57.044 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.044 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più basso | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2025-62468 | MED 5.5 | microsoft windows_11_23h2 Out-of-bounds read in Windows Defender Firewall Service allows an authorized attacker to disclose information locally. | 0,5% | — |
| CVE-2025-62224 | MED 5.5 | microsoft edge User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an authorized attacker to perform spoofing over a network. | 0,3% | — |
| CVE-2025-62209 | MED 5.5 | microsoft windows_10_1507 Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally. | 0,5% | — |
| CVE-2025-62208 | MED 5.5 | microsoft windows_10_1507 Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally. | 0,5% | — |
| CVE-2025-60706 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Hyper-V allows an authorized attacker to disclose information locally. | 0,5% | — |
| CVE-2025-60007 | MED 5.5 | juniper junos A NULL Pointer Dereference vulnerability in the chassis daemon (chassisd) of Juniper Networks Junos OS on MX, SRX and EX Series allows a local attacker with low privileges to cause a Denial-of-Service (DoS). When a user executes the 'show chassis' command wi | 0,1% | — |
| CVE-2025-59961 | MED 5.5 | juniper junos An Incorrect Permission Assignment for Critical Resource vulnerability in the Juniper DHCP daemon (jdhcpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged user to write to the Unix socket used to manage the jdhcpd process, resu | 0,1% | — |
| CVE-2025-59959 | MED 5.5 | juniper junos An Untrusted Pointer Dereference vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with low privileges to cause a Denial-of-Service (DoS). When the command 'show route < | 0,1% | — |
| CVE-2025-59513 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to disclose information locally. | 0,5% | — |
| CVE-2025-59510 | MED 5.5 | microsoft windows_10_1607 Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to deny service locally. | 0,5% | — |
| CVE-2025-59509 | MED 5.5 | microsoft windows_10_1809 Insertion of sensitive information into sent data in Windows Speech allows an authorized attacker to disclose information locally. | 0,6% | — |
| CVE-2025-59260 | MED 5.5 | microsoft windows_server_2016 Exposure of sensitive information to an unauthorized actor in Microsoft Failover Cluster Virtual Driver allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2025-59253 | MED 5.5 | microsoft windows_10_1507 Improper access control in Microsoft Windows Search Component allows an authorized attacker to deny service locally. | 0,3% | — |
| CVE-2025-59240 | MED 5.5 | microsoft 365_apps Exposure of sensitive information to an unauthorized actor in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | 0,6% | — |
| CVE-2025-59229 | MED 5.5 | microsoft 365_apps Uncaught exception in Microsoft Office allows an unauthorized attacker to deny service locally. | 0,4% | — |
| CVE-2025-59211 | MED 5.5 | microsoft windows_10_1507 Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disclose information locally. | 0,6% | — |
| CVE-2025-59209 | MED 5.5 | microsoft windows_10_1507 Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2025-59204 | MED 5.5 | microsoft windows_10_1809 Use of uninitialized resource in Windows Management Services allows an authorized attacker to disclose information locally. | 0,5% | — |
| CVE-2025-59203 | MED 5.5 | microsoft windows_10_1507 Insertion of sensitive information into log file in Windows StateRepository API allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2025-59197 | MED 5.5 | microsoft windows_10_1507 Insertion of sensitive information into log file in Windows ETL Channel allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2025-59190 | MED 5.5 | microsoft windows_10_1507 Improper input validation in Microsoft Windows Search Component allows an unauthorized attacker to deny service locally. | 0,5% | — |
| CVE-2025-59188 | MED 5.5 | microsoft windows_server_2012 Exposure of sensitive information to an unauthorized actor in Windows Failover Cluster allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2025-59186 | MED 5.5 | microsoft windows_server_2016 Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally. | 0,6% | — |
| CVE-2025-59184 | MED 5.5 | microsoft windows_server_2016 Exposure of sensitive information to an unauthorized actor in Windows High Availability Services allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2025-58740 | MED 5.5 | milner imagedirector_capture The use of a hard-coded encryption key in calls to the Password function in C2SGlobalSettings.dll in Milner ImageDirector Capture on Windows allows a local attacker to decrypt database credentials by reading the cryptographic key from the executable. This iss | 0,1% | — |