EN
58.507 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

CVE Tracker

58.507 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordinato dal più basso
CVE-2022-38376 MED 6.1 fortinet fortinac Multiple improper neutralization of input during web page generation ('Cross-site Scripting') vulnerabilities [CWE-79] in Fortinet FortiNAC portal UI before 9.4.1 allows an attacker to perform an XSS attack via crafted HTTP requests. 0,6% —
CVE-2022-38375 CRIT 9.1 fortinet fortinac An improper authorization vulnerability [CWE-285]  in Fortinet FortiNAC version 9.4.0 through 9.4.1 and before 9.2.6 allows an unauthenticated user to perform some administrative operations over the FortiNAC instance via crafted HTTP POST requests. 1,1% —
CVE-2022-38374 HIGH 8.8 fortinet fortiadc A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiADC 7.0.0 - 7.0.2 and 6.2.0 - 6.2.4 allows an attacker to execute unauthorized code or commands via the URL and User fields observed in the traffic and even 1,9% —
CVE-2022-38373 HIGH 8.0 fortinet fortideceptor An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiDeceptor management interface 4.2.0, 4.1.0 through 4.1.1, 4.0.2 may allow an authenticated user to perform a cross site scripting (XSS) attack via sending requests wi 0,5% —
CVE-2022-38372 MED 6.7 fortinet fortitester A hidden functionality vulnerability [CWE-1242] in FortiTester CLI 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow a local, privileged user to obtain a root shell on the device via an undocumented command. 0,2% —
CVE-2022-38370 HIGH 7.5 apache iotdb Apache IoTDB grafana-connector version 0.13.0 contains an interface without authorization, which may expose the internal structure of database. Users should upgrade to version 0.13.1 which addresses this issue. 1,3% —
CVE-2022-38369 HIGH 8.8 apache iotdb Apache IoTDB version 0.13.0 is vulnerable by session id attack. Users should upgrade to version 0.13.1 which addresses this issue. 1,3% —
CVE-2022-38362 HIGH 8.8 apache apache-airflow-providers-docker Apache Airflow Docker's Provider prior to 3.0.0 shipped with an example DAG that was vulnerable to (authenticated) remote code exploit of code on the Airflow worker host. 1,9% —
CVE-2022-38221 CRIT 9.8 the_isle_evrima_project the_isle_evrima A buffer overflow in the FTcpListener thread in The Isle Evrima (the dedicated server on Windows and Linux) 0.9.88.07 before 2022-08-12 allows a remote attacker to crash any server with an accessible RCON port, or possibly execute arbitrary code. 1,8% —
CVE-2022-38170 MED 4.7 apache airflow In Apache Airflow prior to 2.3.4, an insecure umask was configured for numerous Airflow components when running with the `--daemon` flag which could result in a race condition giving world-writable files in the Airflow home directory and allowing local users t 0,6% —
CVE-2022-38166 HIGH 7.5 f-secure elements_endpoint_protection In F-Secure Endpoint Protection for Windows and macOS before channel with Capricorn database 2022-11-22_07, the aerdl.dll unpacker handler crashes. This can lead to a scanning engine crash, triggerable remotely by an attacker for denial of service. 0,7% —
CVE-2022-38096 MED 6.3 linux linux_kernel A NULL pointer dereference vulnerability was found in vmwgfx driver in drivers/gpu/vmxgfx/vmxgfx_execbuf.c in GPU component of Linux kernel with device file '/dev/dri/renderD128 (or Dxxx)'. This flaw allows a local attacker with a user account on the system to 0,8% —
CVE-2022-38054 CRIT 9.8 apache airflow In Apache Airflow versions 2.2.4 through 2.3.3, the `database` webserver session backend was susceptible to session fixation. 2,1% —
CVE-2022-38053 HIGH 8.8 microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability 76,4% —
CVE-2022-38051 HIGH 7.8 microsoft windows_10 Windows Graphics Component Elevation of Privilege Vulnerability 7,3% —
CVE-2022-38050 HIGH 7.8 microsoft windows_10 Win32k Elevation of Privilege Vulnerability 7,3% —
CVE-2022-38049 HIGH 7.8 microsoft 365_apps Microsoft Office Graphics Remote Code Execution Vulnerability 0,9% —
CVE-2022-38048 HIGH 7.8 microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability 1,6% —
CVE-2022-38047 HIGH 8.1 microsoft windows_10 Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability 1,2% —
CVE-2022-38046 HIGH 7.5 microsoft windows_10 Web Account Manager Information Disclosure Vulnerability 1,9% —
CVE-2022-38045 HIGH 8.8 microsoft windows_10 Windows Server Service Elevation of Privilege Vulnerability 2,3% —
CVE-2022-38044 HIGH 7.8 microsoft windows_10 Windows CD-ROM File System Driver Remote Code Execution Vulnerability 56,3% —
CVE-2022-38043 MED 5.5 microsoft windows_10 Windows Security Support Provider Interface Information Disclosure Vulnerability 0,6% —
CVE-2022-38042 HIGH 7.1 microsoft windows_10 Active Directory Domain Services Elevation of Privilege Vulnerability 1,4% —
CVE-2022-38041 HIGH 7.5 microsoft windows_10 Windows Secure Channel Denial of Service Vulnerability 2,2% —