EN
56.959 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia

CVE Tracker

56.959 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordinato dal più basso
CVE-2025-25003 HIGH 7.3 microsoft visual_studio_2019 Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally. 0,4%
CVE-2025-25002 MED 6.8 microsoft azure_local_cluster Insertion of sensitive information into log file in Azure Local Cluster allows an authorized attacker to disclose information over an adjacent network. 1,0%
CVE-2025-25001 MED 4.3 microsoft edge Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. 0,7%
CVE-2025-25000 HIGH 8.8 microsoft edge_chromium Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. 0,9%
CVE-2025-24999 HIGH 8.8 microsoft sql_server_2016 Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network. 1,6%
CVE-2025-24998 HIGH 7.3 microsoft visual_studio_2017 Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally. 0,4%
CVE-2025-24997 MED 4.4 microsoft windows_10_21h2 Null pointer dereference in Windows Kernel Memory allows an authorized attacker to deny service locally. 0,6%
CVE-2025-24996 MED 6.5 microsoft windows_10_1507 External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. 1,3%
CVE-2025-24995 HIGH 7.8 microsoft windows_10_1507 Heap-based buffer overflow in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally. 0,6%
CVE-2025-24994 HIGH 7.3 microsoft windows_11_22h2 Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally. 1,2%
CVE-2025-24992 MED 5.5 microsoft windows_10_1507 Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally. 1,0%
CVE-2025-24988 MED 6.6 microsoft windows_10_1507 Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack. 0,7%
CVE-2025-24987 MED 6.6 microsoft windows_10_1507 Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack. 0,7%
CVE-2025-24986 MED 6.5 microsoft azure_promptflow_core Improper isolation or compartmentalization in Azure PromptFlow allows an unauthorized attacker to execute code over a network. 0,5%
CVE-2025-24917 HIGH 7.8 tenable nessus_network_monitor In Tenable Network Monitor versions prior to 6.5.1 on a Windows host, it was found that a non-administrative user could stage files in a local directory to run arbitrary code with SYSTEM privileges, potentially leading to local privilege escalation. 0,2%
CVE-2025-24916 HIGH 7.0 tenable nessus_network_monitor When installing Tenable Network Monitor to a non-default location on a Windows host, Tenable Network Monitor versions prior to 6.5.1 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secure 0,1%
CVE-2025-24860 MED 5.4 apache cassandra Incorrect Authorization vulnerability in Apache Cassandra allowing users to access a datacenter or IP/CIDR groups they should not be able to when using CassandraNetworkAuthorizer or CassandraCIDRAuthorizer. Users with restricted data center access can update 1,1%
CVE-2025-24859 HIGH 8.8 apache roller A session management vulnerability exists in Apache Roller before version 6.1.5 where active user sessions are not properly invalidated after password changes. When a user's password is changed, either by the user themselves or by an administrator, existing se 1,1%
CVE-2025-24854 MED 6.1 apache jspwiki A carefully crafted request using the Image plugin could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki us 0,4%
CVE-2025-24853 HIGH 7.5 apache jspwiki A carefully crafted request when creating a header link using the wiki markup syntax, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Further research by the JSPWiki team s 0,5%
CVE-2025-24814 MED 5.5 apache solr Core creation allows users to replace "trusted" configset files with arbitrary configuration Solr instances that (1) use the "FileSystemConfigSetService" component (the default in "standalone" or "user-managed" mode), and (2) are running without authenticatio 1,2%
CVE-2025-24795 MED 4.4 snowflake snowflake_connector The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. On Linux s 0,1%
CVE-2025-24791 MED 4.4 snowflake snowflake_connector snowflake-connector-nodejs is a NodeJS driver for Snowflake. Snowflake discovered and remediated a vulnerability in the Snowflake NodeJS Driver. File permissions checks of the temporary credential cache could be bypassed by an attacker with write access to the 0,1%
CVE-2025-24790 MED 4.4 snowflake snowflake_jdbc Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connect to Snowflake. Snowflake discovered and remediated a vulnerability in the Snowflake JDBC Driver. On Linux systems, when temporary credential caching 0,2%
CVE-2025-24789 HIGH 7.8 snowflake snowflake_jdbc Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connect to Snowflake. Snowflake discovered and remediated a vulnerability in the Snowflake JDBC Driver. When the EXTERNALBROWSER authentication method is us 0,3%