30412 | CRIT 10.0 | acronis cyber_protect Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis Cyber Protect 15 (Linux, Windows) before build 41800. | 0,6% | — |
| CVE-2025-30411 | CRIT 10.0 | acronis cyber_protect Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis Cyber Protect 15 (Linux, Windows) before build 41800. | 0,7% | — |
| CVE-2025-30399 | HIGH 7.5 | microsoft .net Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network. | 0,9% | — |
| CVE-2025-30398 | HIGH 8.1 | microsoft nuance_powerscribe_360 Missing authorization in Nuance PowerScribe allows an unauthorized attacker to disclose information over a network. | 0,8% | — |
| CVE-2025-30394 | MED 5.9 | microsoft windows_server_2012 Sensitive data storage in improperly locked memory in Remote Desktop Gateway Service allows an unauthorized attacker to deny service over a network. | 30,5% | — |
| CVE-2025-30393 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2025-30392 | CRIT 9.8 | microsoft azure_ai_bot_service Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network. | 1,0% | — |
| CVE-2025-30391 | HIGH 8.1 | microsoft dynamics_365_customer_service Improper input validation in Microsoft Dynamics allows an unauthorized attacker to disclose information over a network. | 1,3% | — |
| CVE-2025-30390 | CRIT 9.9 | microsoft azure_machine_learning Improper authorization in Azure allows an authorized attacker to elevate privileges over a network. | 0,9% | — |
| CVE-2025-30389 | HIGH 8.7 | microsoft azure_ai_bot_service Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network. | 0,8% | — |
| CVE-2025-30388 | HIGH 7.8 | microsoft 365_copilot Heap-based buffer overflow in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally. | 3,9% | — |
| CVE-2025-30387 | CRIT 9.8 | microsoft azure_ai_document_intelligence_studio Improper limitation of a pathname to a restricted directory ('path traversal') in Azure allows an unauthorized attacker to elevate privileges over a network. | 1,2% | — |
| CVE-2025-30386 | HIGH 8.4 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 0,7% | — |
| CVE-2025-30385 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | 0,5% | — |
| CVE-2025-30384 | HIGH 7.4 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally. | 1,3% | — |
| CVE-2025-30383 | HIGH 7.8 | microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0,5% | — |
| CVE-2025-30382 | HIGH 7.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally. | 2,5% | — |
| CVE-2025-30381 | HIGH 7.8 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0,5% | — |
| CVE-2025-30379 | HIGH 7.8 | microsoft 365_apps Release of invalid pointer or reference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0,5% | — |
| CVE-2025-30378 | HIGH 7.0 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally. | 1,4% | — |