EN
56.960 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia

CVE Tracker

56.960 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordinato dal più alto
CVE-2025-14596 MED 6.7 intel quartus_prime Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Pro Installer (SFX) on Windows allows Search Order Hijacking.This issue affects Quartus Prime Pro: from 24.1 through 24.3.1. 0,1%
CVE-2025-14373 MED 4.3 google chrome Inappropriate implementation in Toolbar in Google Chrome on Android prior to 143.0.7499.110 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium) 0,3%
CVE-2025-14372 MED 6.1 google chrome Use after free in Password Manager in Google Chrome prior to 143.0.7499.110 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) 0,2%
CVE-2025-13995 MED 5.0 ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 could allow an attacker with access to one tenant to access hostname data from another tenant's account. 0,2%
CVE-2025-13992 MED 4.7 google chrome Side-channel information leakage in Navigation and Loading in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium) 0,2%
CVE-2025-13941 HIGH 8.8 foxit pdf_editor A local privilege escalation vulnerability exists in the Foxit PDF Reader/Editor Update Service. During plugin installation, incorrect file system permissions are assigned to resources used by the update service. A local attacker with low privileges could modi 0,2%
CVE-2025-13916 MED 5.9 ibm aspera_shares IBM Aspera Shares 1.9.9 through 1.11.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information 0,2%
CVE-2025-13914 HIGH 8.7 juniper apstra A Key Exchange without Entity Authentication vulnerability in the SSH implementation of Juniper Networks Apstra allows a unauthenticated, MITM attacker to impersonate managed devices. Due to insufficient SSH host key validation an attacker can perform a mac 0,3%
CVE-2025-13855 HIGH 7.6 ibm storage_protect_server IBM Storage Protect Server 8.2.0 IBM Storage Protect Plus Server is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. 0,3%
CVE-2025-13751 MED 5.5 openvpn openvpn Interactive service agent in OpenVPN version 2.5.0 through 2.6.16 and 2.7_alpha1 through 2.7_rc2 on Windows allows a local authenticated user to connect to the service and trigger an error causing a local denial of service. 0,2%
CVE-2025-13726 MED 5.3 ibm sterling_partner_engagement_manager IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow a remote attacker to obtain sensitive information when detailed technical error messages are returned. This information could be used in further attacks aga 0,3%
CVE-2025-13723 MED 5.3 ibm sterling_partner_engagement_manager IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow an attacker to obtain sensitive user information using an expired access token 0,2%
CVE-2025-13721 HIGH 7.5 google chrome Race in v8 in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) 0,2%
CVE-2025-13720 HIGH 8.8 google chrome Bad cast in Loader in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) 0,3%
CVE-2025-13718 LOW 3.7 ibm sterling_partner_engagement_manager IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow a remote attacker to obtain sensitive information in cleartext in a communication channel that can be sniffed by unauthorized actors. 0,2%
CVE-2025-13702 MED 6.1 ibm sterling_partner_engagement_manager IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended funct 0,2%
CVE-2025-13670 MED 6.7 intel high_level_synthesis_compiler The High Level Synthesis Compiler i++ command for Windows is vulnerable to a DLL planting vulnerability 0,1%
CVE-2025-13669 MED 6.7 intel high_level_synthesis_compiler Uncontrolled Search Path Element vulnerability in Altera High Level Synthesis Compiler on Windows allows Search Order Hijacking.This issue affects High Level Synthesis Compiler: from 19.1 through 24.3. 0,1%
CVE-2025-13668 MED 6.7 intel quartus_prime A potential security vulnerability in Quartus® Prime Pro Edition Design Software may allow escalation of privilege. 0,1%
CVE-2025-13665 MED 6.7 intel quartus_prime The System Console Utility for Windows is vulnerable to a DLL planting vulnerability 0,1%
CVE-2025-13664 MED 6.7 intel quartus_prime A potential security vulnerability in Quartus® Prime Standard Edition Design Software may allow escalation of privilege. 0,1%
CVE-2025-13663 MED 6.7 intel quartus_prime Under certain circumstances, the Quartus Prime Pro Installer for Windows does not check the permissions of the Quartus target installation directory if the target installation directory already exists. 0,1%
CVE-2025-13640 LOW 3.5 google chrome Inappropriate implementation in Passwords in Google Chrome prior to 143.0.7499.41 allowed a local attacker to bypass authentication via physical access to the device. (Chromium security severity: Low) 0,2%
CVE-2025-13639 HIGH 8.1 google chrome Inappropriate implementation in WebRTC in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Low) 0,3%
CVE-2025-13638 HIGH 8.8 google chrome Use after free in Media Stream in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low) 0,3%