56.960 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.960 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2025-14596 | MED 6.7 | intel quartus_prime Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Pro Installer (SFX) on Windows allows Search Order Hijacking.This issue affects Quartus Prime Pro: from 24.1 through 24.3.1. | 0,1% | — |
| CVE-2025-14373 | MED 4.3 | google chrome Inappropriate implementation in Toolbar in Google Chrome on Android prior to 143.0.7499.110 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium) | 0,3% | — |
| CVE-2025-14372 | MED 6.1 | google chrome Use after free in Password Manager in Google Chrome prior to 143.0.7499.110 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) | 0,2% | — |
| CVE-2025-13995 | MED 5.0 | ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 could allow an attacker with access to one tenant to access hostname data from another tenant's account. | 0,2% | — |
| CVE-2025-13992 | MED 4.7 | google chrome Side-channel information leakage in Navigation and Loading in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium) | 0,2% | — |
| CVE-2025-13941 | HIGH 8.8 | foxit pdf_editor A local privilege escalation vulnerability exists in the Foxit PDF Reader/Editor Update Service. During plugin installation, incorrect file system permissions are assigned to resources used by the update service. A local attacker with low privileges could modi | 0,2% | — |
| CVE-2025-13916 | MED 5.9 | ibm aspera_shares IBM Aspera Shares 1.9.9 through 1.11.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information | 0,2% | — |
| CVE-2025-13914 | HIGH 8.7 | juniper apstra A Key Exchange without Entity Authentication vulnerability in the SSH implementation of Juniper Networks Apstra allows a unauthenticated, MITM attacker to impersonate managed devices. Due to insufficient SSH host key validation an attacker can perform a mac | 0,3% | — |
| CVE-2025-13855 | HIGH 7.6 | ibm storage_protect_server IBM Storage Protect Server 8.2.0 IBM Storage Protect Plus Server is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. | 0,3% | — |
| CVE-2025-13751 | MED 5.5 | openvpn openvpn Interactive service agent in OpenVPN version 2.5.0 through 2.6.16 and 2.7_alpha1 through 2.7_rc2 on Windows allows a local authenticated user to connect to the service and trigger an error causing a local denial of service. | 0,2% | — |
| CVE-2025-13726 | MED 5.3 | ibm sterling_partner_engagement_manager IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow a remote attacker to obtain sensitive information when detailed technical error messages are returned. This information could be used in further attacks aga | 0,3% | — |
| CVE-2025-13723 | MED 5.3 | ibm sterling_partner_engagement_manager IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow an attacker to obtain sensitive user information using an expired access token | 0,2% | — |
| CVE-2025-13721 | HIGH 7.5 | google chrome Race in v8 in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) | 0,2% | — |
| CVE-2025-13720 | HIGH 8.8 | google chrome Bad cast in Loader in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) | 0,3% | — |
| CVE-2025-13718 | LOW 3.7 | ibm sterling_partner_engagement_manager IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow a remote attacker to obtain sensitive information in cleartext in a communication channel that can be sniffed by unauthorized actors. | 0,2% | — |
| CVE-2025-13702 | MED 6.1 | ibm sterling_partner_engagement_manager IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended funct | 0,2% | — |
| CVE-2025-13670 | MED 6.7 | intel high_level_synthesis_compiler The High Level Synthesis Compiler i++ command for Windows is vulnerable to a DLL planting vulnerability | 0,1% | — |
| CVE-2025-13669 | MED 6.7 | intel high_level_synthesis_compiler Uncontrolled Search Path Element vulnerability in Altera High Level Synthesis Compiler on Windows allows Search Order Hijacking.This issue affects High Level Synthesis Compiler: from 19.1 through 24.3. | 0,1% | — |
| CVE-2025-13668 | MED 6.7 | intel quartus_prime A potential security vulnerability in Quartus® Prime Pro Edition Design Software may allow escalation of privilege. | 0,1% | — |
| CVE-2025-13665 | MED 6.7 | intel quartus_prime The System Console Utility for Windows is vulnerable to a DLL planting vulnerability | 0,1% | — |
| CVE-2025-13664 | MED 6.7 | intel quartus_prime A potential security vulnerability in Quartus® Prime Standard Edition Design Software may allow escalation of privilege. | 0,1% | — |
| CVE-2025-13663 | MED 6.7 | intel quartus_prime Under certain circumstances, the Quartus Prime Pro Installer for Windows does not check the permissions of the Quartus target installation directory if the target installation directory already exists. | 0,1% | — |
| CVE-2025-13640 | LOW 3.5 | google chrome Inappropriate implementation in Passwords in Google Chrome prior to 143.0.7499.41 allowed a local attacker to bypass authentication via physical access to the device. (Chromium security severity: Low) | 0,2% | — |
| CVE-2025-13639 | HIGH 8.1 | google chrome Inappropriate implementation in WebRTC in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Low) | 0,3% | — |
| CVE-2025-13638 | HIGH 8.8 | google chrome Use after free in Media Stream in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low) | 0,3% | — |