56.959 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.959 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2025-27746 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 0,8% | — |
| CVE-2025-27745 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 1,1% | — |
| CVE-2025-27744 | HIGH 7.8 | microsoft office Improper access control in Microsoft Office allows an authorized attacker to elevate privileges locally. | 1,1% | — |
| CVE-2025-27743 | HIGH 7.8 | microsoft system_center_data_protection_manager Untrusted search path in System Center allows an authorized attacker to elevate privileges locally. | 0,8% | — |
| CVE-2025-27742 | MED 5.5 | microsoft windows_10_1507 Out-of-bounds read in Windows NTFS allows an unauthorized attacker to disclose information locally. | 0,8% | — |
| CVE-2025-27741 | HIGH 7.8 | microsoft windows_10_1507 Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally. | 0,8% | — |
| CVE-2025-27740 | HIGH 8.8 | microsoft windows_server_2008 Weak authentication in Windows Active Directory Certificate Services allows an authorized attacker to elevate privileges over a network. | 3,3% | — |
| CVE-2025-27739 | HIGH 7.8 | microsoft windows_10_1809 Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0,6% | — |
| CVE-2025-27738 | MED 6.5 | microsoft windows_10_1507 Improper access control in Windows Resilient File System (ReFS) allows an authorized attacker to disclose information over a network. | 3,2% | — |
| CVE-2025-27737 | HIGH 8.6 | microsoft windows_10_1507 Improper input validation in Windows Security Zone Mapping allows an unauthorized attacker to bypass a security feature locally. | 0,7% | — |
| CVE-2025-27736 | MED 5.5 | microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Power Dependency Coordinator allows an authorized attacker to disclose information locally. | 0,8% | — |
| CVE-2025-27735 | MED 6.0 | microsoft windows_10_1507 Insufficient verification of data authenticity in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally. | 0,4% | — |
| CVE-2025-27733 | HIGH 7.8 | microsoft windows_10_1507 Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally. | 0,7% | — |
| CVE-2025-27732 | HIGH 7.0 | microsoft windows_10_1507 Sensitive data storage in improperly locked memory in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2025-27731 | HIGH 7.8 | microsoft windows_10_1809 Improper input validation in OpenSSH for Windows allows an authorized attacker to elevate privileges locally. | 0,6% | — |
| CVE-2025-27730 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. | 0,6% | — |
| CVE-2025-27729 | HIGH 7.8 | microsoft windows_10_21h2 Use after free in Windows Shell allows an unauthorized attacker to execute code locally. | 0,8% | — |
| CVE-2025-27728 | HIGH 7.8 | microsoft windows_11_24h2 Out-of-bounds read in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. | 0,6% | — |
| CVE-2025-27727 | HIGH 7.8 | microsoft windows_10_1507 Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to elevate privileges locally. | 0,9% | — |
| CVE-2025-27696 | HIGH 8.8 | apache superset Incorrect Authorization vulnerability in Apache Superset allows ownership takeover of dashboards, charts or datasets by authenticated users with read permissions. This issue affects Apache Superset: through 4.1.1. Users are recommended to upgrade to version | 1,2% | — |
| CVE-2025-27636 | MED 5.6 | apache camel Bypass/Injection vulnerability in Apache Camel components under particular conditions. This issue affects Apache Camel: from 4.10.0 through <= 4.10.1, from 4.8.0 through <= 4.8.4, from 3.10.0 through <= 3.22.3. Users are recommended to upgrade to version 4.1 | 80,9% | — |
| CVE-2025-27556 | MED 5.8 | djangoproject django An issue was discovered in Django 5.1 before 5.1.8 and 5.0 before 5.0.14. The NFKC normalization is slow on Windows. As a consequence, django.contrib.auth.views.LoginView, django.contrib.auth.views.LogoutView, and django.views.i18n.set_language are subject to | 1,0% | — |
| CVE-2025-27555 | MED 6.5 | apache airflow Airflow versions before 2.11.1 have a vulnerability that allows authenticated users with audit log access to see sensitive values in audit logs which they should not see. When sensitive connection parameters were set via airflow CLI, values of those variables | 0,4% | — |
| CVE-2025-27553 | HIGH 7.5 | apache commons_vfs Relative Path Traversal vulnerability in Apache Commons VFS before 2.10.0. The FileObject API in Commons VFS has a 'resolveFile' method that takes a 'scope' parameter. Specifying 'NameScope.DESCENDENT' promises that "an exception is thrown if the resolved fil | 1,4% | — |
| CVE-2025-27533 | HIGH 7.5 | apache activemq Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ. During unmarshalling of OpenWire commands the size value of buffers was not properly validated which could lead to excessive memory allocation and be exploited to cause a denial of | 8,6% | — |