Database CVE
Archivio delle vulnerabilità note (CVE) con punteggio CVSS, gravità, prodotti e vendor coinvolti. Filtra per anno e severità, collegato ai nostri articoli.
- CVE-2025-68461Alta7.2
Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.
- CVE-2025-43529Alta8.8
Un problema di use-after-free è stato risolto con una migliore gestione della memoria. Questo problema è corretto in Safari 26.2, iOS 18.7.3 e iPadOS 18.7.3, iOS 26.2 e iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. L'elaborazione di contenuti web creati in modo dannoso può portare all'esecuzione di codice arbitrario. Apple è a conoscenza di una segnalazione secondo cui questo problema potrebbe essere stato sfruttato in un attacco estremamente sofisticato contro specifici individui presi di mira su versioni di iOS precedenti a iOS 26. Il CVE-2025-14174 è stato emesso anche in risposta a questa segnalazione.
- CVE-2025-20393Critica10.0
A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to execute arbitrary system commands on an affected device with root privileges. This vulnerability is due to insufficient validation of HTTP requests by the Spam Quarantine feature. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with root privileges.
- CVE-2025-59374Critica9.8
"UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specific targeting conditions to perform unintended actions. Only devices that met these conditions and installed the compromised versions were affected. The Live Update client has already reached End-of-Support (EOS) in October 2021, and no currently supported devices or products are affected by this issue.
- CVE-2025-37164Critica10.0
A remote code execution issue exists in HPE OneView.
- CVE-2025-43520Media5.5
Un problema di danneggiamento della memoria è stato risolto con una gestione migliorata della memoria. Questo problema è stato corretto in iOS 18.7.2 e iPadOS 18.7.2, iOS 26.1 e iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Un'applicazione dannosa potrebbe causare l'interruzione imprevista del sistema o scrivere nella memoria del kernel.
- CVE-2025-43510Alta7.8
Un problema di danneggiamento della memoria è stato risolto con un controllo migliorato dello stato di blocco. Questo problema è stato risolto in iOS 18.7.2 e iPadOS 18.7.2, iOS 26.1 e iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Un'applicazione dannosa potrebbe causare modifiche impreviste alla memoria condivisa tra i processi.
- CVE-2025-14611Critica9.8
Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degrades security for public exposed endpoints that may make use of it and may offer arbitrary local file inclusion when provided a specially crafted request without authentication. This opens the door for future exploitation and can be leveraged with previous vulnerabilities to gain a full system compromise.
- CVE-2025-14174Alta8.8
Accesso alla memoria fuori dai limiti in ANGLE in Google Chrome su Mac prima della 143.0.7499.110 ha consentito a un attaccante remoto di eseguire un accesso alla memoria fuori dai limiti tramite una pagina HTML appositamente creata. (Gravità di sicurezza di Chromium: Alta)
- CVE-2025-8110Alta8.8
Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.
- CVE-2025-62221Alta7.8
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
- CVE-2025-59718Critica9.8
A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0.0 through 7.0.21, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.
- CVE-2025-48633Media5.5
In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVE-2025-48572Alta7.8
In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVE-2025-34291Alta8.8
Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with allow_credentials=True) combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. An attacker-controlled origin can therefore obtain fresh access_token / refresh_token pairs for a victim session. Obtained tokens permit access to authenticated endpoints — including built-in code-execution functionality — allowing the attacker to execute arbitrary code and achieve full system compromise.
- CVE-2025-66644Alta7.2
Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025.
- CVE-2025-55182Critica10.0
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.
- CVE-2025-58487Media4.0
Autorizzazione impropria in Samsung Account prima della versione 15.5.01.1 consente a un attaccante locale di avviare un'attività arbitraria con privilegi di Samsung Account.
- CVE-2025-58486Media4.0
Validazione impropria dell'input in Samsung Account prima della versione 15.5.01.1 consente a un attaccante locale di eseguire script arbitrario.
- CVE-2025-62593Alta8.8
Ray è un motore di elaborazione per l'IA. Prima della versione 2.52.0, gli sviluppatori che utilizzano Ray come strumento di sviluppo possono essere sfruttati tramite una vulnerabilità RCE critica sfruttabile tramite Firefox e Safari. Questa vulnerabilità è dovuta a una protezione insufficiente contro gli attacchi basati su browser, poiché la difesa attuale utilizza l'header User-Agent che inizia con la stringa "Mozilla" come meccanismo di difesa. Questa difesa è insufficiente poiché la specifica fetch consente di modificare l'header User-Agent. In combinazione con un attacco di DNS rebinding contro il browser, questa vulnerabilità è sfruttabile contro uno sviluppatore che esegue Ray e visita inavvertitamente un sito web malevolo, o a cui viene mostrato un annuncio pubblicitario malevolo (malvertising). Questo problema è stato corretto nella versione 2.52.0.
This product uses the NVD API but is not endorsed or certified by the NVD.