Database CVE
Archivio delle vulnerabilità note (CVE) con punteggio CVSS, gravità, prodotti e vendor coinvolti. Filtra per anno e severità, collegato ai nostri articoli.
- CVE-2025-21479Alta8.6
Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
- CVE-2025-27038Alta7.5
Memory corruption while rendering graphics using Adreno GPU drivers in Chrome.
- CVE-2025-21480Alta8.6
Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
- CVE-2025-5419Alta8.8
Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2025-5086Critica9.0
A deserialization of untrusted data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could lead to a remote code execution.
- CVE-2025-49113Critica9.9
Roundcube Webmail prima di 1.5.10 e 1.6.x prima di 1.6.11 consente l'esecuzione di codice da remoto da parte di utenti autenticati perché il parametro _from in un URL non è convalidato in program/actions/settings/upload.php, portando a PHP Object Deserialization.
- CVE-2025-48928Media4.0
The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent to a "core dump" in which a password previously sent over HTTP would be included in this dump, as exploited in the wild in May 2025.
- CVE-2025-48927Media5.3
The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploited in the wild in May 2025.
- CVE-2025-34026Alta7.5
The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The internal Actuator endpoint can be leveraged for access to heap dumps and trace logs.This issue is known to affect Concerto from 12.1.2 through 12.2.0. Additional versions may be vulnerable.
- CVE-2025-4008Alta8.8
The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer their meteobridge system through a web application written in CGI shell scripts and C. This web interface exposes an endpoint that is vulnerable to command injection. Remote unauthenticated attackers can gain arbitrary command execution with elevated privileges ( root ) on affected devices.
- CVE-2025-32709Alta7.8
Dereferenziazione del puntatore null in Windows Ancillary Function Driver for WinSock consente a un attaccante autorizzato di elevare i privilegi localmente.
- CVE-2025-32706Alta7.8
Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
- CVE-2025-32701Alta7.8
Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
- CVE-2025-30400Alta7.8
Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.
- CVE-2025-30397Alta7.5
Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network.
- CVE-2025-4428Alta7.2
Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers to execute arbitrary code via crafted API requests.
- CVE-2025-4427Media5.3
An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via the API.
- CVE-2025-32756Critica9.8
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiNDR 7.6.0, FortiNDR 7.4.0 through 7.4.7, FortiNDR 7.2.0 through 7.2.4, FortiNDR 7.0.0 through 7.0.6, FortiRecorder 7.2.0 through 7.2.3, FortiRecorder 7.0.0 through 7.0.5, FortiRecorder 6.4.0 through 6.4.5, FortiVoice 7.2.0, FortiVoice 7.0.0 through 7.0.6, FortiVoice 6.4.0 through 6.4.10 allows a remote unauthenticated attacker to execute arbitrary code or commands via sending HTTP requests with specially crafted hash cookie.
- CVE-2025-4632Critica9.8
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to write arbitrary file as system authority.
- CVE-2025-42999Critica9.1
SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system.
This product uses the NVD API but is not endorsed or certified by the NVD.